File name:

hfs-exp-tool.exe

Full analysis: https://app.any.run/tasks/effb149b-22a2-49ab-802a-ddc4a927b240
Verdict: Malicious activity
Analysis date: January 11, 2025, 11:47:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-scr
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 15 sections
MD5:

1AD987183F79617A3D3F72183A087247

SHA1:

02398A6D93DA7E3F9C10C9608D894220BA2CC471

SHA256:

1ED380142382AF81527437DCD483E1B46F7308004E5657F3BDFB468730D542CF

SSDEEP:

98304:dkP1SRtKZ65l+6lm/WPIBaOh/brUSZhilgvZSCHsa9Gci10dF4wYZdRM6K1Ieho6:fwrmV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 4952)
  • SUSPICIOUS

    • Node.exe was dropped

      • WinRAR.exe (PID: 6244)
    • Executable content was dropped or overwritten

      • hfs.exe (PID: 3840)
    • Starts CMD.EXE for commands execution

      • hfs.exe (PID: 3840)
      • NETSTAT.EXE (PID: 5308)
      • cmd.exe (PID: 5252)
    • Hides command output

      • cmd.exe (PID: 5252)
    • Get information on the list of running processes

      • hfs.exe (PID: 3840)
      • cmd.exe (PID: 5252)
      • cmd.exe (PID: 5460)
    • Starts application with an unusual extension

      • cmd.exe (PID: 5252)
    • The process bypasses the loading of PowerShell profile settings

      • hfs.exe (PID: 3840)
    • Uses ROUTE.EXE to obtain the routing table information

      • cmd.exe (PID: 2216)
    • Application launched itself

      • cmd.exe (PID: 5252)
    • BASE64 encoded PowerShell command has been detected

      • hfs.exe (PID: 3840)
    • The process hide an interactive prompt from the user

      • hfs.exe (PID: 3840)
    • Base64-obfuscated command line is found

      • hfs.exe (PID: 3840)
    • Starts POWERSHELL.EXE for commands execution

      • hfs.exe (PID: 3840)
    • Uses REG/REGEDIT.EXE to modify registry

      • hfs.exe (PID: 3840)
  • INFO

    • Checks supported languages

      • hfs-exp-tool.exe (PID: 6224)
      • hfs.exe (PID: 3840)
      • chcp.com (PID: 4528)
      • identity_helper.exe (PID: 6952)
    • Manual execution by a user

      • WinRAR.exe (PID: 4716)
      • WinRAR.exe (PID: 6244)
      • hfs.exe (PID: 3840)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6244)
      • WinRAR.exe (PID: 4716)
    • Reads product name

      • hfs.exe (PID: 3840)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6244)
    • Reads Environment values

      • hfs.exe (PID: 3840)
      • identity_helper.exe (PID: 6952)
    • Process checks computer location settings

      • hfs.exe (PID: 3840)
    • Reads CPU info

      • hfs.exe (PID: 3840)
    • Reads the computer name

      • hfs.exe (PID: 3840)
      • identity_helper.exe (PID: 6952)
    • Changes the display of characters in the console

      • cmd.exe (PID: 5252)
    • Prints a route via ROUTE.EXE

      • ROUTE.EXE (PID: 5572)
    • Create files in a temporary directory

      • hfs.exe (PID: 3840)
    • Application launched itself

      • msedge.exe (PID: 6740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 3
CodeSize: 2210816
InitializedDataSize: 203776
UninitializedDataSize: -
EntryPoint: 0x67ba0
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
182
Monitored processes
54
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start hfs-exp-tool.exe no specs conhost.exe no specs winrar.exe no specs rundll32.exe no specs winrar.exe no specs hfs.exe conhost.exe no specs cmd.exe no specs cmd.exe no specs netstat.exe no specs chcp.com no specs cmd.exe no specs route.exe no specs cmd.exe no specs tasklist.exe no specs powershell.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs tasklist.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs tasklist.exe no specs reg.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs tasklist.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
396C:\WINDOWS\system32\cmd.exe /d /s /c "netstat -rn"C:\Windows\System32\cmd.exehfs.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
524reg query HKCU\Software\Classes\*\shell\AddToHFS3C:\Windows\System32\reg.exehfs.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
828"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=5596 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1064"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2316 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1080tasklist /fi "imagename eq frpc.exe" /nhC:\Windows\System32\tasklist.exehfs.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1172"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6280 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1556"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2504 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1804"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --instant-process --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=28 --mojo-platform-channel-handle=6656 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2216C:\WINDOWS\system32\cmd.exe /c "C:\WINDOWS\system32\route.exe" printC:\Windows\System32\cmd.exeNETSTAT.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
2440"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=6156 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
9 904
Read events
9 859
Write events
45
Delete events
0

