download:

/package/parsec-windows.exe

Full analysis: https://app.any.run/tasks/a6f200b7-392b-49f0-b884-e64277884c39
Verdict: Malicious activity
Analysis date: April 24, 2025, 19:22:22
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

0B9F6C9D89E9B427A469F34988B48F2C

SHA1:

DC29246551FB3BAAF77DCB3B926A2BF7E6FC567A

SHA256:

206CD186AAA431D3975EB30F682B83851EF4F81125D2004F53B681117DA23EC6

SSDEEP:

98304:i8QkWrhYycq4DJLyPsYLhOtx+WVCj5VWMkV17LrQQSrLhdtjB2MzxuPhzAPHwZLM:23UUScD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • parsec-windows.exe (PID: 3100)
      • pservice.exe (PID: 780)
      • parsecd.exe (PID: 2692)
      • parsecd.exe (PID: 6388)
      • parsecd.exe (PID: 1020)
    • Changes the autorun value in the registry

      • nefconw.exe (PID: 2420)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • parsec-windows.exe (PID: 5304)
    • The process creates files with name similar to system file names

      • parsec-windows.exe (PID: 5304)
      • parsec-vud.exe (PID: 1128)
      • parsec-vdd.exe (PID: 6032)
    • Executable content was dropped or overwritten

      • parsec-windows.exe (PID: 5304)
      • parsec-vud.exe (PID: 1128)
      • nefconw.exe (PID: 5668)
      • drvinst.exe (PID: 5260)
      • nefconw.exe (PID: 2420)
      • drvinst.exe (PID: 5956)
      • parsec-vdd.exe (PID: 6032)
      • nefconw.exe (PID: 1168)
      • drvinst.exe (PID: 856)
      • parsecd.exe (PID: 6388)
      • parsecd.exe (PID: 1852)
      • parsecd.exe (PID: 2692)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • parsec-windows.exe (PID: 5304)
      • parsec-vud.exe (PID: 1128)
      • parsec-vdd.exe (PID: 6032)
    • Windows service management via SC.EXE

      • sc.exe (PID: 2088)
      • sc.exe (PID: 5260)
      • sc.exe (PID: 976)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 1324)
      • wscript.exe (PID: 1272)
      • wscript.exe (PID: 6576)
      • wscript.exe (PID: 4200)
      • wscript.exe (PID: 5964)
      • wscript.exe (PID: 1052)
    • Uses TASKKILL.EXE to kill process

      • wscript.exe (PID: 1324)
    • The process executes VB scripts

      • parsec-windows.exe (PID: 5304)
    • Stops a currently running service

      • sc.exe (PID: 5392)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 6576)
      • wscript.exe (PID: 5964)
      • wscript.exe (PID: 1052)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • wscript.exe (PID: 6576)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 2240)
    • Creates a software uninstall entry

      • parsec-windows.exe (PID: 5304)
      • parsec-vud.exe (PID: 1128)
      • parsec-vdd.exe (PID: 6032)
    • Creates a new Windows service

      • sc.exe (PID: 2908)
    • Executes as Windows Service

      • pservice.exe (PID: 780)
      • WUDFHost.exe (PID: 6080)
    • Starts CMD.EXE for commands execution

      • parsec-windows.exe (PID: 5304)
      • parsec-vud.exe (PID: 1128)
      • parsec-vdd.exe (PID: 6032)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • wscript.exe (PID: 1052)
    • Executing commands from a ".bat" file

      • parsec-vud.exe (PID: 1128)
      • parsec-vdd.exe (PID: 6032)
    • Drops a system driver (possible attempt to evade defenses)

      • parsec-vud.exe (PID: 1128)
      • nefconw.exe (PID: 5668)
      • drvinst.exe (PID: 5260)
      • nefconw.exe (PID: 2420)
      • drvinst.exe (PID: 5956)
    • Creates files in the driver directory

      • drvinst.exe (PID: 5260)
      • drvinst.exe (PID: 5956)
      • drvinst.exe (PID: 856)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 5640)
      • drvinst.exe (PID: 3332)
      • drvinst.exe (PID: 1188)
      • drvinst.exe (PID: 1852)
    • Uses WEVTUTIL.EXE to remove publishers and event logs from the manifest

      • parsec-vdd.exe (PID: 6032)
      • wevtutil.exe (PID: 4728)
    • Uses WEVTUTIL.EXE to install publishers and event logs from the manifest

      • parsec-vdd.exe (PID: 6032)
      • wevtutil.exe (PID: 6388)
    • Reads security settings of Internet Explorer

      • parsecd.exe (PID: 2692)
    • Application launched itself

      • parsecd.exe (PID: 6388)
  • INFO

    • Checks supported languages

      • parsec-windows.exe (PID: 5304)
      • pservice.exe (PID: 780)
      • parsec-vud.exe (PID: 1128)
      • nefconc.exe (PID: 6676)
      • nefconw.exe (PID: 6068)
      • nefconw.exe (PID: 5668)
      • drvinst.exe (PID: 5260)
      • drvinst.exe (PID: 3332)
      • drvinst.exe (PID: 5640)
      • nefconw.exe (PID: 2420)
      • drvinst.exe (PID: 5956)
      • parsec-vdd.exe (PID: 6032)
      • drvinst.exe (PID: 1188)
      • nefconw.exe (PID: 1188)
      • nefconw.exe (PID: 6584)
      • nefconw.exe (PID: 1168)
      • drvinst.exe (PID: 856)
      • drvinst.exe (PID: 1852)
      • parsecd.exe (PID: 2692)
      • parsecd.exe (PID: 1852)
    • The sample compiled with english language support

