File name:

Total-Uninstall-Essential-Setup-7.6.0.exe

Full analysis: https://app.any.run/tasks/a9e18ab1-26f3-4481-9e6d-7efa191625fd
Verdict: Malicious activity
Analysis date: April 21, 2025, 18:05:07
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
delphi
inno
installer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

CDEB596B0EA5E0CB8CAD06C0FCDAC70B

SHA1:

8397E32A55EC95A25FC24F62FDFA3AF0FFE84200

SHA256:

22F2474595ABB6A9B7A3AEC37DBA3FAFC9855C7AF9031CE364B4060FA4DF6031

SSDEEP:

98304:4+cD4dnoPNUVL74QdacaGEU7Zm1pc9Yg3bi7nJk/PCPzl1Vi2wni0Zfznax28QEC:QcLD2gDpDbZ/9ClZ7Ou8cyPhDkEx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Total-Uninstall-Essential-Setup-7.6.0.exe (PID: 7712)
      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7892)
      • Total-Uninstall-Essential-Setup-7.6.0.exe (PID: 7860)
    • Reads security settings of Internet Explorer

      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7756)
      • Tu.exe (PID: 7216)
    • Reads the BIOS version

      • Tu.exe (PID: 7216)
      • Tu.exe (PID: 7428)
    • Reads the date of Windows installation

      • Tu.exe (PID: 7216)
      • Tu.exe (PID: 7428)
    • Reads the Windows owner or organization settings

      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7892)
    • Starts POWERSHELL.EXE for commands execution

      • Tu.exe (PID: 7216)
  • INFO

    • Checks supported languages

      • Total-Uninstall-Essential-Setup-7.6.0.exe (PID: 7712)
      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7756)
      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7892)
      • Tu.exe (PID: 7428)
      • Total-Uninstall-Essential-Setup-7.6.0.exe (PID: 7860)
      • Tu.exe (PID: 7216)
    • Create files in a temporary directory

      • Total-Uninstall-Essential-Setup-7.6.0.exe (PID: 7712)
      • Total-Uninstall-Essential-Setup-7.6.0.exe (PID: 7860)
      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7892)
      • Tu.exe (PID: 7216)
      • Tu.exe (PID: 7428)
    • Process checks computer location settings

      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7756)
      • Tu.exe (PID: 7216)
    • Reads the computer name

      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7756)
      • Tu.exe (PID: 7216)
      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7892)
      • Tu.exe (PID: 7428)
    • Creates files in the program directory

      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7892)
      • Tu.exe (PID: 7216)
    • The sample compiled with english language support

      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7892)
    • Detects InnoSetup installer (YARA)

      • Total-Uninstall-Essential-Setup-7.6.0.exe (PID: 7712)
      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7756)
    • Compiled with Borland Delphi (YARA)

      • Total-Uninstall-Essential-Setup-7.6.0.exe (PID: 7712)
      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7756)
    • Creates a software uninstall entry

      • Total-Uninstall-Essential-Setup-7.6.0.tmp (PID: 7892)
    • Process checks whether UAC notifications are on

      • Tu.exe (PID: 7216)
      • Tu.exe (PID: 7428)
    • Reads CPU info

      • Tu.exe (PID: 7216)
    • Reads Environment values

      • Tu.exe (PID: 7428)
      • Tu.exe (PID: 7216)
    • Manual execution by a user

      • Tu.exe (PID: 7196)
      • Tu.exe (PID: 7428)
    • Checks proxy server information

