File name:

Simple Traffic Exchange 140406.zip

Full analysis: https://app.any.run/tasks/aae8eb62-a821-4bc7-b102-fb1c80e34f2b
Verdict: Malicious activity
Analysis date: June 01, 2025, 19:33:08
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
windivert-sys
mal-driver
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

0C6D8F1F85C3759AB1925622F1C5C95E

SHA1:

A0268F0582049D88FBFEAD2974FDB093BF8CD5C5

SHA256:

1E5719FF215553ADB4BF6E1907B264BCE9D5C24BED3019342C521480B0257769

SSDEEP:

196608:vf7XGGNPvoFEfy3S82QG/092tKlCdwuDDiIU:vDXlvot3h2QG/09MK0dw4RU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes Windows Error Reporting flag

      • Simple Traffic Exchange.exe (PID: 2316)
      • Simple Traffic Exchange.exe (PID: 2504)
      • Simple Traffic Exchange.exe (PID: 7012)
    • Malicious driver has been detected

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2104)
      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • Executable content was dropped or overwritten

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • The process drops C-runtime libraries

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • Drops a system driver (possible attempt to evade defenses)

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • Process drops python dynamic module

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • There is functionality for taking screenshot (YARA)

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 2104)
      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2104)
      • firefox.exe (PID: 7296)
    • Reads the computer name

      • Simple Traffic Exchange.exe (PID: 2316)
      • Simple Traffic Exchange.exe (PID: 2504)
      • AppUpdater.exe (PID: 7468)
      • Simple Traffic Exchange.exe (PID: 7012)
      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • Checks supported languages

      • Simple Traffic Exchange.exe (PID: 2316)
      • Simple Traffic Exchange.exe (PID: 2504)
      • AppUpdater.exe (PID: 7468)
      • Simple Traffic Exchange.exe (PID: 7012)
      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • Manual execution by a user

      • Simple Traffic Exchange.exe (PID: 2316)
      • Simple Traffic Exchange.exe (PID: 2504)
      • AppUpdater.exe (PID: 7468)
      • Simple Traffic Exchange.exe (PID: 7012)
      • firefox.exe (PID: 6208)
    • Reads the machine GUID from the registry

      • Simple Traffic Exchange.exe (PID: 2316)
      • Simple Traffic Exchange.exe (PID: 2504)
      • AppUpdater.exe (PID: 7468)
      • Simple Traffic Exchange.exe (PID: 7012)
    • Checks proxy server information

      • Simple Traffic Exchange.exe (PID: 2316)
      • Simple Traffic Exchange.exe (PID: 2504)
      • Simple Traffic Exchange.exe (PID: 7012)
      • AppUpdater.exe (PID: 7468)
    • Disables trace logs

      • Simple Traffic Exchange.exe (PID: 2316)
      • Simple Traffic Exchange.exe (PID: 2504)
      • AppUpdater.exe (PID: 7468)
      • Simple Traffic Exchange.exe (PID: 7012)
    • Reads the software policy settings

      • Simple Traffic Exchange.exe (PID: 2316)
      • Simple Traffic Exchange.exe (PID: 2504)
      • AppUpdater.exe (PID: 7468)
      • Simple Traffic Exchange.exe (PID: 7012)
    • Launch of the file from Downloads directory

      • firefox.exe (PID: 7296)
    • Application launched itself

      • firefox.exe (PID: 6208)
      • firefox.exe (PID: 7296)
    • Create files in a temporary directory

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • Reads CPU info

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • Process checks whether UAC notifications are on

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • Reads the time zone

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • Reads Environment values

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
    • Creates files in the program directory

