File name:

Remover-Virus-Acceso-Directo(By Pixel4brain.com).zip

Full analysis: https://app.any.run/tasks/2596f1a0-59be-4ddb-9c7d-e06ac9b7ec89
Verdict: Malicious activity
Analysis date: August 08, 2024, 21:49:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

42510139D773823A103A7B35BB207BF5

SHA1:

774BCCF0A241FFEDEC3D74602E3D88CAF1BE281E

SHA256:

1FCA7814AD5A9F1E2F361B1BE30EC5B6737A1D3A79E836C6E081C80CB2A1CFC7

SSDEEP:

98304:pU1E6+cYcA7IW6kLYvOHR6VXMDuBQMITyJf3fwOgs/hwc7qfAB3xuh0UWEz5XqTc:PBuCi6to8SXUjT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • UsbFix.exe (PID: 4296)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6252)
      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • UsbFix.exe (PID: 4296)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 6252)
      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • UsbFix_9.018.exe (PID: 5880)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
    • Executable content was dropped or overwritten

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • UsbFix_9.018.exe (PID: 5880)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
    • Reads the date of Windows installation

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
    • Checks Windows Trust Settings

      • UsbFix.exe (PID: 4296)
    • Contacting a server suspected of hosting an CnC

      • UsbFix.exe (PID: 4296)
    • Creates a software uninstall entry

      • UsbFix_9.018.exe (PID: 5880)
  • INFO

    • Checks supported languages

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • Shortcut Virus Remover v3.1.exe (PID: 6532)
      • UsbFix_9.018.exe (PID: 5880)
      • UsbFix.exe (PID: 4296)
      • identity_helper.exe (PID: 7368)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
      • Shortcut Virus Remover v3.1.exe (PID: 4004)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6252)
    • Reads the computer name

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • Shortcut Virus Remover v3.1.exe (PID: 6532)
      • UsbFix.exe (PID: 4296)
      • identity_helper.exe (PID: 7368)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
      • Shortcut Virus Remover v3.1.exe (PID: 4004)
    • Create files in a temporary directory

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • Shortcut Virus Remover v3.1.exe (PID: 6532)
      • UsbFix.exe (PID: 4296)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
      • Shortcut Virus Remover v3.1.exe (PID: 4004)
    • Process checks computer location settings

      • Shortcut Virus Remover v3.1.exe (PID: 6444)
      • Shortcut Virus Remover v3.1.exe (PID: 1048)
    • Checks proxy server information

      • UsbFix.exe (PID: 4296)
    • Reads the machine GUID from the registry

      • UsbFix.exe (PID: 4296)
    • Reads the software policy settings

      • UsbFix.exe (PID: 4296)
    • Reads Environment values

      • UsbFix.exe (PID: 4296)
      • identity_helper.exe (PID: 7368)
    • Creates files or folders in the user directory

      • UsbFix.exe (PID: 4296)
    • Reads Microsoft Office registry keys

      • UsbFix.exe (PID: 4296)
      • msedge.exe (PID: 7576)
      • msedge.exe (PID: 1556)
      • msedge.exe (PID: 6540)
    • Application launched itself

      • msedge.exe (PID: 1556)
      • msedge.exe (PID: 7576)
      • msedge.exe (PID: 6540)
    • Reads mouse settings

      • UsbFix.exe (PID: 4296)
    • Manual execution by a user

      • msedge.exe (PID: 6540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0002
ZipCompression: Deflated
ZipModifyDate: 2014:09:29 07:02:58
ZipCRC: 0xfdf0abdb
ZipCompressedSize: 515667
ZipUncompressedSize: 806717
ZipFileName: Shortcut Virus Remover v3.1.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
183
Monitored processes
47
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe shortcut virus remover v3.1.exe shortcut virus remover v3.1.exe no specs usbfix_9.018.exe no specs usbfix_9.018.exe usbfix.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs shortcut virus remover v3.1.exe shortcut virus remover v3.1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048"C:\Users\admin\AppData\Local\Temp\Rar$EXa6252.12671\Shortcut Virus Remover v3.1.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6252.12671\Shortcut Virus Remover v3.1.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6252.12671\shortcut virus remover v3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1556"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument microsoft-edge:https://www.usb-antivirus.com/C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeUsbFix.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1964"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3464 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2508"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4208 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2960"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5228 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2992"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3636 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3028"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2548 --field-trial-handle=2424,i,4636854826946629428,8461202765441588517,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4004"C:\Users\admin\AppData\Local\Temp\RarSFX0\Shortcut Virus Remover v3.1.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\Shortcut Virus Remover v3.1.exeShortcut Virus Remover v3.1.exe
User:
admin
Company:
Cyber X
Integrity Level:
MEDIUM
Description:
Shortcut Virus Remover
Exit code:
0
Version:
3.01.0012
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\shortcut virus remover v3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4080"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2116 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4236"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2416 --field-trial-handle=2424,i,4636854826946629428,8461202765441588517,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
33 678
Read events
33 432
Write events
235
Delete events
11