      • Tu.exe (PID: 7216)
    • Reads the software policy settings

      • Tu.exe (PID: 7216)
    • Reads the machine GUID from the registry

      • Tu.exe (PID: 7216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 7.6.0.660
ProductVersionNumber: 7.6.0.660
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Gavrila MARTAU
FileDescription: Total Uninstall Essential 7.6.0 Setup
FileVersion: 7.6.0.660
LegalCopyright: Gavrila MARTAU 2001 - 2023
OriginalFileName:
ProductName: Total Uninstall Essential
ProductVersion: 7.6.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
12
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start total-uninstall-essential-setup-7.6.0.exe total-uninstall-essential-setup-7.6.0.tmp no specs total-uninstall-essential-setup-7.6.0.exe total-uninstall-essential-setup-7.6.0.tmp tu.exe tu.exe no specs tu.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4336C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7196"C:\Program Files\Total Uninstall Essential\Tu.exe" C:\Program Files\Total Uninstall Essential\Tu.exeexplorer.exe
User:
admin
Company:
Gavrila Martau
Integrity Level:
MEDIUM
Description:
Total Uninstall Essential - Uninstaller, cleaner and start-up manager
Exit code:
3221226540
Version:
7.6.0.660
Modules
Images
c:\program files\total uninstall essential\tu.exe
c:\windows\system32\ntdll.dll
7216"C:\Program Files\Total Uninstall Essential\Tu.exe" /language EnglishC:\Program Files\Total Uninstall Essential\Tu.exe
Total-Uninstall-Essential-Setup-7.6.0.tmp
User:
admin
Company:
Gavrila Martau
Integrity Level:
HIGH
Description:
Total Uninstall Essential - Uninstaller, cleaner and start-up manager
Version:
7.6.0.660
Modules
Images
c:\program files\total uninstall essential\tu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\combase.dll
7396"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "Get-AppxPackage -user \"admin\" | Select IsFramework, PackageFamilyName, PackageFullName, Name, InstallLocation, Version | ConvertTo-Csv -Delimiter `| -NoTypeInformation" > \"C:\Users\admin\AppData\Local\Temp\TuL4841.tmp\"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeTu.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
7428"C:\Program Files\Total Uninstall Essential\Tu.exe" C:\Program Files\Total Uninstall Essential\Tu.exe
explorer.exe
User:
admin
Company:
Gavrila Martau
Integrity Level:
HIGH
Description:
Total Uninstall Essential - Uninstaller, cleaner and start-up manager
Exit code:
0
Version:
7.6.0.660
Modules
Images
c:\program files\total uninstall essential\tu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\combase.dll
c:\windows\system32\oleacc.dll
7520\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7712"C:\Users\admin\AppData\Local\Temp\Total-Uninstall-Essential-Setup-7.6.0.exe" C:\Users\admin\AppData\Local\Temp\Total-Uninstall-Essential-Setup-7.6.0.exe
explorer.exe
User:
admin
Company:
Gavrila MARTAU
Integrity Level:
MEDIUM
Description:
Total Uninstall Essential 7.6.0 Setup
Exit code:
0
Version:
7.6.0.660
Modules
Images
c:\users\admin\appdata\local\temp\total-uninstall-essential-setup-7.6.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7756"C:\Users\admin\AppData\Local\Temp\is-LGQSK.tmp\Total-Uninstall-Essential-Setup-7.6.0.tmp" /SL5="$802A2,14865832,832512,C:\Users\admin\AppData\Local\Temp\Total-Uninstall-Essential-Setup-7.6.0.exe" C:\Users\admin\AppData\Local\Temp\is-LGQSK.tmp\Total-Uninstall-Essential-Setup-7.6.0.tmpTotal-Uninstall-Essential-Setup-7.6.0.exe
User:
admin
Company:
Gavrila MARTAU
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-lgqsk.tmp\total-uninstall-essential-setup-7.6.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
7800\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7852"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "Get-AppxPackage -user \"admin\" | ForEach-Object {$prop = (Get-AppxPackageManifest $_).Package.Properties; Add-Member -InputObject $prop -NotePropertyName PackageFamilyName -NotePropertyValue $_.PackageFamilyName; Add-Member -InputObject $prop -NotePropertyName PackageFullName -NotePropertyValue $_.PackageFullName; $prop} | Select PackageFamilyName, PackageFullName, DisplayName, PublisherDisplayName, Logo | ConvertTo-Csv -Delimiter `| -NoTypeInformation" > \"C:\Users\admin\AppData\Local\Temp\TuL4841.tmp\"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeTu.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
67 751
Read events
67 687
Write events
64
Delete events
0

Modification events

(PID) Process:(7892) Total-Uninstall-Essential-Setup-7.6.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall Essential_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.1
(PID) Process:(7892) Total-Uninstall-Essential-Setup-7.6.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall Essential_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\Total Uninstall Essential
(PID) Process:(7892) Total-Uninstall-Essential-Setup-7.6.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall Essential_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Total Uninstall Essential\
(PID) Process:(7892) Total-Uninstall-Essential-Setup-7.6.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall Essential_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(7892) Total-Uninstall-Essential-Setup-7.6.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall Essential_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(7892) Total-Uninstall-Essential-Setup-7.6.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall Essential_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
desktopicon
(PID) Process:(7892) Total-Uninstall-Essential-Setup-7.6.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall Essential_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
(PID) Process:(7892) Total-Uninstall-Essential-Setup-7.6.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall Essential_is1
Operation:writeName:Inno Setup: Language
Value:
English
(PID) Process:(7892) Total-Uninstall-Essential-Setup-7.6.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall Essential_is1
Operation:writeName:DisplayName
Value:
Total Uninstall Essential 7.6.0
(PID) Process:(7892) Total-Uninstall-Essential-Setup-7.6.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall Essential_is1
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Total Uninstall Essential\Tu.exe
Executable files
9
Suspicious files
64
Text files
20
Unknown types
0