Modification events

(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4716) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4716) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4716) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4716) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4952) powershell.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4952) powershell.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
37
Suspicious files
606
Text files
104
Unknown types
0

Dropped files

PID
Process
Filename
Type
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\hfs.exe
MD5:
SHA256:
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\plugins\list-uploader\plugin.jstext
MD5:C8626FBD639B192F447E4475423724C8
SHA256:15A1DF98E9293608381FC54258F102FF454DC2FCCCBF23CEF68D5771A1216980
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\plugins\download-counter\public\main.jstext
MD5:6B1D1095E35A02864ACF63FA407590CA
SHA256:8B66A271FC37237E8385B805DE6F236C468B338B561ACE1156586EA076DA666D
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\plugins\download-counter\plugin.jstext
MD5:EFDF0AA3F878F8532B896A4223761FDF
SHA256:5592042209B265B73F93B28BE996E5387F2821ECBDC43A6C9960138BEE886EF3
6244WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\说明.txttext
MD5:D27800BEE101995E8F5E3DB33E96896B
SHA256:8D3589FD529D0B678A069B695F33EF0ECA67885E7B94A74AF0A0552443940185
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\plugins\antibrute\plugin.jstext
MD5:7FBB2FC54A42D184E479F0CD3F54967F
SHA256:6899DDB93F0DFB480C393460D406686764ED77BE1012B7393F31ABDD11F37F10
3840hfs.exeC:\Users\admin\.cache\pkg\7d35e714e6ef15bd7731c514306e92c60e5c83f6f0c410756f6ba6ac7f969015\fswin\x64\fswin.nodeexecutable
MD5:51BA3036A393733AF680966AA3FF847F
SHA256:7D35E714E6EF15BD7731C514306E92C60E5C83F6F0C410756F6BA6AC7F969015
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\plugins\updater-disabled\plugin.jstext
MD5:2DDEF37982D534C71FB11E9BEAA8AFDA
SHA256:C3E5F612FC848055165E26D40F74B06425175B0776199C5958F75D6AD9CA68E0
3840hfs.exeC:\Users\admin\AppData\Local\Temp\pkg-wl2pS4\da45b7c852a9360681168b6ae7cd451a927b6941bf74f039aedc187e7c73f2f8executable
MD5:51BA3036A393733AF680966AA3FF847F
SHA256:7D35E714E6EF15BD7731C514306E92C60E5C83F6F0C410756F6BA6AC7F969015
3840hfs.exeC:\Users\admin\AppData\Local\Temp\pkg-wl2pS4\e94e4ba9d2f1f28490db2e3ecbd6428b2ea3e4de44767e331eaf3a82d9b37d4ebinary
MD5:D39446E7C9FA0E7DF209D7E994C99043
SHA256:E94E4BA9D2F1F28490DB2E3ECBD6428B2EA3E4DE44767E331EAF3A82D9B37D4E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
91
DNS requests
123
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
188
svchost.exe
GET
200
2.16.164.24:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
188
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6908
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6908
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1556
msedge.exe
GET
304
23.192.153.142:80
http://r3.i.lencr.org/
unknown
whitelisted
1228
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1556
msedge.exe
GET
304
23.192.153.142:80
http://x1.i.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
188
svchost.exe
2.16.164.24:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
188
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.23.242.9:443
go.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
1176
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.24
  • 2.16.164.40
  • 2.16.164.32
  • 2.16.164.34
  • 2.16.164.18
  • 2.16.164.9
  • 2.16.164.97
  • 2.16.164.17
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.238
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
  • 104.126.37.185
  • 104.126.37.130
  • 104.126.37.144
  • 104.126.37.131
  • 104.126.37.137
  • 104.126.37.129
  • 104.126.37.128
  • 104.126.37.136
  • 104.126.37.178
  • 104.126.37.162
  • 104.126.37.145
  • 104.126.37.153
  • 104.126.37.139
  • 104.126.37.171
  • 104.126.37.160
  • 104.126.37.163
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.0
  • 20.190.159.2
  • 40.126.31.69
  • 20.190.159.73
  • 20.190.159.23
  • 20.190.159.4
  • 40.126.31.71
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

PID
Process
Class
Message
1556
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1556
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1556
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
1556
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
No debug info