File name:

CPUID HWMonitor Pro 1.53 (x64) + Patch.zip

Full analysis: https://app.any.run/tasks/23556373-5ef3-4544-8acc-5d804b516ec9
Verdict: Malicious activity
Analysis date: May 24, 2025, 00:06:05
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
inno
installer
delphi
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

E28AECEEAB0214567CBBBE9A27601A54

SHA1:

9DED618229DC2F6E60AF2D2AFFC2A2844DB9B3C2

SHA256:

1E69AE7FABF6467E011608B681C3CC4EFA9E4633C0710C053B4176709CA4D303

SSDEEP:

98304:OQzx4fAa/rfkNQFs1DcgoHuMOynYbsXgEI4nypvE4OVpzbqX9XNGodHBvUh+mNg6:miJm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7408)
    • Executing a file with an untrusted certificate

      • HWMonitorPro.exe (PID: 8108)
      • HWMonitorPro.exe (PID: 7596)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • hwmonitor-pro_1.53.exe (PID: 7356)
      • hwmonitor-pro_1.53.exe (PID: 5156)
      • hwmonitor-pro_1.53.tmp (PID: 4008)
      • Patch-HWMonitor.Pro.1.3x.exe (PID: 7412)
      • HWMonitorPro.exe (PID: 7596)
    • Reads security settings of Internet Explorer

      • hwmonitor-pro_1.53.tmp (PID: 7528)
    • Reads the Windows owner or organization settings

      • hwmonitor-pro_1.53.tmp (PID: 4008)
    • Application launched itself

      • WinRAR.exe (PID: 4212)
    • There is functionality for taking screenshot (YARA)

      • Patch-HWMonitor.Pro.1.3x.exe (PID: 7412)
    • Connects to unusual port

      • HWMonitorPro.exe (PID: 7596)
    • Drops a system driver (possible attempt to evade defenses)

      • HWMonitorPro.exe (PID: 7596)
  • INFO

    • Manual execution by a user

      • notepad.exe (PID: 5968)
      • hwmonitor-pro_1.53.exe (PID: 7356)
      • WinRAR.exe (PID: 4212)
      • HWMonitorPro.exe (PID: 8108)
      • Patch-HWMonitor.Pro.1.3x.exe (PID: 4112)
      • Patch-HWMonitor.Pro.1.3x.exe (PID: 7412)
      • HWMonitorPro.exe (PID: 7596)
    • Create files in a temporary directory

      • hwmonitor-pro_1.53.exe (PID: 7356)
      • hwmonitor-pro_1.53.exe (PID: 5156)
      • hwmonitor-pro_1.53.tmp (PID: 4008)
    • Checks supported languages

      • hwmonitor-pro_1.53.exe (PID: 7356)
      • hwmonitor-pro_1.53.tmp (PID: 7528)
      • hwmonitor-pro_1.53.exe (PID: 5156)
      • hwmonitor-pro_1.53.tmp (PID: 4008)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7408)
      • WinRAR.exe (PID: 6516)
    • Reads the computer name

      • hwmonitor-pro_1.53.tmp (PID: 7528)
      • hwmonitor-pro_1.53.tmp (PID: 4008)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 5968)
    • Process checks computer location settings

      • hwmonitor-pro_1.53.tmp (PID: 7528)
    • Reads the software policy settings

      • slui.exe (PID: 7580)
    • Detects InnoSetup installer (YARA)

      • hwmonitor-pro_1.53.exe (PID: 7356)
      • hwmonitor-pro_1.53.tmp (PID: 7528)
      • hwmonitor-pro_1.53.tmp (PID: 4008)
      • hwmonitor-pro_1.53.exe (PID: 5156)
    • Compiled with Borland Delphi (YARA)

      • hwmonitor-pro_1.53.tmp (PID: 7528)
      • hwmonitor-pro_1.53.tmp (PID: 4008)
    • Creates files in the program directory

      • hwmonitor-pro_1.53.tmp (PID: 4008)
    • The sample compiled with english language support

      • hwmonitor-pro_1.53.tmp (PID: 4008)
      • HWMonitorPro.exe (PID: 7596)
    • Creates a software uninstall entry

