File name:

hfs-exp-tool.exe

Full analysis: https://app.any.run/tasks/effb149b-22a2-49ab-802a-ddc4a927b240
Verdict: Malicious activity
Analysis date: January 11, 2025, 11:47:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-scr
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 15 sections
MD5:

1AD987183F79617A3D3F72183A087247

SHA1:

02398A6D93DA7E3F9C10C9608D894220BA2CC471

SHA256:

1ED380142382AF81527437DCD483E1B46F7308004E5657F3BDFB468730D542CF

SSDEEP:

98304:dkP1SRtKZ65l+6lm/WPIBaOh/brUSZhilgvZSCHsa9Gci10dF4wYZdRM6K1Ieho6:fwrmV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 4952)
  • SUSPICIOUS

    • Node.exe was dropped

      • WinRAR.exe (PID: 6244)
    • Executable content was dropped or overwritten

      • hfs.exe (PID: 3840)
    • Starts CMD.EXE for commands execution

      • hfs.exe (PID: 3840)
      • cmd.exe (PID: 5252)
      • NETSTAT.EXE (PID: 5308)
    • Get information on the list of running processes

      • hfs.exe (PID: 3840)
      • cmd.exe (PID: 5252)
      • cmd.exe (PID: 5460)
    • Uses ROUTE.EXE to obtain the routing table information

      • cmd.exe (PID: 2216)
    • Application launched itself

      • cmd.exe (PID: 5252)
    • Hides command output

      • cmd.exe (PID: 5252)
    • Starts application with an unusual extension

      • cmd.exe (PID: 5252)
    • Uses REG/REGEDIT.EXE to modify registry

      • hfs.exe (PID: 3840)
    • The process bypasses the loading of PowerShell profile settings

      • hfs.exe (PID: 3840)
    • BASE64 encoded PowerShell command has been detected

      • hfs.exe (PID: 3840)
    • Base64-obfuscated command line is found

      • hfs.exe (PID: 3840)
    • The process hide an interactive prompt from the user

      • hfs.exe (PID: 3840)
    • Starts POWERSHELL.EXE for commands execution

      • hfs.exe (PID: 3840)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 6244)
      • hfs.exe (PID: 3840)
      • WinRAR.exe (PID: 4716)
    • Checks supported languages

      • hfs-exp-tool.exe (PID: 6224)
      • hfs.exe (PID: 3840)
      • chcp.com (PID: 4528)
      • identity_helper.exe (PID: 6952)
    • Reads product name

      • hfs.exe (PID: 3840)
    • Reads Environment values

      • hfs.exe (PID: 3840)
      • identity_helper.exe (PID: 6952)
    • Process checks computer location settings

      • hfs.exe (PID: 3840)
    • Reads CPU info

      • hfs.exe (PID: 3840)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6244)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6244)
      • WinRAR.exe (PID: 4716)
    • Reads the computer name

      • hfs.exe (PID: 3840)
      • identity_helper.exe (PID: 6952)
    • Prints a route via ROUTE.EXE

      • ROUTE.EXE (PID: 5572)
    • Create files in a temporary directory

      • hfs.exe (PID: 3840)
    • Changes the display of characters in the console

      • cmd.exe (PID: 5252)
    • Application launched itself

      • msedge.exe (PID: 6740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 3
CodeSize: 2210816
InitializedDataSize: 203776
UninitializedDataSize: -
EntryPoint: 0x67ba0
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
182
Monitored processes
54
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start hfs-exp-tool.exe no specs conhost.exe no specs winrar.exe no specs rundll32.exe no specs winrar.exe no specs hfs.exe conhost.exe no specs cmd.exe no specs cmd.exe no specs netstat.exe no specs chcp.com no specs cmd.exe no specs route.exe no specs cmd.exe no specs tasklist.exe no specs powershell.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs tasklist.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs tasklist.exe no specs reg.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs tasklist.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
396C:\WINDOWS\system32\cmd.exe /d /s /c "netstat -rn"C:\Windows\System32\cmd.exehfs.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
524reg query HKCU\Software\Classes\*\shell\AddToHFS3C:\Windows\System32\reg.exehfs.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
828"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=5596 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1064"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2316 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1080tasklist /fi "imagename eq frpc.exe" /nhC:\Windows\System32\tasklist.exehfs.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1172"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6280 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1556"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2504 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1804"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --instant-process --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=28 --mojo-platform-channel-handle=6656 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2216C:\WINDOWS\system32\cmd.exe /c "C:\WINDOWS\system32\route.exe" printC:\Windows\System32\cmd.exeNETSTAT.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
2440"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=6156 --field-trial-handle=2320,i,13823084478036837108,2351939542753139108,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
9 904
Read events
9 859
Write events
45
Delete events
0

