File name:

Remover-Virus-Acceso-Directo(By Pixel4brain.com).zip

Full analysis: https://app.any.run/tasks/2596f1a0-59be-4ddb-9c7d-e06ac9b7ec89
Verdict: Malicious activity
Analysis date: August 08, 2024, 21:49:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

42510139D773823A103A7B35BB207BF5

SHA1:

774BCCF0A241FFEDEC3D74602E3D88CAF1BE281E

SHA256:

1FCA7814AD5A9F1E2F361B1BE30EC5B6737A1D3A79E836C6E081C80CB2A1CFC7

SSDEEP:

98304:pU1E6+cYcA7IW6kLYvOHR6VXMDuBQMITyJf3fwOgs/hwc7qfAB3xuh0UWEz5XqTc:PBuCi6to8SXUjT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • UsbFix.exe (PID: 4296)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 6252)
      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
      • UsbFix_9.018.exe (PID: 5880)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6252)
      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • UsbFix.exe (PID: 4296)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
    • Executable content was dropped or overwritten

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
      • UsbFix_9.018.exe (PID: 5880)
    • Reads the date of Windows installation

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
    • Checks Windows Trust Settings

      • UsbFix.exe (PID: 4296)
    • Contacting a server suspected of hosting an CnC

      • UsbFix.exe (PID: 4296)
    • Creates a software uninstall entry

      • UsbFix_9.018.exe (PID: 5880)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6252)
    • Reads mouse settings

      • UsbFix.exe (PID: 4296)
    • Reads the computer name

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • UsbFix.exe (PID: 4296)
      • identity_helper.exe (PID: 7368)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
      • Shortcut Virus Remover v3.1.exe (PID: 4004)
      • Shortcut Virus Remover v3.1.exe (PID: 6532)
    • Checks supported languages

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • Shortcut Virus Remover v3.1.exe (PID: 6532)
      • identity_helper.exe (PID: 7368)
      • Shortcut Virus Remover v3.1.exe (PID: 4004)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
      • UsbFix_9.018.exe (PID: 5880)
      • UsbFix.exe (PID: 4296)
    • Create files in a temporary directory

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • Shortcut Virus Remover v3.1.exe (PID: 6532)
      • UsbFix.exe (PID: 4296)
      • Shortcut Virus Remover v3.1.exe (PID: 4004)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
    • Process checks computer location settings

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
    • Checks proxy server information

      • UsbFix.exe (PID: 4296)
    • Reads the software policy settings

      • UsbFix.exe (PID: 4296)
    • Reads the machine GUID from the registry

      • UsbFix.exe (PID: 4296)
    • Creates files or folders in the user directory

      • UsbFix.exe (PID: 4296)
    • Reads Environment values

      • UsbFix.exe (PID: 4296)
      • identity_helper.exe (PID: 7368)
    • Reads Microsoft Office registry keys

      • UsbFix.exe (PID: 4296)
      • msedge.exe (PID: 7576)
      • msedge.exe (PID: 1556)
      • msedge.exe (PID: 6540)
    • Manual execution by a user

      • msedge.exe (PID: 6540)
    • Application launched itself

      • msedge.exe (PID: 7576)
      • msedge.exe (PID: 1556)
      • msedge.exe (PID: 6540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0002
ZipCompression: Deflated
ZipModifyDate: 2014:09:29 07:02:58
ZipCRC: 0xfdf0abdb
ZipCompressedSize: 515667
ZipUncompressedSize: 806717
ZipFileName: Shortcut Virus Remover v3.1.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
183
Monitored processes
47
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe shortcut virus remover v3.1.exe shortcut virus remover v3.1.exe no specs usbfix_9.018.exe no specs usbfix_9.018.exe usbfix.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs shortcut virus remover v3.1.exe shortcut virus remover v3.1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048"C:\Users\admin\AppData\Local\Temp\Rar$EXa6252.12671\Shortcut Virus Remover v3.1.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6252.12671\Shortcut Virus Remover v3.1.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6252.12671\shortcut virus remover v3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1556"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument microsoft-edge:https://www.usb-antivirus.com/C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeUsbFix.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1964"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3464 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2508"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4208 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2960"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5228 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2992"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3636 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3028"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2548 --field-trial-handle=2424,i,4636854826946629428,8461202765441588517,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4004"C:\Users\admin\AppData\Local\Temp\RarSFX0\Shortcut Virus Remover v3.1.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\Shortcut Virus Remover v3.1.exeShortcut Virus Remover v3.1.exe
User:
admin
Company:
Cyber X
Integrity Level:
MEDIUM
Description:
Shortcut Virus Remover
Exit code:
0
Version:
3.01.0012
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\shortcut virus remover v3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4080"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2116 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4236"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2416 --field-trial-handle=2424,i,4636854826946629428,8461202765441588517,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
33 678
Read events
33 432
Write events
235
Delete events
11