      • hwmonitor-pro_1.53.tmp (PID: 4008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:05:24 00:58:02
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: CPUID HWMonitor Pro 1.53 (x64) + Patch/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
164
Monitored processes
19
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe rundll32.exe no specs notepad.exe no specs hwmonitor-pro_1.53.exe hwmonitor-pro_1.53.tmp no specs hwmonitor-pro_1.53.exe hwmonitor-pro_1.53.tmp slui.exe shellexperiencehost.exe no specs rundll32.exe no specs Copy/Move/Rename/Delete/Link Object no specs winrar.exe no specs winrar.exe patch-hwmonitor.pro.1.3x.exe no specs patch-hwmonitor.pro.1.3x.exe hwmonitorpro.exe no specs hwmonitorpro.exe

Process information

PID
CMD
Path
Indicators
Parent process
1228C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2420C:\WINDOWS\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
4008"C:\Users\admin\AppData\Local\Temp\is-QPS4O.tmp\hwmonitor-pro_1.53.tmp" /SL5="$501E2,1664338,58368,C:\Users\admin\Desktop\CPUID HWMonitor Pro 1.53 (x64) + Patch\CPUID HWMonitor Pro 1.53 (x64) + Patch\Setup\hwmonitor-pro_1.53.exe" /SPAWNWND=$30160 /NOTIFYWND=$60260 C:\Users\admin\AppData\Local\Temp\is-QPS4O.tmp\hwmonitor-pro_1.53.tmp
hwmonitor-pro_1.53.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-qps4o.tmp\hwmonitor-pro_1.53.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4112"C:\Program Files\CPUID\HWMonitorPro\Patch-HWMonitor.Pro.1.3x.exe" C:\Program Files\CPUID\HWMonitorPro\Patch-HWMonitor.Pro.1.3x.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\program files\cpuid\hwmonitorpro\patch-hwmonitor.pro.1.3x.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4212"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Program Files\CPUID\HWMonitorPro\Patch.rar" "C:\Program Files\CPUID\HWMonitorPro\"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5156"C:\Users\admin\Desktop\CPUID HWMonitor Pro 1.53 (x64) + Patch\CPUID HWMonitor Pro 1.53 (x64) + Patch\Setup\hwmonitor-pro_1.53.exe" /SPAWNWND=$30160 /NOTIFYWND=$60260 C:\Users\admin\Desktop\CPUID HWMonitor Pro 1.53 (x64) + Patch\CPUID HWMonitor Pro 1.53 (x64) + Patch\Setup\hwmonitor-pro_1.53.exe
hwmonitor-pro_1.53.tmp
User:
admin
Company:
CPUID, Inc.
Integrity Level:
HIGH
Description:
CPUID HWMonitor Pro Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\cpuid hwmonitor pro 1.53 (x64) + patch\cpuid hwmonitor pro 1.53 (x64) + patch\setup\hwmonitor-pro_1.53.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5256C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
5968"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\CPUID HWMonitor Pro 1.53 (x64) + Patch\CPUID HWMonitor Pro 1.53 (x64) + Patch\Read Me.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
6516"C:\Program Files\WinRAR\WinRAR.exe" -elevate4212C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7356"C:\Users\admin\Desktop\CPUID HWMonitor Pro 1.53 (x64) + Patch\CPUID HWMonitor Pro 1.53 (x64) + Patch\Setup\hwmonitor-pro_1.53.exe" C:\Users\admin\Desktop\CPUID HWMonitor Pro 1.53 (x64) + Patch\CPUID HWMonitor Pro 1.53 (x64) + Patch\Setup\hwmonitor-pro_1.53.exe
explorer.exe
User:
admin
Company:
CPUID, Inc.
Integrity Level:
MEDIUM
Description:
CPUID HWMonitor Pro Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\cpuid hwmonitor pro 1.53 (x64) + patch\cpuid hwmonitor pro 1.53 (x64) + patch\setup\hwmonitor-pro_1.53.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
5 903
Read events
5 849
Write events
54
Delete events
0

