File name:

AudFree_Spotify_Music_Converter_2.16.1.102.7z

Full analysis: https://app.any.run/tasks/f6ba3c22-bc92-400f-9ddd-183aad2c0b79
Verdict: Malicious activity
Analysis date: November 09, 2024, 08:10:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
qrcode
arch-html
arch-scr
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

95D43064AD0BE3B00661C9488F8A5C98

SHA1:

930ACCD0FDDDADBCA8E8AF8DCBB9B5A7F5CC52B4

SHA256:

1DE71749A19543D61DE3171DCFC8FE0C31AE977FBF04E6D7DBDC4537BEE72902

SSDEEP:

98304:ad+iCA7AQj97Tu+qC/QR/QgJfzOAwluKEBFjJpFLZvbxP4NSebbPj/orAEjUDwEx:XXoirRPt4yC/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6564)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 6288)
      • SpoDable.exe (PID: 2684)
      • SpoDable.tmp (PID: 6224)
      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 7088)
      • SpoDable.tmp (PID: 7384)
      • SpoDable.exe (PID: 8092)
      • SpWebInst0.exe (PID: 7564)
    • Process drops legitimate windows executable

      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 6288)
      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 7088)
      • SpWebInst0.exe (PID: 7564)
    • Starts CMD.EXE for commands execution

      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 6288)
      • cmd.exe (PID: 7892)
      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 7088)
      • cmd.exe (PID: 7908)
      • cmd.exe (PID: 7864)
      • cmd.exe (PID: 5168)
    • Executing commands from a ".bat" file

      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 6288)
      • cmd.exe (PID: 7892)
      • cmd.exe (PID: 7864)
      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 7088)
      • cmd.exe (PID: 7908)
      • cmd.exe (PID: 5168)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 7892)
      • cmd.exe (PID: 7864)
      • cmd.exe (PID: 7908)
      • cmd.exe (PID: 5168)
    • Application launched itself

      • cmd.exe (PID: 7892)
      • cmd.exe (PID: 7864)
      • cmd.exe (PID: 7908)
      • cmd.exe (PID: 5168)
      • Spotify.exe (PID: 7264)
  • INFO

    • Manual execution by a user

      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 5756)
      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 6288)
      • msedge.exe (PID: 5332)
      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 7176)
      • AudFree Spotify Music Converter 2.16.1.102.exe (PID: 7088)
      • AFSpotifyMusicConverter.exe (PID: 6736)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6564)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6564)
      • msiexec.exe (PID: 300)
      • msedge.exe (PID: 3020)
      • msedge.exe (PID: 512)
    • Application launched itself

      • msedge.exe (PID: 5236)
      • msedge.exe (PID: 5332)
      • msedge.exe (PID: 6676)
      • msedge.exe (PID: 3020)
      • msedge.exe (PID: 7192)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2024:10:22 00:17:41+00:00
ArchivedFileName: AudFree Spotify Music Converter 2.16.1.102.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
354
Monitored processes
191
Malicious processes
2
Suspicious processes
11

Behavior graph

Click at the process to see the details
start winrar.exe audfree spotify music converter 2.16.1.102.exe no specs audfree spotify music converter 2.16.1.102.exe msiexec.exe msiexec.exe no specs spodable.exe spodable.tmp msedge.exe no specs msedge.exe no specs msiexec.exe no specs msiexec.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs msedge.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs audfree spotify music converter 2.16.1.102.exe no specs audfree spotify music converter 2.16.1.102.exe msiexec.exe no specs spodable.exe spodable.tmp msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs cmd.exe no specs cmd.exe no specs attrib.exe no specs cmd.exe no specs cmd.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs afspotifymusicconverter.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs spotifysetup.exe no specs spwebinst0.exe msedge.exe no specs spotify.exe no specs spotify.exe no specs spotify.exe no specs spotify.exe no specs spotify.exe no specs spotify.exe no specs spotify.exe no specs spotify.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs spotify.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs sechealthui.exe no specs securityhealthhost.exe no specs securityhealthhost.exe no specs securityhealthhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
204"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=788 --field-trial-handle=2340,i,16010229692261931530,17433202153678290770,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
300C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
512"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2544 --field-trial-handle=2372,i,3656342523538970080,17361738446015638955,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
528C:\Windows\System32\SecurityHealthHost.exe {E041C90B-68BA-42C9-991E-477B73A75C90} -EmbeddingC:\Windows\System32\SecurityHealthHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Security Health Host
Exit code:
0
Version:
4.18.1907.16384 (WinBuild.160101.0800)
848"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=30 --mojo-platform-channel-handle=6204 --field-trial-handle=2372,i,3656342523538970080,17361738446015638955,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
920"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x290,0x294,0x298,0x208,0x2a0,0x7ffbca3b5fd8,0x7ffbca3b5fe4,0x7ffbca3b5ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
1160"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5372 --field-trial-handle=2380,i,5609478614031747770,11124758690533081355,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1172"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5216 --field-trial-handle=2372,i,3656342523538970080,17361738446015638955,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
1244"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=3364 --field-trial-handle=2372,i,3656342523538970080,17361738446015638955,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
122.0.2365.59
1332"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=4912 --field-trial-handle=2372,i,3656342523538970080,17361738446015638955,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Total events
13 116
Read events
12 946
Write events
147
Delete events
23