Modification events

(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Remover-Virus-Acceso-Directo(By Pixel4brain.com).zip
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
18
Suspicious files
149
Text files
198
Unknown types
1

Dropped files

PID
Process
Filename
Type
6444Shortcut Virus Remover v3.1.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\pskill.exeexecutable
MD5:6F2F60AF33A5CAF03E1D0AC81A2DE892
SHA256:ED8F3C368BA229043C8ACEF7AE4F4A0FDE62BF39FCE51522916B7DCE1E837F71
6252WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6252.9458\Shortcut Virus Remover v3.1.exeexecutable
MD5:BC1C264165EC26EDA413024AE079341E
SHA256:83C9829FB99DCB4A61BCFD6ECDF22791E1589418C26A2AA51B676EFFFC0B988E
6252WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6252.9458\UsbFix_9.018.exeexecutable
MD5:7F72C1915DC932065294F62C96B8A79F
SHA256:CCE20E86DF16B3853E0AFA5E623F6B1E628FED3958B669A322345BF6D9C5BD77
6444Shortcut Virus Remover v3.1.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\Shortcut Virus Remover v3.1.exeexecutable
MD5:A9FEC8AD17B80EF7C3D3A142BF58CBB2
SHA256:B898EF094D66880BA27AFE8B4C61950059EB6B403832776FBE067F3B1D9DA49F
6252WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6252.10763\UsbFix_9.018.exeexecutable
MD5:7F72C1915DC932065294F62C96B8A79F
SHA256:CCE20E86DF16B3853E0AFA5E623F6B1E628FED3958B669A322345BF6D9C5BD77
6532Shortcut Virus Remover v3.1.exeC:\Users\admin\AppData\Local\Temp\~DFC1B8BC3FD2C0EA97.TMPbinary
MD5:2416B0A4F94219CA2190FFAD8D442E0E
SHA256:A9EEB8EE2EB97E0A2AD878F31A608D9BCF329872F45F8CADF7DA352E989B5C82
5880UsbFix_9.018.exeC:\UsbFix\Res\Apply2.jpgimage
MD5:1D2DBB4273A5E717BC50D0485C8325F1
SHA256:83608235287DF83712530EF2526269BB88929E7C042AA47A3BB51E209F18D7DC
5880UsbFix_9.018.exeC:\UsbFix\Res\AutoClean.pngimage
MD5:5DFE56A16FEF1C0599426F575B3BF707
SHA256:4959DAE2F8CB8494D09BD8771B1CB8205ECE92DB2BE85BC86468ADE1CB7DD3ED
5880UsbFix_9.018.exeC:\UsbFix\Res\Angle2.pngimage
MD5:EC7B1BC95DA3B18F18ACB18EE157947D
SHA256:409398A8701008AEF28D844FADADB99802205A51F0643FB759736BDE6AB72C90
5880UsbFix_9.018.exeC:\UsbFix\Res\Angle.pngimage
MD5:41108867BA519CA76C88711DCE4FBFF0
SHA256:58A56E197655D53886EA7BB483B21EE25E1B852925BF39D4A8393C4E8378695B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
75
DNS requests
73
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5484
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5484
svchost.exe
GET
304
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6672
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6712
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4056
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3972
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
4056
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5336
SearchApp.exe
104.126.37.155:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5484
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.46
whitelisted
www.bing.com
  • 104.126.37.155
  • 104.126.37.160
  • 104.126.37.153
  • 104.126.37.144
  • 104.126.37.139
  • 104.126.37.163
  • 104.126.37.161
  • 104.126.37.171
  • 104.126.37.184
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.4
  • 20.190.159.64
  • 40.126.31.71
  • 20.190.159.68
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.75
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
th.bing.com
  • 104.126.37.184
  • 104.126.37.155
  • 104.126.37.160
  • 104.126.37.153
  • 104.126.37.144
  • 104.126.37.139
  • 104.126.37.163
  • 104.126.37.161
  • 104.126.37.171
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
www.usb-antivirus.com
  • 109.234.162.139
unknown

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info