File name:

advisorinstaller.exe

Full analysis: https://app.any.run/tasks/6fbee45b-2582-4daf-a4ee-18180ed7147b
Verdict: Malicious activity
Analysis date: January 14, 2025, 18:47:06
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

952B1665A671E4A29E4AEBA66433C890

SHA1:

3C86180E72EBAFC465EBD84838814A35C017C58C

SHA256:

1FBE239B724C48DB37098E45671EBE9ABD57ACB21801EBA88ED5B1475D37C206

SSDEEP:

98304:jCB20TtTZMZdk1Wcv9PLVA3R7t9OeGlkxfuKtvVoieNCDAvxo1XR5w8pgC4msI/7:iCoRuN2/K

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Searches for installed software

      • advisorinstaller.exe (PID: 6616)
    • Reads security settings of Internet Explorer

      • advisorinstaller.exe (PID: 6616)
      • BelarcAdvisor.exe (PID: 556)
    • Starts application with an unusual extension

      • advisorinstaller.exe (PID: 6616)
    • Creates/Modifies COM task schedule object

      • GLJ8699.tmp (PID: 6228)
    • Creates a software uninstall entry

      • advisorinstaller.exe (PID: 6616)
    • Executable content was dropped or overwritten

      • advisorinstaller.exe (PID: 6616)
    • Reads the date of Windows installation

      • BelarcAdvisor.exe (PID: 556)
    • Checks Windows Trust Settings

      • BelarcAdvisor.exe (PID: 556)
  • INFO

    • Reads the computer name

      • advisorinstaller.exe (PID: 6616)
      • BelarcAdvisor.exe (PID: 556)
      • GLJ8699.tmp (PID: 6228)
    • Checks supported languages

      • GLJ8699.tmp (PID: 6228)
      • advisorinstaller.exe (PID: 6616)
      • BelarcAdvisor.exe (PID: 556)
    • Creates files in the program directory

      • advisorinstaller.exe (PID: 6616)
      • BelarcAdvisor.exe (PID: 556)
    • Process checks whether UAC notifications are on

      • BelarcAdvisor.exe (PID: 556)
    • Process checks computer location settings

      • advisorinstaller.exe (PID: 6616)
    • Reads the machine GUID from the registry

      • BelarcAdvisor.exe (PID: 556)
    • Reads the software policy settings

      • BelarcAdvisor.exe (PID: 556)
    • Creates files or folders in the user directory

      • advisorinstaller.exe (PID: 6616)
      • BelarcAdvisor.exe (PID: 556)
    • The sample compiled with english language support

      • advisorinstaller.exe (PID: 6616)
    • Create files in a temporary directory

      • advisorinstaller.exe (PID: 6616)
    • Checks proxy server information

      • BelarcAdvisor.exe (PID: 556)
    • Reads Windows Product ID

      • BelarcAdvisor.exe (PID: 556)
    • Reads Environment values

      • BelarcAdvisor.exe (PID: 556)
    • Manual execution by a user

      • firefox.exe (PID: 1744)
    • Application launched itself

      • firefox.exe (PID: 1744)
      • firefox.exe (PID: 5728)
    • Reads product name

