File name:

KORG.MS-20.v2.3.1.Incl.Keygen-RET.rar

Full analysis: https://app.any.run/tasks/3eb1eb69-59f7-4ed7-baea-dff8a4528f08
Verdict: Malicious activity
Analysis date: April 18, 2025, 03:55:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
delphi
inno
installer
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

BC33682A53775B244FFE3CCD6D2E3C29

SHA1:

8ADE58ABC14C1F25C77741ECD24000C9297DD900

SHA256:

1E492662AC7352BD3C72A46A0A4F02BE68C6601A3DA9E1B96D914618BC89E6AF

SSDEEP:

98304:bckZAVwjj40rM5ULVyKXQh0scRw/4HPuMbQEJPC9R33fHcUsselPu2LMBWMhRG21:wUL5PbrKLDsKvG0s6liz2RheOD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7644)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • Setup MS-20 v2.3.1.exe (PID: 7348)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • Setup MS-20 v2.3.1.exe (PID: 5868)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Reads security settings of Internet Explorer

      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
    • Reads the Windows owner or organization settings

      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Searches for installed software

      • Setup MS-20 v2.3.1.tmp (PID: 7812)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 5216)
      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • WinRAR.exe (PID: 7940)
      • KORG3_KeyGen.exe (PID: 4688)
      • WinRAR.exe (PID: 7768)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • WinRAR.exe (PID: 1184)
      • WinRAR.exe (PID: 4244)
    • Create files in a temporary directory

      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • Setup MS-20 v2.3.1.exe (PID: 7348)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • Setup MS-20 v2.3.1.exe (PID: 5868)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Checks supported languages

      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • Setup MS-20 v2.3.1.exe (PID: 7348)
      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • KORG3_KeyGen.exe (PID: 4688)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
      • Setup MS-20 v2.3.1.exe (PID: 5868)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5216)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 5216)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Reads the computer name

      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • KORG3_KeyGen.exe (PID: 4688)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Process checks computer location settings

      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
    • Creates files in the program directory

      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • KORG3_KeyGen.exe (PID: 4688)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Compiled with Borland Delphi (YARA)

      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.exe (PID: 7348)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
      • Setup MS-20 v2.3.1.exe (PID: 5868)
    • Detects InnoSetup installer (YARA)

      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.exe (PID: 7152)
      • Setup MS-20 v2.3.1.tmp (PID: 496)
      • Setup MS-20 v2.3.1.exe (PID: 7348)
      • Setup MS-20 v2.3.1.exe (PID: 2152)
      • Setup MS-20 v2.3.1.tmp (PID: 4008)
      • Setup MS-20 v2.3.1.exe (PID: 5868)
    • Creates a software uninstall entry

      • Setup MS-20 v2.3.1.tmp (PID: 7372)
      • Setup MS-20 v2.3.1.tmp (PID: 7812)
    • Reads the machine GUID from the registry

      • KORG3_KeyGen.exe (PID: 4688)
    • Checks proxy server information

      • slui.exe (PID: 7444)
    • Reads the software policy settings

      • slui.exe (PID: 7444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 4560028
UncompressedSize: 4560028
OperatingSystem: Win32
ArchivedFileName: KORG.MS-20.v2.3.1.Incl.Keygen-RET/ret-0207.r00
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
17
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs rundll32.exe no specs winrar.exe no specs winrar.exe setup ms-20 v2.3.1.exe setup ms-20 v2.3.1.tmp no specs setup ms-20 v2.3.1.exe setup ms-20 v2.3.1.tmp slui.exe korg3_keygen.exe no specs winrar.exe no specs winrar.exe no specs winrar.exe no specs setup ms-20 v2.3.1.exe setup ms-20 v2.3.1.tmp no specs setup ms-20 v2.3.1.exe setup ms-20 v2.3.1.tmp