      • parsec-windows.exe (PID: 5304)
      • parsec-vud.exe (PID: 1128)
      • parsec-vdd.exe (PID: 6032)
      • drvinst.exe (PID: 856)
      • nefconw.exe (PID: 1168)
      • parsecd.exe (PID: 1852)
      • parsecd.exe (PID: 2692)
      • parsecd.exe (PID: 6388)
    • Reads the computer name

      • parsec-windows.exe (PID: 5304)
      • pservice.exe (PID: 780)
      • nefconw.exe (PID: 6068)
      • nefconw.exe (PID: 5668)
      • drvinst.exe (PID: 5640)
      • nefconw.exe (PID: 2420)
      • drvinst.exe (PID: 5956)
      • drvinst.exe (PID: 3332)
      • drvinst.exe (PID: 5260)
      • drvinst.exe (PID: 1188)
      • nefconw.exe (PID: 1188)
      • nefconw.exe (PID: 6584)
      • nefconw.exe (PID: 1168)
      • drvinst.exe (PID: 856)
      • drvinst.exe (PID: 1852)
      • parsecd.exe (PID: 2692)
      • parsecd.exe (PID: 1852)
    • Create files in a temporary directory

      • parsec-windows.exe (PID: 5304)
      • parsec-vud.exe (PID: 1128)
      • nefconw.exe (PID: 5668)
      • nefconw.exe (PID: 2420)
      • parsec-vdd.exe (PID: 6032)
      • nefconw.exe (PID: 1168)
    • Creates files in the program directory

      • parsec-windows.exe (PID: 5304)
      • parsec-vud.exe (PID: 1128)
      • parsec-vdd.exe (PID: 6032)
      • parsecd.exe (PID: 2692)
      • parsecd.exe (PID: 1852)
    • Reads the software policy settings

      • drvinst.exe (PID: 5260)
      • drvinst.exe (PID: 5956)
      • drvinst.exe (PID: 856)
      • parsecd.exe (PID: 2692)
      • parsecd.exe (PID: 1852)
      • pservice.exe (PID: 780)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 5260)
      • drvinst.exe (PID: 5956)
      • drvinst.exe (PID: 856)
      • pservice.exe (PID: 780)
      • parsecd.exe (PID: 1852)
      • parsecd.exe (PID: 2692)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 1040)
    • Reads the time zone

      • runonce.exe (PID: 1040)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:55:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 184832
UninitializedDataSize: 2048
EntryPoint: 0x3552
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 150.97.4.0
ProductVersionNumber: 150.97.4.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Parsec
FileVersion: 150.97.4.0
ProductName: Parsec
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
210
Monitored processes
73
Malicious processes
14
Suspicious processes
7

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
208\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
300\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
660"C:\Windows\System32\netsh.exe" advfirewall firewall add rule name=Parsec dir=in action=allow program="C:\Program Files\Parsec\parsecd.exe" enable=yes profile=public,private,domainC:\Windows\SysWOW64\netsh.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\oleaut32.dll
684wevtutil im "C:\Program Files\Parsec Virtual Display Driver\mm.man" /fromwow64C:\Windows\System32\wevtutil.exewevtutil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
780"C:\Program Files\Parsec\pservice.exe"C:\Program Files\Parsec\pservice.exeservices.exe
User:
SYSTEM
Company:
Parsec
Integrity Level:
SYSTEM
Description:
Parsec
Version:
150.97c.0.0
Modules
Images
c:\program files\parsec\pservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
812\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exewevtutil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
856DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{4e041bd2-5e09-a14e-8ed3-12e12db71974}\mm.inf" "9" "484386e17" "00000000000001BC" "WinSta0\Default" "0000000000000214" "208" "C:\Program Files\Parsec Virtual Display Driver\driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
976"C:\Windows\System32\sc.exe" start ParsecC:\Windows\SysWOW64\sc.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\rpcrt4.dll
1020\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1020"C:\Program Files\Parsec\parsecd.exe" "" "SERVICE_LAUNCHED_V10" "LOADER_V13" "PARSEC_IPC_2d66ed3a25c14738"C:\Program Files\Parsec\parsecd.exe
parsecd.exe
User:
admin
Company:
Parsec
Integrity Level:
MEDIUM
Description:
Parsec
Version:
150.97c.0.0
Modules
Images
c:\program files\parsec\parsecd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
35 348
Read events
35 217
Write events
114
Delete events
17