      • BelarcAdvisor.exe (PID: 556)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (86.4)
.exe | Win32 Executable MS Visual C++ (generic) (5.7)
.exe | Win64 Executable (generic) (5)
.dll | Win32 Dynamic Link Library (generic) (1.2)
.exe | Win32 Executable (generic) (0.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:08:13 17:13:38+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap
PEType: PE32
LinkerVersion: 6
CodeSize: 8704
InitializedDataSize: 6144
UninitializedDataSize: -
EntryPoint: 0x21af
OSVersion: 4
ImageVersion: 4
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 12.1.0.0
ProductVersionNumber: 12.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Belarc, Inc.
FileDescription: Belarc Advisor Installer
FileVersion: 12.1
LegalCopyright: Copyright (c) 1997-2023 Belarc, Inc.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
159
Monitored processes
31
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start advisorinstaller.exe glj8699.tmp no specs belarcadvisor.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs advisorinstaller.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
556"C:\PROGRA~2\Belarc\BELARC~1\BELARC~1.EXE" C:\Program Files (x86)\Belarc\BelarcAdvisor\BelarcAdvisor.exe
advisorinstaller.exe
User:
admin
Company:
Belarc, Inc.
Integrity Level:
HIGH
Description:
Belarc Advisor Computer Inventory
Version:
12.1
Modules
Images
c:\program files (x86)\belarc\belarcadvisor\belarcadvisor.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1344"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4960 -childID 5 -isForBrowser -prefsHandle 5116 -prefMapHandle 5112 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {84cf9aa4-f0ce-48d7-8ef0-bf19c1ad89a0} 5728 "\\.\pipe\gecko-crash-server-pipe.5728" 252cb714f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1616"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5312 -childID 7 -isForBrowser -prefsHandle 4968 -prefMapHandle 5124 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a5c5bf39-2e06-4ac8-89ce-bfa660df2ff5} 5728 "\\.\pipe\gecko-crash-server-pipe.5728" 252d069a310 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1744"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\crypt32.dll
1916"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2100 -childID 3 -isForBrowser -prefsHandle 4856 -prefMapHandle 4296 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ac28b9c7-b59d-4e13-9754-941b67ad0f31} 5728 "\\.\pipe\gecko-crash-server-pipe.5728" 252ce0c8f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140_1.dll
2084"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1412 -childID 4 -isForBrowser -prefsHandle 4576 -prefMapHandle 2972 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {147f1f52-0c06-4ba1-a8cf-813d97df3b4d} 5728 "\\.\pipe\gecko-crash-server-pipe.5728" 252cf1a6a10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\msvcp140.dll
2096"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5068 -childID 18 -isForBrowser -prefsHandle 5080 -prefMapHandle 5084 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {5b042341-4ff1-423b-ae59-ebb46e3d89f0} 5728 "\\.\pipe\gecko-crash-server-pipe.5728" 252d1303690 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2728"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5992 -childID 15 -isForBrowser -prefsHandle 5896 -prefMapHandle 5900 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {e849dec9-5cad-470d-9044-67a56eca8666} 5728 "\\.\pipe\gecko-crash-server-pipe.5728" 252d1303d90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3656"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5436 -childID 9 -isForBrowser -prefsHandle 5428 -prefMapHandle 5424 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {0879a7f2-4594-4003-9a5b-67bc6a63ee07} 5728 "\\.\pipe\gecko-crash-server-pipe.5728" 252d069a690 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3688"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1900 -parentBuildID 20240213221259 -prefsHandle 1820 -prefMapHandle 1812 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fd05fd79-cbf5-4967-93f7-2f095567e0fc} 5728 "\\.\pipe\gecko-crash-server-pipe.5728" 252c6feba10 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
Total events
22 655
Read events
22 604
Write events
51
Delete events
0

Modification events

(PID) Process:(6616) advisorinstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bci
Operation:writeName:Content Type
Value:
application/vnd.belarc-bci
(PID) Process:(6616) advisorinstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/vnd.belarc-bci
Operation:writeName:Extension
Value:
.bci
(PID) Process:(6616) advisorinstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Belarc\Advisor
Operation:writeName:UuidMethod
Value:
0
(PID) Process:(6616) advisorinstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Belarc\Advisor
Operation:writeName:Computer ID
Value:
0
(PID) Process:(6616) advisorinstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Belarc\Advisor
Operation:writeName:Test2
Value:
(PID) Process:(6616) advisorinstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Belarc\Advisor
Operation:writeName:ShowNtAdminMessage
Value:
1
(PID) Process:(6616) advisorinstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Belarc Advisor
Operation:writeName:DisplayName
Value:
Belarc Advisor 12.1
(PID) Process:(6616) advisorinstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Belarc Advisor
Operation:writeName:Publisher
Value:
Belarc, Inc.
(PID) Process:(6616) advisorinstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Belarc Advisor
Operation:writeName:DisplayVersion
Value:
12.1.0.0
(PID) Process:(6616) advisorinstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Belarc Advisor
Operation:writeName:HelpLink
Value:
https://www.belarc.com/download.html#faq
Executable files
14
Suspicious files
69
Text files
255
Unknown types
0