      • mitmproxy-12.1.1-windows-x86_64-installer.exe (PID: 2320)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2014:04:06 08:36:16
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: browser/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
21
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe simple traffic exchange.exe simple traffic exchange.exe appupdater.exe slui.exe simple traffic exchange.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs mitmproxy-12.1.1-windows-x86_64-installer.exe no specs THREAT mitmproxy-12.1.1-windows-x86_64-installer.exe svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
1180"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5268 -childID 4 -isForBrowser -prefsHandle 5188 -prefMapHandle 5196 -prefsLen 31198 -prefMapSize 244583 -jsInitHandle 1432 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {02e67ff1-d466-40d4-b7bf-f06af8c0e1e7} 7296 "\\.\pipe\gecko-crash-server-pipe.7296" 2080549e150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2104"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Simple Traffic Exchange 140406.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2192"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5348 -childID 5 -isForBrowser -prefsHandle 4904 -prefMapHandle 5268 -prefsLen 31198 -prefMapSize 244583 -jsInitHandle 1432 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {11d67729-9815-4302-8e66-d3ccefd17e36} 7296 "\\.\pipe\gecko-crash-server-pipe.7296" 2080549e4d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140_1.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2316"C:\Users\admin\Desktop\Simple Traffic Exchange.exe" C:\Users\admin\Desktop\Simple Traffic Exchange.exe
explorer.exe
User:
admin
Company:
SilentProject™ Softwares
Integrity Level:
MEDIUM
Description:
Simple Traffic Exchange
Exit code:
0
Version:
1.2.11.0
Modules
Images
c:\users\admin\desktop\simple traffic exchange.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2320"C:\Users\admin\Downloads\mitmproxy-12.1.1-windows-x86_64-installer.exe" C:\Users\admin\Downloads\mitmproxy-12.1.1-windows-x86_64-installer.exe
firefox.exe
User:
admin
Company:
mitmproxy.org
Integrity Level:
HIGH
Version:
1.0.0.0
Modules
Images
c:\users\admin\downloads\mitmproxy-12.1.1-windows-x86_64-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2392"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5316 -childID 7 -isForBrowser -prefsHandle 5480 -prefMapHandle 5944 -prefsLen 31279 -prefMapSize 244583 -jsInitHandle 1432 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {1d0a2d41-0cec-4699-9af4-aa491968f356} 7296 "\\.\pipe\gecko-crash-server-pipe.7296" 2080549ea10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2504"C:\Users\admin\Desktop\Simple Traffic Exchange.exe" C:\Users\admin\Desktop\Simple Traffic Exchange.exe
explorer.exe
User:
admin
Company:
SilentProject™ Softwares
Integrity Level:
MEDIUM
Description:
Simple Traffic Exchange
Exit code:
0
Version:
1.2.11.0
Modules
Images
c:\users\admin\desktop\simple traffic exchange.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
3208"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2672 -childID 1 -isForBrowser -prefsHandle 2664 -prefMapHandle 2660 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1432 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {10e99fd6-cb9d-45af-90e3-e39e526d6a03} 7296 "\\.\pipe\gecko-crash-server-pipe.7296" 2080698ed90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
5504"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1872 -parentBuildID 20240213221259 -prefsHandle 1812 -prefMapHandle 1804 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d691053a-c74b-4e39-bf35-60f678689c60} 7296 "\\.\pipe\gecko-crash-server-pipe.7296" 2087f4e5b10 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
Total events
19 404
Read events
19 328
Write events
76
Delete events
0

Modification events

(PID) Process:(2104) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2104) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2104) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2104) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Simple Traffic Exchange 140406.zip
(PID) Process:(2104) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2104) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2104) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2104) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2104) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(2104) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
122
Suspicious files
192
Text files
139
Unknown types
0