Modification events

(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Remover-Virus-Acceso-Directo(By Pixel4brain.com).zip
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6252) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
18
Suspicious files
149
Text files
198
Unknown types
1

Dropped files

PID
Process
Filename
Type
5880UsbFix_9.018.exeC:\UsbFix\Modules\Api_USBFix.exeexecutable
MD5:ECAE51F4BD335F68EE8B9357CD39C27A
SHA256:999804474FB78F2B6D7C581B9C11D218C21B5123A5617FEF241682EA1E8B4B6D
5880UsbFix_9.018.exeC:\UsbFix\Res\Account.pngimage
MD5:63208410787525C8AA87586CB7C14131
SHA256:9C07A60DBC76102373C8E22062F2BEDAEA2F28A0D3B9D04C700303363CB5810D
6252WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6252.10763\UsbFix_9.018.exeexecutable
MD5:7F72C1915DC932065294F62C96B8A79F
SHA256:CCE20E86DF16B3853E0AFA5E623F6B1E628FED3958B669A322345BF6D9C5BD77
5880UsbFix_9.018.exeC:\UsbFix\UsbFix.exeexecutable
MD5:C1E8169CBA11038C0FC1A02E8B314179
SHA256:E750F0BE50856C01C87663FF45AE439754024D1244BD473306153B6437A686B2
6444Shortcut Virus Remover v3.1.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\Shortcut Virus Remover v3.1.exeexecutable
MD5:A9FEC8AD17B80EF7C3D3A142BF58CBB2
SHA256:B898EF094D66880BA27AFE8B4C61950059EB6B403832776FBE067F3B1D9DA49F
6252WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6252.9458\UsbFix_9.018.exeexecutable
MD5:7F72C1915DC932065294F62C96B8A79F
SHA256:CCE20E86DF16B3853E0AFA5E623F6B1E628FED3958B669A322345BF6D9C5BD77
5880UsbFix_9.018.exeC:\UsbFix\Res\Apply.jpgimage
MD5:1D2DBB4273A5E717BC50D0485C8325F1
SHA256:83608235287DF83712530EF2526269BB88929E7C042AA47A3BB51E209F18D7DC
6444Shortcut Virus Remover v3.1.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\pskill.exeexecutable
MD5:6F2F60AF33A5CAF03E1D0AC81A2DE892
SHA256:ED8F3C368BA229043C8ACEF7AE4F4A0FDE62BF39FCE51522916B7DCE1E837F71
5880UsbFix_9.018.exeC:\UsbFix\Res\AutoClean.pngimage
MD5:5DFE56A16FEF1C0599426F575B3BF707
SHA256:4959DAE2F8CB8494D09BD8771B1CB8205ECE92DB2BE85BC86468ADE1CB7DD3ED
5880UsbFix_9.018.exeC:\UsbFix\Res\Apply2.jpgimage
MD5:1D2DBB4273A5E717BC50D0485C8325F1
SHA256:83608235287DF83712530EF2526269BB88929E7C042AA47A3BB51E209F18D7DC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
75
DNS requests
73
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5484
svchost.exe
GET
304
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5484
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6712
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6672
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4056
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3972
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
4056
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5336
SearchApp.exe
104.126.37.155:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5484
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.46
whitelisted
www.bing.com
  • 104.126.37.155
  • 104.126.37.160
  • 104.126.37.153
  • 104.126.37.144
  • 104.126.37.139
  • 104.126.37.163
  • 104.126.37.161
  • 104.126.37.171
  • 104.126.37.184
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.4
  • 20.190.159.64
  • 40.126.31.71
  • 20.190.159.68
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.75
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
th.bing.com
  • 104.126.37.184
  • 104.126.37.155
  • 104.126.37.160
  • 104.126.37.153
  • 104.126.37.144
  • 104.126.37.139
  • 104.126.37.163
  • 104.126.37.161
  • 104.126.37.171
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
www.usb-antivirus.com
  • 109.234.162.139
unknown

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info