Dropped files

PID
Process
Filename
Type
6616advisorinstaller.exeC:\Users\admin\AppData\Local\Temp\GLC8521.tmpexecutable
MD5:09E59D00DF5D2EFFD8DD9B30385CB9D2
SHA256:1C574EAB5E83CCFE5A0BB7B59E028CC5FA2F4E77868051E305D83C709711FF77
6616advisorinstaller.exeC:\Users\admin\AppData\Local\Temp\GLF9254.tmpexecutable
MD5:9DA8F742593D4BBCA708B90725282AE2
SHA256:E362A9815527869E0F71FDF766A1C3648E307145DEFDA7A5279914E522BCB57C
6616advisorinstaller.exeC:\Users\admin\AppData\Local\Temp\BAlicense.txttext
MD5:D77843630B0A4A6C6569EBF9498E970D
SHA256:70EA020C345734C1BB308963DE62A97732D8AE143CAFB4706E85EDA1936513AA
6616advisorinstaller.exeC:\Users\admin\AppData\Local\Temp\~GLH0001.TMPtext
MD5:D77843630B0A4A6C6569EBF9498E970D
SHA256:70EA020C345734C1BB308963DE62A97732D8AE143CAFB4706E85EDA1936513AA
6616advisorinstaller.exeC:\Program Files (x86)\Belarc\BelarcAdvisor\System\NPBelv32.dllexecutable
MD5:36117B5809DDC19C3B0DA4DF57D41774
SHA256:9D381D28E02107C49005EF6487203F9C742411A981E78D4218A7B22D72E48847
6616advisorinstaller.exeC:\Users\admin\AppData\Local\Temp\GLJ8699.tmpexecutable
MD5:6F608D264503796BEBD7CD66B687BE92
SHA256:49833D2820AFB1D7409DFBD916480F2CDF5787D2E2D94166725BEB9064922D5D
6616advisorinstaller.exeC:\Users\admin\AppData\Local\Temp\~GLH0000.TMPexecutable
MD5:9DA8F742593D4BBCA708B90725282AE2
SHA256:E362A9815527869E0F71FDF766A1C3648E307145DEFDA7A5279914E522BCB57C
6616advisorinstaller.exeC:\Program Files (x86)\Belarc\BelarcAdvisor\System\~GLH0002.TMPexecutable
MD5:36117B5809DDC19C3B0DA4DF57D41774
SHA256:9D381D28E02107C49005EF6487203F9C742411A981E78D4218A7B22D72E48847
6616advisorinstaller.exeC:\Program Files (x86)\Belarc\BelarcAdvisor\BelarcAdvisor.exeexecutable
MD5:23B1AFC68EA87B108D1B85C6F0CBFF2B
SHA256:43E9E2551BEAA2B7204AF2C6DE9D1890656C41137B83BE01C1515465D9B5356A
6616advisorinstaller.exeC:\Program Files (x86)\Belarc\BelarcAdvisor\~GLH0003.TMPexecutable
MD5:23B1AFC68EA87B108D1B85C6F0CBFF2B
SHA256:43E9E2551BEAA2B7204AF2C6DE9D1890656C41137B83BE01C1515465D9B5356A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
57
DNS requests
59
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5728
firefox.exe
POST
200
195.138.255.24:80
http://r10.o.lencr.org/
unknown
whitelisted
5728
firefox.exe
POST
200
195.138.255.24:80
http://r10.o.lencr.org/
unknown
whitelisted
5728
firefox.exe
POST
200
195.138.255.24:80
http://r10.o.lencr.org/
unknown
whitelisted
5728
firefox.exe
POST
200
142.250.186.99:80
http://o.pki.goog/wr2
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7092
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2396
svchost.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7092
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
556
BelarcAdvisor.exe
GET
200
18.66.145.213:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2396
svchost.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2.16.110.123:443
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.176
  • 23.48.23.164
  • 23.48.23.173
  • 23.48.23.159
  • 23.48.23.150
  • 23.48.23.166
  • 23.48.23.162
  • 23.48.23.158
  • 23.48.23.167
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
google.com
  • 142.250.184.206
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
login.live.com
  • 20.190.159.0
  • 40.126.31.73
  • 20.190.159.23
  • 40.126.31.71
  • 40.126.31.67
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.73
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
www.belarc.com
  • 54.156.112.248
  • 3.226.150.129
whitelisted

Threats

No threats detected
No debug info