File name:

KORG.MS-20.v2.3.1.Incl.Keygen-RET.rar

Full analysis: https://app.any.run/tasks/3eb1eb69-59f7-4ed7-baea-dff8a4528f08
Verdict: Malicious activity
Analysis date: April 18, 2025, 03:55:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
delphi
inno
installer
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

BC33682A53775B244FFE3CCD6D2E3C29

SHA1:

8ADE58ABC14C1F25C77741ECD24000C9297DD900

SHA256:

1E492662AC7352BD3C72A46A0A4F02BE68C6601A3DA9E1B96D914618BC89E6AF

SSDEEP:

98304:bckZAVwjj40rM5ULVyKXQh0scRw/4HPuMbQEJPC9R33fHcUsselPu2LMBWMhRG21:wUL5PbrKLDsKvG0s6liz2RheOD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7644)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • Setup MS-20 v2.3.1.exe (PID: 7348)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • Setup MS-20 v2.3.1.exe (PID: 5868)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Reads security settings of Internet Explorer

      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
    • Reads the Windows owner or organization settings

      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Searches for installed software

      • Setup MS-20 v2.3.1.tmp (PID: 7812)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 7940)
      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • WinRAR.exe (PID: 5216)
      • WinRAR.exe (PID: 4244)
      • WinRAR.exe (PID: 1184)
      • WinRAR.exe (PID: 7768)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • KORG3_KeyGen.exe (PID: 4688)
    • Checks supported languages

      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.exe (PID: 7348)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
      • KORG3_KeyGen.exe (PID: 4688)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
      • Setup MS-20 v2.3.1.exe (PID: 5868)
    • Create files in a temporary directory

      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.exe (PID: 7348)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • Setup MS-20 v2.3.1.exe (PID: 5868)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 5216)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5216)
    • Reads the computer name

      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • KORG3_KeyGen.exe (PID: 4688)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
    • Process checks computer location settings

      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
    • Creates files in the program directory

      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • KORG3_KeyGen.exe (PID: 4688)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Detects InnoSetup installer (YARA)

      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • Setup MS-20 v2.3.1.exe (PID: 7348)
      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
      • Setup MS-20 v2.3.1.exe (PID: 5868)
    • Compiled with Borland Delphi (YARA)

      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.exe (PID: 7348)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
      • Setup MS-20 v2.3.1.exe (PID: 5868)
    • Reads the machine GUID from the registry

      • KORG3_KeyGen.exe (PID: 4688)
    • Checks proxy server information

      • slui.exe (PID: 7444)
    • Creates a software uninstall entry

      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Reads the software policy settings

      • slui.exe (PID: 7444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 4560028
UncompressedSize: 4560028
OperatingSystem: Win32
ArchivedFileName: KORG.MS-20.v2.3.1.Incl.Keygen-RET/ret-0207.r00
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
17
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs rundll32.exe no specs winrar.exe no specs winrar.exe setup ms-20 v2.3.1.exe setup ms-20 v2.3.1.tmp no specs setup ms-20 v2.3.1.exe setup ms-20 v2.3.1.tmp slui.exe korg3_keygen.exe no specs winrar.exe no specs winrar.exe no specs winrar.exe no specs setup ms-20 v2.3.1.exe setup ms-20 v2.3.1.tmp no specs setup ms-20 v2.3.1.exe setup ms-20 v2.3.1.tmp

Process information

PID
CMD
Path
Indicators
Parent process
496"C:\Users\admin\AppData\Local\Temp\is-RGQNK.tmp\Setup MS-20 v2.3.1.tmp" /SL5="$C0346,13569899,327680,C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" C:\Users\admin\AppData\Local\Temp\is-RGQNK.tmp\Setup MS-20 v2.3.1.tmpSetup MS-20 v2.3.1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rgqnk.tmp\setup ms-20 v2.3.1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1184"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\ret-0207.r00"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2152"C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe
explorer.exe
User:
admin
Company:
KORG
Integrity Level:
MEDIUM
Description:
MS-20 Setup
Exit code:
0
Version:
2.3.1
Modules
Images
c:\users\admin\desktop\korg.ms-20.v2.3.1.incl.keygen-ret\setup ms-20 v2.3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\oleaut32.dll
c:\windows\syswow64\msvcp_win.dll
4008"C:\Users\admin\AppData\Local\Temp\is-E11BS.tmp\Setup MS-20 v2.3.1.tmp" /SL5="$12035C,13569899,327680,C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" C:\Users\admin\AppData\Local\Temp\is-E11BS.tmp\Setup MS-20 v2.3.1.tmpSetup MS-20 v2.3.1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-e11bs.tmp\setup ms-20 v2.3.1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\oleaut32.dll
c:\windows\syswow64\msvcp_win.dll
4244"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\ret-0207.r00" C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
255
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4688"C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\RET\KORG3_KeyGen.exe" C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\RET\KORG3_KeyGen.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
KORG KeyGen
Exit code:
0
Modules
Images
c:\users\admin\desktop\korg.ms-20.v2.3.1.incl.keygen-ret\ret\korg3_keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5216"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\ret-0207.rar" C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5868"C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" /SPAWNWND=$902F2 /NOTIFYWND=$12035C C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe
Setup MS-20 v2.3.1.tmp
User:
admin
Company:
KORG
Integrity Level:
HIGH
Description:
MS-20 Setup
Exit code:
0
Version:
2.3.1
Modules
Images
c:\users\admin\desktop\korg.ms-20.v2.3.1.incl.keygen-ret\setup ms-20 v2.3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
7152"C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe
explorer.exe
User:
admin
Company:
KORG
Integrity Level:
MEDIUM
Description:
MS-20 Setup
Exit code:
0
Version:
2.3.1
Modules
Images
c:\users\admin\desktop\korg.ms-20.v2.3.1.incl.keygen-ret\setup ms-20 v2.3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
7348"C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" /SPAWNWND=$3035C /NOTIFYWND=$C0346 C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe
Setup MS-20 v2.3.1.tmp
User:
admin
Company:
KORG
Integrity Level:
HIGH
Description:
MS-20 Setup
Exit code:
0
Version:
2.3.1
Modules
Images
c:\users\admin\desktop\korg.ms-20.v2.3.1.incl.keygen-ret\setup ms-20 v2.3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
6 588
Read events
6 471
Write events
116
Delete events
1