Process information

PID
CMD
Path
Indicators
Parent process
496"C:\Users\admin\AppData\Local\Temp\is-RGQNK.tmp\Setup MS-20 v2.3.1.tmp" /SL5="$C0346,13569899,327680,C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" C:\Users\admin\AppData\Local\Temp\is-RGQNK.tmp\Setup MS-20 v2.3.1.tmpSetup MS-20 v2.3.1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rgqnk.tmp\setup ms-20 v2.3.1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1184"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\ret-0207.r00"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2152"C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe
explorer.exe
User:
admin
Company:
KORG
Integrity Level:
MEDIUM
Description:
MS-20 Setup
Exit code:
0
Version:
2.3.1
Modules
Images
c:\users\admin\desktop\korg.ms-20.v2.3.1.incl.keygen-ret\setup ms-20 v2.3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\oleaut32.dll
c:\windows\syswow64\msvcp_win.dll
4008"C:\Users\admin\AppData\Local\Temp\is-E11BS.tmp\Setup MS-20 v2.3.1.tmp" /SL5="$12035C,13569899,327680,C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" C:\Users\admin\AppData\Local\Temp\is-E11BS.tmp\Setup MS-20 v2.3.1.tmpSetup MS-20 v2.3.1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-e11bs.tmp\setup ms-20 v2.3.1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\oleaut32.dll
c:\windows\syswow64\msvcp_win.dll
4244"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\ret-0207.r00" C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
255
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4688"C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\RET\KORG3_KeyGen.exe" C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\RET\KORG3_KeyGen.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
KORG KeyGen
Exit code:
0
Modules
Images
c:\users\admin\desktop\korg.ms-20.v2.3.1.incl.keygen-ret\ret\korg3_keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5216"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\ret-0207.rar" C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5868"C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" /SPAWNWND=$902F2 /NOTIFYWND=$12035C C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe
Setup MS-20 v2.3.1.tmp
User:
admin
Company:
KORG
Integrity Level:
HIGH
Description:
MS-20 Setup
Exit code:
0
Version:
2.3.1
Modules
Images
c:\users\admin\desktop\korg.ms-20.v2.3.1.incl.keygen-ret\setup ms-20 v2.3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
7152"C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe
explorer.exe
User:
admin
Company:
KORG
Integrity Level:
MEDIUM
Description:
MS-20 Setup
Exit code:
0
Version:
2.3.1
Modules
Images
c:\users\admin\desktop\korg.ms-20.v2.3.1.incl.keygen-ret\setup ms-20 v2.3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
7348"C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe" /SPAWNWND=$3035C /NOTIFYWND=$C0346 C:\Users\admin\Desktop\KORG.MS-20.v2.3.1.Incl.Keygen-RET\Setup MS-20 v2.3.1.exe
Setup MS-20 v2.3.1.tmp
User:
admin
Company:
KORG
Integrity Level:
HIGH
Description:
MS-20 Setup
Exit code:
0
Version:
2.3.1
Modules
Images
c:\users\admin\desktop\korg.ms-20.v2.3.1.incl.keygen-ret\setup ms-20 v2.3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
6 588
Read events
6 471
Write events
116
Delete events
1

Modification events

(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\KORG.MS-20.v2.3.1.Incl.Keygen-RET.rar
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7940) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7940) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
Executable files
22
Suspicious files
1 684
Text files
8
Unknown types
3

Dropped files

PID
Process
Filename
Type
7644WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7644.36620\KORG.MS-20.v2.3.1.Incl.Keygen-RET\ret-0207.r00
MD5:
SHA256:
7644WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7644.36620\KORG.MS-20.v2.3.1.Incl.Keygen-RET\ret-0207.rar
MD5:
SHA256:
7372Setup MS-20 v2.3.1.tmpC:\Program Files\KORG\MS-20\is-USM8B.tmpexecutable
MD5:0D87A6C596B4493B867FCCA605F9D5BD
SHA256:E86C4256B3143AE305F64D40D0F0D34D015C3AAB1D3C090473AF4B5293EE18C4
7372Setup MS-20 v2.3.1.tmpC:\Program Files\Common Files\KORG\Collection\is-I2K35.tmpexecutable
MD5:7D9752C0982E729FA266AEA3F23A329B
SHA256:6E3BF3DD842DDEE9337BB5BF5734C8B38D4A9BD1A296DD269026787E604EBD3F
7372Setup MS-20 v2.3.1.tmpC:\Program Files\Common Files\KORG\Collection\is-KBUVP.tmpexecutable
MD5:62A3FF7BDED27E94D34D426ACD90D370
SHA256:F4AD9A1A70003EDB94DDBF12CED9F42C37EBBF113FE91127EFCA6EE2B0639A30
7372Setup MS-20 v2.3.1.tmpC:\Program Files\KORG\MS-20\unins000.exeexecutable
MD5:0D87A6C596B4493B867FCCA605F9D5BD
SHA256:E86C4256B3143AE305F64D40D0F0D34D015C3AAB1D3C090473AF4B5293EE18C4
7644WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7644.36620\KORG.MS-20.v2.3.1.Incl.Keygen-RET\RET.nfotext
MD5:228A2A4B8B3D0CEE14259922B2537428
SHA256:74711F9F53BB177C8D06BB66DB7D48B3A8484E2CF29B398419813BE86ABF6B39
7348Setup MS-20 v2.3.1.exeC:\Users\admin\AppData\Local\Temp\is-Q15OU.tmp\Setup MS-20 v2.3.1.tmpexecutable
MD5:2B1BFC50B524224678A8C2C5340D3266
SHA256:7FDE3B4D88A40CD405FC2B7569026C2B791384FEC2357067CAF1AAD16E76F389
7372Setup MS-20 v2.3.1.tmpC:\Program Files\KORG\MS-20\MS-20.icoimage
MD5:025A6CEC54E98FF93616FA1D728A01ED
SHA256:D0BEF060C90AD8DCDF62156ADA11A9A7A6EACFDB48ADAFFEFD7E57243BBC7B7B
7372Setup MS-20 v2.3.1.tmpC:\Program Files\Common Files\KORG\Collection\MS-20.dllexecutable
MD5:62A3FF7BDED27E94D34D426ACD90D370
SHA256:F4AD9A1A70003EDB94DDBF12CED9F42C37EBBF113FE91127EFCA6EE2B0639A30
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
19
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8100
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8100
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
8100
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8100
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
8100
SIHClient.exe
52.165.164.15:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7568
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
google.com
  • 216.58.206.78
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.13
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.0
  • 40.126.31.1
  • 40.126.31.3
  • 40.126.31.128
  • 40.126.31.129
  • 40.126.31.67
  • 40.126.31.71
whitelisted

Threats

No threats detected
No debug info