Modification events

(PID) Process:(7408) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7408) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7408) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7408) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CPUID HWMonitor Pro 1.53 (x64) + Patch.zip
(PID) Process:(7408) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7408) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7408) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7408) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7408) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(7408) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
13
Suspicious files
18
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
7408WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7408.611\CPUID HWMonitor Pro 1.53 (x64) + Patch\CPUID HWMonitor Pro 1.53 (x64) + Patch\Read Me.txttext
MD5:9C2E5BF5A4B9428E703C77945EC81539
SHA256:B2CF726AD033BED3F5323AADEA997FFD1480DCF1CDF307E40AF3899396BC066E
7408WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7408.611\CPUID HWMonitor Pro 1.53 (x64) + Patch\Torrent Downloaded from Glodls.to.txttext
MD5:6F0F399B10783E29CD30D3B91ED37851
SHA256:44C5A1F0DC1219376B96745FC453AE44C7CE2ACEC0220E88E29E8B8E9DDA281D
7408WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7408.611\CPUID HWMonitor Pro 1.53 (x64) + Patch\CPUID HWMonitor Pro 1.53 (x64) + Patch\HaxNode.Net.urlurl
MD5:D2DBDD8CC5165FF6E4122B9F15B82EE9
SHA256:CB92547DBACFB6D6C102C2C0ED1D280C6AEA32210F280A85CE01BCEAC765C91E
7356hwmonitor-pro_1.53.exeC:\Users\admin\AppData\Local\Temp\is-76MVO.tmp\hwmonitor-pro_1.53.tmpexecutable
MD5:76C5633FDF19FDA1844AE72C27F21561
SHA256:3A170F6F800B582C67B9E3DB2BDB543D78F769D21D7FA9933E4C42C064A0B1B4
7408WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7408.611\CPUID HWMonitor Pro 1.53 (x64) + Patch\[TGx]Downloaded from torrentgalaxy.to .txttext
MD5:74A40DCFD6535544678651419DFA91B0
SHA256:2EC53F0009A499F171AADB6337BE20593072E516D4E97B94B1F9FC0FDF5D9389
7408WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7408.611\CPUID HWMonitor Pro 1.53 (x64) + Patch\CPUID HWMonitor Pro 1.53 (x64) + Patch\Patch\Patch.rarcompressed
MD5:023864E21DAFF51131BC1A291E327C85
SHA256:D2E3B714DF025D39F39627225E07EE020A228D9EE6A08F47806988D856D9D6D0
5156hwmonitor-pro_1.53.exeC:\Users\admin\AppData\Local\Temp\is-QPS4O.tmp\hwmonitor-pro_1.53.tmpexecutable
MD5:76C5633FDF19FDA1844AE72C27F21561
SHA256:3A170F6F800B582C67B9E3DB2BDB543D78F769D21D7FA9933E4C42C064A0B1B4
4008hwmonitor-pro_1.53.tmpC:\Program Files\CPUID\HWMonitorPro\unins000.exeexecutable
MD5:76C5633FDF19FDA1844AE72C27F21561
SHA256:3A170F6F800B582C67B9E3DB2BDB543D78F769D21D7FA9933E4C42C064A0B1B4
7408WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7408.611\CPUID HWMonitor Pro 1.53 (x64) + Patch\CPUID HWMonitor Pro 1.53 (x64) + Patch\Setup\hwmonitor-pro_1.53.exeexecutable
MD5:811644366616387AAAA93FC40FCE748C
SHA256:B582DC3F0D0B5D8AEFB53FAC00A9467481567410DD505B7324D9CEE2424D0FCD
4008hwmonitor-pro_1.53.tmpC:\Users\admin\AppData\Local\Temp\is-7CG7U.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
35
DNS requests
29
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8156
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7596
HWMonitorPro.exe
GET
200
184.24.77.67:80
http://e5.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQeEcDJrP2kU%2B9LL2pzIRVgTVStuQQUmc0pw6FYJq96ekyEWo9ziGCw394CEgXUpPdU%2FW8TIskaufODJXIgig%3D%3D
unknown
whitelisted
8156
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7920
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
7596
HWMonitorPro.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.42:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
2112
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.71
  • 20.190.159.129
  • 20.190.159.128
  • 40.126.31.128
  • 20.190.159.75
  • 40.126.31.1
  • 40.126.31.71
  • 20.190.160.20
  • 40.126.32.74
  • 20.190.160.128
  • 20.190.160.67
  • 40.126.32.140
  • 20.190.160.130
  • 20.190.160.2
  • 20.190.160.132
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info