Modification events

(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\KORG.MS-20.v2.3.1.Incl.Keygen-RET.rar
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7940) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7940) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
Executable files
22
Suspicious files
1 684
Text files
8
Unknown types
3

Dropped files

PID
Process
Filename
Type
7644WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7644.36620\KORG.MS-20.v2.3.1.Incl.Keygen-RET\ret-0207.r00
MD5:
SHA256:
7644WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7644.36620\KORG.MS-20.v2.3.1.Incl.Keygen-RET\ret-0207.rar
MD5:
SHA256:
7372Setup MS-20 v2.3.1.tmpC:\Program Files\KORG\MS-20\is-16EAC.tmpimage
MD5:025A6CEC54E98FF93616FA1D728A01ED
SHA256:D0BEF060C90AD8DCDF62156ADA11A9A7A6EACFDB48ADAFFEFD7E57243BBC7B7B
5216WinRAR.exeC:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exeexecutable
MD5:3BF8435EFADC6D6AE2CCF33A1D09DDB9
SHA256:3E9D18C818EC8BA063A31686D004715A8B451DC5391329CAD4DBBEC951554259
7372Setup MS-20 v2.3.1.tmpC:\Program Files\KORG\MS-20\unins000.exeexecutable
MD5:0D87A6C596B4493B867FCCA605F9D5BD
SHA256:E86C4256B3143AE305F64D40D0F0D34D015C3AAB1D3C090473AF4B5293EE18C4
7644WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7644.36620\KORG.MS-20.v2.3.1.Incl.Keygen-RET\ret-0207.sfvtext
MD5:89AB3351490D0296EC638CF68E17BDC2
SHA256:8C004150269244DA9733B47568D378A687FC33EE19C1493631BB44C4FCC46B70
7372Setup MS-20 v2.3.1.tmpC:\Program Files\KORG\MS-20\MS-20.icoimage
MD5:025A6CEC54E98FF93616FA1D728A01ED
SHA256:D0BEF060C90AD8DCDF62156ADA11A9A7A6EACFDB48ADAFFEFD7E57243BBC7B7B
7372Setup MS-20 v2.3.1.tmpC:\ProgramData\KORG\MS-20\is-PRED7.tmpbinary
MD5:E46DBA07624DB92FA12A5D5BAD01AE9E
SHA256:E17217FB1F2A23DFBF5051B3333E8F18C4D16BDE5742386243B6CD7DBD703FFD
5216WinRAR.exeC:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\RET\KORG3_KeyGen.exeexecutable
MD5:1BD4CA1FEC6A0117894306A671D882F2
SHA256:52C35C51467C0B8D57F63F5EA0003B4ABE64BBDA970A553CABB800F1F6C4353C
7372Setup MS-20 v2.3.1.tmpC:\Users\admin\AppData\Local\Temp\is-1M1EP.tmp\R2RINNO.dllexecutable
MD5:5DF8ADA84A16F5DFC24096EF90A5CE3A
SHA256:48A9C8C332FDE541B571D9D522D0E37834B452F55AF8CBDC341B12222E78FB5B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
19
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8100
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8100
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
8100
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8100
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
8100
SIHClient.exe
52.165.164.15:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7568
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
google.com
  • 216.58.206.78
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.13
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.0
  • 40.126.31.1
  • 40.126.31.3
  • 40.126.31.128
  • 40.126.31.129
  • 40.126.31.67
  • 40.126.31.71
whitelisted

Threats

No threats detected
No debug info