Modification events

(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AudFree_Spotify_Music_Converter_2.16.1.102.7z
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6224) SpoDable.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AudFree Spotify Music Converter_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.2
(PID) Process:(6224) SpoDable.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AudFree Spotify Music Converter_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\AudFree Spotify Music Converter
(PID) Process:(6224) SpoDable.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AudFree Spotify Music Converter_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\AudFree Spotify Music Converter\
(PID) Process:(6224) SpoDable.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AudFree Spotify Music Converter_is1
Operation:writeName:Inno Setup: Icon Group
Value:
AudFree Spotify Music Converter
Executable files
115
Suspicious files
1 105
Text files
630
Unknown types
77

Dropped files

PID
Process
Filename
Type
6288AudFree Spotify Music Converter 2.16.1.102.exeC:\Users\admin\AppData\Local\Temp\holder0.aiphbinary
MD5:D49D6E6A973FE2441A79203EDC92FF73
SHA256:A9A240E64A73B01159CD287A666BFE264EA17FAEA941C2B5ACDBB6A5F40A3F65
6288AudFree Spotify Music Converter 2.16.1.102.exeC:\Users\admin\AppData\Local\Temp\MSIE9AF.tmpexecutable
MD5:EC6EBF65FE4F361A73E473F46730E05C
SHA256:D3614D7BECE53E0D408E31DA7D9B0FF2F7285A7DD544C778847ED0C5DED5D52F
6288AudFree Spotify Music Converter 2.16.1.102.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_6288\infoimage
MD5:8595D2A2D58310B448729E28649443D6
SHA256:27F13C4829994B214BB1A26EEF474DA67C521FD429536CB8421BA2F7C3E02B5F
6288AudFree Spotify Music Converter 2.16.1.102.exeC:\Users\admin\AppData\Local\Temp\MSIE931.tmpexecutable
MD5:EC6EBF65FE4F361A73E473F46730E05C
SHA256:D3614D7BECE53E0D408E31DA7D9B0FF2F7285A7DD544C778847ED0C5DED5D52F
6288AudFree Spotify Music Converter 2.16.1.102.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_6288\dialog.jpgimage
MD5:5F6253CFF5A8B031BFB3B161079D0D86
SHA256:36D9BAB35D1E4B50045BF902F5D42B6F865488C75F6E60FC00A6CD6F69034AB0
6288AudFree Spotify Music Converter 2.16.1.102.exeC:\Users\admin\AppData\Local\Temp\AudFree_Spotify_Music_Converter.msiexecutable
MD5:382FF0A3F2368014CEA68D9496F22007
SHA256:B0B1B1F8B4CF562F39F45829B2A699CA16AA923B5006DC6B3DAABD3047008946
6288AudFree Spotify Music Converter 2.16.1.102.exeC:\Users\admin\AppData\Local\Temp\MSIEA0E.tmpexecutable
MD5:EC6EBF65FE4F361A73E473F46730E05C
SHA256:D3614D7BECE53E0D408E31DA7D9B0FF2F7285A7DD544C778847ED0C5DED5D52F
6288AudFree Spotify Music Converter 2.16.1.102.exeC:\Users\admin\AppData\Local\Temp\shiE8D2.tmpexecutable
MD5:84A34BF3486F7B9B7035DB78D78BDD1E
SHA256:F85911C910B660E528D2CF291BAA40A92D09961996D6D84E7A53A7095C7CD96E
6288AudFree Spotify Music Converter 2.16.1.102.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_6288\completiimage
MD5:C23AF89757665BC0386FD798A61B2112
SHA256:031ED0378F819926D7B5B2C6C9367A0FB1CBAE40E1A3959E2652FE30A47D52F2
6288AudFree Spotify Music Converter 2.16.1.102.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_6288\custiconimage
MD5:BE6D2F48AA6634FB2101C273C798D4D9
SHA256:0E22BC2BF7184DFDB55223A11439304A453FB3574E3C9034A6497AF405C628EF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
84
TCP/UDP connections
230
DNS requests
257
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4700
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1376
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
304
2.23.197.184:80
http://x1.c.lencr.org/
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3848
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1376
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7060
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4360
SearchApp.exe
2.23.209.179:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4700
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4700
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4360
SearchApp.exe
2.23.209.133:443
www.bing.com
Akamai International B.V.
GB
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.23.209.179
  • 2.23.209.175
  • 2.23.209.156
  • 2.23.209.158
  • 2.23.209.162
  • 2.23.209.160
  • 2.23.209.177
  • 2.23.209.173
  • 2.23.209.166
  • 2.23.209.133
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.135
  • 2.23.209.141
  • 2.23.209.130
  • 2.23.209.150
  • 2.23.209.144
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.185
  • 2.23.209.181
  • 2.23.209.182
  • 2.23.209.176
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.185.174
whitelisted
login.live.com
  • 40.126.32.68
  • 40.126.32.76
  • 40.126.32.140
  • 20.190.160.14
  • 40.126.32.133
  • 40.126.32.72
  • 40.126.32.74
  • 20.190.160.17
whitelisted
th.bing.com
  • 2.23.209.133
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.135
  • 2.23.209.141
  • 2.23.209.130
  • 2.23.209.150
  • 2.23.209.144
  • 2.23.209.158
  • 2.23.209.181
  • 2.23.209.182
  • 2.23.209.179
  • 2.23.209.185
  • 2.23.209.160
  • 2.23.209.177
  • 2.23.209.176
whitelisted
go.microsoft.com
  • 23.218.210.69
  • 184.28.89.167
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
api.audfree.com
  • 104.21.64.50
  • 172.67.176.90
unknown
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted

Threats

No threats detected
No debug info