Modification events

(PID) Process:(5304) parsec-windows.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Parsec.App.0
Value:
(PID) Process:(5304) parsec-windows.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Parsec
Operation:writeName:Comments
Value:
Parsec
(PID) Process:(5304) parsec-windows.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Parsec
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Parsec\parsecd.exe
(PID) Process:(5304) parsec-windows.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Parsec
Operation:writeName:DisplayName
Value:
Parsec
(PID) Process:(5304) parsec-windows.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Parsec
Operation:writeName:DisplayVersion
Value:
150-97d
(PID) Process:(5304) parsec-windows.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Parsec
Operation:writeName:EstimatedSize
Value:
8414
(PID) Process:(5304) parsec-windows.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Parsec
Operation:writeName:HelpLink
Value:
https://support.parsec.app
(PID) Process:(5304) parsec-windows.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Parsec
Operation:writeName:InstallLocation
Value:
C:\Program Files\Parsec
(PID) Process:(5304) parsec-windows.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Parsec
Operation:writeName:NoModify
Value:
1
(PID) Process:(5304) parsec-windows.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Parsec
Operation:writeName:NoRepair
Value:
1
Executable files
41
Suspicious files
45
Text files
15
Unknown types
1

Dropped files

PID
Process
Filename
Type
5304parsec-windows.exeC:\Users\admin\AppData\Local\Temp\nsaF7EF.tmp\nsDialogs.dllexecutable
MD5:B7D61F3F56ABF7B7FF0D4E7DA3AD783D
SHA256:89A82C4849C21DFE765052681E1FAD02D2D7B13C8B5075880C52423DCA72A912
5304parsec-windows.exeC:\Program Files\Parsec\vdd\parsec-vdd.exeexecutable
MD5:4B9A3048286692A865187013B70F44E8
SHA256:E23332448FDAF5AA017CB308DB5EF6855FAC526A7DED05D80C039404126D5362
5304parsec-windows.exeC:\Users\admin\AppData\Local\Temp\nsaF7EF.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
5304parsec-windows.exeC:\Program Files\Parsec\wscripts\firewall-add.vbstext
MD5:882374285898F16B5F9FF44AFC1AE701
SHA256:0BE5AA5CC6395A86878F56B131E13DB4908E48F06E892FF8F8CF9E2D3B6C8ABB
5304parsec-windows.exeC:\Program Files\Parsec\wscripts\legacy-cleanup.vbstext
MD5:C78520C3162C1962F3164714B37EB4D0
SHA256:DEA38BD553ABE93C689DE42D0220ADD18F9BE3E3D2FA53F97EB8649F586DF4F3
5304parsec-windows.exeC:\Program Files\Parsec\wscripts\firewall-remove.vbstext
MD5:5D4D70CDF36FCDAA292DA1DA9133320C
SHA256:75F1DECE4FDA689A907F6D74B513ADB0C1771C1B79EA71160179542C9C4AB2F0
5304parsec-windows.exeC:\Program Files\Parsec\wscripts\service-install.vbstext
MD5:971E2A344A6E17347A81EEB21ADA7BA7
SHA256:01F62A12DE3307B375DFF3EBCD6961D76FFCBC24F70682C7875655A811CE76A1
5304parsec-windows.exeC:\Program Files\Parsec\wscripts\service-remove.vbstext
MD5:B90E75DD7903CB2D6328BB3714865C7A
SHA256:970B3C2A9EA1906A177810990478932E3517F47ABA267CF2AB9E4BA65E7B475F
5304parsec-windows.exeC:\Program Files\Parsec\vusb\parsec-vud.exeexecutable
MD5:FA2814C8CFF38B2F4737085C70154B8F
SHA256:F8DB024B61C36E5D45CA5B485BF855DBFE1D0523333158E873D7DEB4D86EC0E4
5304parsec-windows.exeC:\Program Files\Parsec\wscripts\service-kill-parsec.vbstext
MD5:F7B0C63E7AEA5CBD96F7BF1021B28B73
SHA256:71F9CC28497B959377439F6611615EF582745DD5B9CCA02B5C4B24BB1FC3DFB8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
42
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.55.236.70:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
US
binary
825 b
whitelisted
2980
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
6544
svchost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
2980
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
407 b
whitelisted
6388
parsecd.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
DE
binary
471 b
whitelisted
6388
parsecd.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAloEugzUPGt9OnVZ%2FPPgls%3D
DE
binary
727 b
whitelisted
6388
parsecd.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
DE
binary
727 b
whitelisted
2104
svchost.exe
GET
200
23.55.236.70:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
US
binary
825 b
whitelisted
2104
svchost.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
868 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6476
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
23.55.236.70:80
crl.microsoft.com
AKAMAI-AS
US
whitelisted
5496
MoUsoCoreWorker.exe
23.55.236.70:80
crl.microsoft.com
AKAMAI-AS
US
whitelisted
2104
svchost.exe
2.16.253.202:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
23.63.118.230:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 23.55.236.70
  • 23.55.236.72
whitelisted
www.microsoft.com
  • 2.16.253.202
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.68
  • 40.126.31.73
  • 20.190.159.130
  • 20.190.159.131
  • 40.126.31.0
  • 20.190.159.23
  • 40.126.31.130
whitelisted
ocsp.digicert.com
  • 23.63.118.230
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
go.microsoft.com
  • 95.100.186.9
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info