Dropped files

PID
Process
Filename
Type
2104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2104.24236\browser\avutil-51.dllexecutable
MD5:156C7C1A4DB6321329E6E471AF03D875
SHA256:21E2621354129510CB5E66987B4BE82AAED8BBE580BE1E773E5154FFAEBEE377
2104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2104.24236\browser\Awesomium.Core.dllexecutable
MD5:FC130792958C1DF4DAD60444AC8BC9B8
SHA256:C951E1A89472CD0EEA98FB7CFD90FE7CD5031661D17582A4B8E2BF8A0510C2FA
2104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2104.24236\browser\Awesomium.Core.xmlxml
MD5:9BCA60DC2D0EBBA0A1F7D4EE5F24A9D1
SHA256:4B284137910967E8C57208260894079E885548573B9EA45451D143311CFC01DF
7296firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
2104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2104.24236\browser\libGLESv2.dllexecutable
MD5:C30613D790EF65B97B4C13B0D174E947
SHA256:FA5366CF056956C9432D4E015A2A22D2DA00E31D430AE7FFF1098528E5F395EC
2104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2104.24236\browser\icudt.dllexecutable
MD5:4E954C3073B930696146998A418A9A1D
SHA256:D617FA99A68296B2F50E0642334EFEAEA64AF89472F36535148097BCA91B312E
2104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2104.24236\browser\Awesomium.Windows.Forms.xmlxml
MD5:FAE007D9157B818B8A1EF0F230276A2C
SHA256:8E1A5B8D203090B420EAC8740A988F0A4C4C25A4F3EB486F9DF5101A73A47398
2104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2104.24236\browser\awesomium_processexecutable
MD5:127D9F855EFF85DE0D3726332C75B05A
SHA256:C0BCB00EFB95B896BA5D15044FCFEC1CE9EB2F5FF93538DD1A0E3254990DC52E
2104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2104.24236\browser\inspector.pakbinary
MD5:A0C2B038B70E857D05807B7AE3C6743A
SHA256:ED81A1AF5595A8BB0D1E14E42EC19B8146C0EC9BF840FE2B53A6B73AA90B9A3A
2104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2104.24236\browser\awesomium.dllexecutable
MD5:2E531B42893FEA9B1C957143625D9D30
SHA256:2242D632DC77CF84532BB5D9D6670B32105589927DD4E8DE3F134AF5062778C8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
95
DNS requests
117
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7296
firefox.exe
POST
200
172.217.23.99:80
http://o.pki.goog/we2
unknown
whitelisted
7296
firefox.exe
POST
200
172.217.23.99:80
http://o.pki.goog/we2
unknown
whitelisted
7296
firefox.exe
POST
200
172.217.23.99:80
http://o.pki.goog/we2
unknown
whitelisted
7296
firefox.exe
POST
200
184.24.77.67:80
http://r10.o.lencr.org/
unknown
whitelisted
7296
firefox.exe
POST
200
184.24.77.54:80
http://r11.o.lencr.org/
unknown
whitelisted
7296
firefox.exe
POST
200
172.217.23.99:80
http://o.pki.goog/we2
unknown
whitelisted
7296
firefox.exe
POST
200
172.217.23.99:80
http://o.pki.goog/we2
unknown
whitelisted
7296
firefox.exe
POST
200
172.217.23.99:80
http://o.pki.goog/we2
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.16.168.114:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
40.126.32.138:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2112
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 40.126.32.133
  • 40.126.32.138
  • 20.190.160.14
  • 40.126.32.68
  • 20.190.160.128
  • 40.126.32.76
  • 20.190.160.4
  • 20.190.160.131
whitelisted
google.com
  • 142.250.186.78
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.35.229.160
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
dl.dropboxusercontent.com
  • 162.125.65.15
whitelisted

Threats

PID
Process
Class
Message
2316
Simple Traffic Exchange.exe
Misc activity
ET INFO DropBox User Content Domain (dl .dropboxusercontent .com in TLS SNI)
2504
Simple Traffic Exchange.exe
Misc activity
ET INFO DropBox User Content Domain (dl .dropboxusercontent .com in TLS SNI)
7468
AppUpdater.exe
Misc activity
ET INFO DropBox User Content Domain (dl .dropboxusercontent .com in TLS SNI)
7012
Simple Traffic Exchange.exe
Misc activity
ET INFO DropBox User Content Domain (dl .dropboxusercontent .com in TLS SNI)
No debug info