Dropped files

PID
Process
Filename
Type
7892Total-Uninstall-Essential-Setup-7.6.0.tmpC:\Program Files\Total Uninstall Essential\Translations\ChineseSimplified.lngbinary
MD5:27060943BE58494056BDE8F61A968B70
SHA256:6BD1E1928F8D34FF0B4E18EE8E9C1D5CEAC7AA18AB54050FD313FC59CAB111A2
7892Total-Uninstall-Essential-Setup-7.6.0.tmpC:\Program Files\Total Uninstall Essential\Translations\Czech.lngbinary
MD5:14806F1F2B204BE879B9B640084270BC
SHA256:74E8279CA2E94F851777B5CD2B5EA147058F996A655B11C11FAD0528ADD05E29
7892Total-Uninstall-Essential-Setup-7.6.0.tmpC:\Program Files\Total Uninstall Essential\Translations\English.lngbinary
MD5:6F3E61CCCDA793D6C0F1EB183BA7EEF6
SHA256:A5F88CF38D4FF79F719DC859CC58738249B5BABB59F17805E441EDAEFA35FCAC
7892Total-Uninstall-Essential-Setup-7.6.0.tmpC:\Program Files\Total Uninstall Essential\Translations\is-BVFIB.tmpbinary
MD5:E4A4ED0157204CC8B5D9CB8D0AC23CD3
SHA256:07838181B2F58D6DAEBAEB296122294641926729B72F6F9813FAC09B6F19744F
7892Total-Uninstall-Essential-Setup-7.6.0.tmpC:\Program Files\Total Uninstall Essential\License.rtftext
MD5:18123E29BC96802E6AEC6B488D3F971B
SHA256:E5E2F1D122F155D3F06E5CD5022F8DB93E61E00ABF2D8F7F2E9CAB33CDB81BBE
7892Total-Uninstall-Essential-Setup-7.6.0.tmpC:\Program Files\Total Uninstall Essential\Translations\is-G5LPR.tmpbinary
MD5:14806F1F2B204BE879B9B640084270BC
SHA256:74E8279CA2E94F851777B5CD2B5EA147058F996A655B11C11FAD0528ADD05E29
7860Total-Uninstall-Essential-Setup-7.6.0.exeC:\Users\admin\AppData\Local\Temp\is-C2RTD.tmp\Total-Uninstall-Essential-Setup-7.6.0.tmpexecutable
MD5:0E98346BABA75197F269EDC54470E9C5
SHA256:05B3081362B0D337C76F6BB54263FBA12DE219C3F8F2938C19C7EEB696922CAA
7892Total-Uninstall-Essential-Setup-7.6.0.tmpC:\Program Files\Total Uninstall Essential\Translations\is-T0QMB.tmpbinary
MD5:728B097A1A7CDEF814D97B0B91EC097F
SHA256:4C796F05F3D3BDCAD31E0A1D42B5B44AC1A26BEE49FA735848C6D71DFC54EAA3
7892Total-Uninstall-Essential-Setup-7.6.0.tmpC:\Program Files\Total Uninstall Essential\Translations\is-IT00S.tmpbinary
MD5:6F3E61CCCDA793D6C0F1EB183BA7EEF6
SHA256:A5F88CF38D4FF79F719DC859CC58738249B5BABB59F17805E441EDAEFA35FCAC
7892Total-Uninstall-Essential-Setup-7.6.0.tmpC:\Program Files\Total Uninstall Essential\Translations\ChineseTraditional.lngbinary
MD5:728B097A1A7CDEF814D97B0B91EC097F
SHA256:4C796F05F3D3BDCAD31E0A1D42B5B44AC1A26BEE49FA735848C6D71DFC54EAA3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
21
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.100.102.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1276
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1276
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
95.100.102.101:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 95.100.102.101
  • 2.16.253.202
whitelisted
google.com
  • 142.250.185.78
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.32.76
  • 20.190.160.2
  • 20.190.160.132
  • 40.126.32.134
  • 20.190.160.130
  • 40.126.32.136
  • 20.190.160.5
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
total-uninstall.com
  • 64.91.254.118
unknown

Threats

No threats detected
No debug info