Modification events

(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6244) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4716) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4716) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4716) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4716) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4952) powershell.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4952) powershell.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
37
Suspicious files
606
Text files
104
Unknown types
0

Dropped files

PID
Process
Filename
Type
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\hfs.exe
MD5:
SHA256:
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\plugins\updater-disabled\plugin.jstext
MD5:2DDEF37982D534C71FB11E9BEAA8AFDA
SHA256:C3E5F612FC848055165E26D40F74B06425175B0776199C5958F75D6AD9CA68E0
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\plugins\download-counter\public\style.csstext
MD5:5CAA36FFB768350A9EFA37D51D2FB925
SHA256:2C5EEB787425D2453FD345B9025EF0363B76A4300B852C1B3A2B2095F3F2A39C
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\plugins\antibrute\plugin.jstext
MD5:7FBB2FC54A42D184E479F0CD3F54967F
SHA256:6899DDB93F0DFB480C393460D406686764ED77BE1012B7393F31ABDD11F37F10
6244WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\hfs-windows-x64-0.55.2.zipcompressed
MD5:389212E461D0DA8071EFA383C527BA0F
SHA256:A42B1E06C37441DFC08A8E73974158B4DC220E1DED433E3CFD2EC1DFDAAF9F32
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\plugins\download-counter\plugin.jstext
MD5:EFDF0AA3F878F8532B896A4223761FDF
SHA256:5592042209B265B73F93B28BE996E5387F2821ECBDC43A6C9960138BEE886EF3
3840hfs.exeC:\Users\admin\.cache\pkg\7d35e714e6ef15bd7731c514306e92c60e5c83f6f0c410756f6ba6ac7f969015\fswin\x64\fswin.nodeexecutable
MD5:51BA3036A393733AF680966AA3FF847F
SHA256:7D35E714E6EF15BD7731C514306E92C60E5C83F6F0C410756F6BA6AC7F969015
3840hfs.exeC:\Users\admin\.cache\pkg\7d35e714e6ef15bd7731c514306e92c60e5c83f6f0c410756f6ba6ac7f969015\fswin\package.jsonbinary
MD5:D39446E7C9FA0E7DF209D7E994C99043
SHA256:E94E4BA9D2F1F28490DB2E3ECBD6428B2EA3E4DE44767E331EAF3A82D9B37D4E
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\plugins\download-counter\public\main.jstext
MD5:6B1D1095E35A02864ACF63FA407590CA
SHA256:8B66A271FC37237E8385B805DE6F236C468B338B561ACE1156586EA076DA666D
4716WinRAR.exeC:\Users\admin\Desktop\最新版http搭建工具\plugins\list-uploader\plugin.jstext
MD5:C8626FBD639B192F447E4475423724C8
SHA256:15A1DF98E9293608381FC54258F102FF454DC2FCCCBF23CEF68D5771A1216980
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
91
DNS requests
123
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
188
svchost.exe
GET
200
2.16.164.24:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
188
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1228
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6908
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6908
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1556
msedge.exe
GET
304
23.192.153.142:80
http://r3.i.lencr.org/
unknown
whitelisted
1556
msedge.exe
GET
304
23.192.153.142:80
http://x1.i.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
188
svchost.exe
2.16.164.24:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
188
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.23.242.9:443
go.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
1176
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.24
  • 2.16.164.40
  • 2.16.164.32
  • 2.16.164.34
  • 2.16.164.18
  • 2.16.164.9
  • 2.16.164.97
  • 2.16.164.17
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.238
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
  • 104.126.37.185
  • 104.126.37.130
  • 104.126.37.144
  • 104.126.37.131
  • 104.126.37.137
  • 104.126.37.129
  • 104.126.37.128
  • 104.126.37.136
  • 104.126.37.178
  • 104.126.37.162
  • 104.126.37.145
  • 104.126.37.153
  • 104.126.37.139
  • 104.126.37.171
  • 104.126.37.160
  • 104.126.37.163
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.0
  • 20.190.159.2
  • 40.126.31.69
  • 20.190.159.73
  • 20.190.159.23
  • 20.190.159.4
  • 40.126.31.71
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

PID
Process
Class
Message
1556
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1556
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1556
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
1556
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
No debug info