File name:

PulseSecureAppLauncher__2_.msi

Full analysis: https://app.any.run/tasks/207d364c-92a4-4229-82d4-da3f7cfa2796
Verdict: Malicious activity
Analysis date: May 09, 2025, 10:33:38
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Pulse Application Launcher, Author: Ivanti, Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install Pulse Application Launcher., Template: Intel;1033, Revision Number: {18C4DC19-FD03-42A0-A147-A118C14E5649}, Create Time/Date: Sun Jan 26 10:02:38 2025, Last Saved Time/Date: Sun Jan 26 10:02:38 2025, Number of Pages: 300, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
MD5:

71FE673B9DDFC3BBBB147F6B62A61676

SHA1:

0D4E891F7D12ABB9896E66C641AD973BE8A0076D

SHA256:

2713771C9745B6A83054F8FBAAB849D2A9BFC5AA56C2084744E222312E16402D

SSDEEP:

98304:Y4cKw4sWD5azOy5Jb5lMuopg7e9XeTRJcQKMAxbrCTrjCe/YvAW3skgwKmIRXt/L:MOnccJSbH8wky

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 7436)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 2392)
      • msiexec.exe (PID: 7348)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 7348)
      • msiexec.exe (PID: 2392)
  • INFO

    • The sample compiled with english language support

      • msiexec.exe (PID: 2392)
      • msiexec.exe (PID: 7348)
    • Checks proxy server information

      • msiexec.exe (PID: 2392)
    • Reads the software policy settings

      • msiexec.exe (PID: 2392)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7348)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 2392)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 2392)
    • Reads the computer name

      • msiexec.exe (PID: 7348)
    • Manual execution by a user

      • PulseApplicationLauncher.exe (PID: 6004)
      • mspaint.exe (PID: 7948)
      • mspaint.exe (PID: 8072)
      • PulseApplicationLauncher.exe (PID: 4932)
      • PulseApplicationLauncher.exe (PID: 6112)
      • PulseExt64.exe (PID: 8016)
    • Checks supported languages

      • msiexec.exe (PID: 7348)
    • Manages system restore points

      • SrTasks.exe (PID: 8112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Pulse Application Launcher
Author: Ivanti, Inc.
Keywords: Installer
Comments: This installer database contains the logic and data required to install Pulse Application Launcher.
Template: Intel;1033
RevisionNumber: {18C4DC19-FD03-42A0-A147-A118C14E5649}
CreateDate: 2025:01:26 10:02:38
ModifyDate: 2025:01:26 10:02:38
Pages: 300
Words: 10
Software: Windows Installer XML Toolset (3.14.1.8722)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
17
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe sppextcomobj.exe no specs slui.exe msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs pulseapplicationlauncher.exe no specs rundll32.exe no specs slui.exe pulseapplicationlauncher.exe no specs pulseapplicationlauncher.exe no specs pulseapplicationlauncher.exe no specs mspaint.exe no specs mspaint.exe no specs pulseext64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
516"C:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\PulseApplicationLauncher.exe" PSALInstallFinishedC:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\PulseApplicationLauncher.exemsiexec.exe
User:
admin
Company:
Ivanti, Inc.
Integrity Level:
MEDIUM
Description:
Pulse Secure Application Launcher
Exit code:
0
Version:
22, 8, 1, 31437
Modules
Images
c:\users\admin\appdata\roaming\pulse secure\psal\pulseapplicationlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2392"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\PulseSecureAppLauncher__2_.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2772C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3884C:\Windows\syswow64\MsiExec.exe -Embedding 70733B233D8086965D2A1EF206E2D2B7C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4932"C:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\PulseApplicationLauncher.exe" C:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\PulseApplicationLauncher.exeexplorer.exe
User:
admin
Company:
Ivanti, Inc.
Integrity Level:
MEDIUM
Description:
Pulse Secure Application Launcher
Exit code:
4294967295
Version:
22, 8, 1, 31437
Modules
Images
c:\users\admin\appdata\roaming\pulse secure\psal\pulseapplicationlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6004"C:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\x64\PulseApplicationLauncher.exe" C:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\x64\PulseApplicationLauncher.exeexplorer.exe
User:
admin
Company:
Ivanti, Inc.
Integrity Level:
MEDIUM
Description:
Pulse Secure Application Launcher
Exit code:
4294967295
Version:
22, 8, 1, 31437
Modules
Images
c:\users\admin\appdata\roaming\pulse secure\psal\x64\pulseapplicationlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6112"C:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\PulseApplicationLauncher.exe" C:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\PulseApplicationLauncher.exeexplorer.exe
User:
admin
Company:
Ivanti, Inc.
Integrity Level:
MEDIUM
Description:
Pulse Secure Application Launcher
Exit code:
4294967295
Version:
22, 8, 1, 31437
Modules
Images
c:\users\admin\appdata\roaming\pulse secure\psal\pulseapplicationlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7228C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7284"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7348C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
12 827
Read events
12 482
Write events
325
Delete events
20

Modification events

(PID) Process:(7348) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
480000000000000002B427DBCDC0DB01B41C0000E81C0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7348) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
480000000000000002B427DBCDC0DB01B41C0000E81C0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7348) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
480000000000000032F877DBCDC0DB01B41C0000E81C0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7348) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
480000000000000032F877DBCDC0DB01B41C0000E81C0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7348) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000003FBF7CDBCDC0DB01B41C0000E81C0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7348) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
480000000000000024227FDBCDC0DB01B41C0000E81C0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7348) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(7348) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4800000000000000BC9510DCCDC0DB01B41C0000E81C0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7348) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000037F912DCCDC0DB01B41C0000701D0000E80300000100000000000000000000007EC5E6FCDC69B04791746B2B7EB0241800000000000000000000000000000000
(PID) Process:(7436) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000AD4021DCCDC0DB010C1D0000941D0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
46
Suspicious files
26
Text files
15
Unknown types
0

Dropped files

PID
Process
Filename
Type
7348msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
7348msiexec.exeC:\Windows\Installer\11216f.msi
MD5:
SHA256:
7348msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:9AAB057DAB03BF40E81D51DD0C8BDF3E
SHA256:F195E042870D0947AEABA04927DFDE6D51157B655818A1563EA5FFA0E1DCC9BD
7348msiexec.exeC:\Windows\Temp\~DFFA13D6E46833A3A1.TMPbinary
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
7348msiexec.exeC:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\x86\dsOpenSSL.dllexecutable
MD5:85816C6654048D67096FFF85804CEF16
SHA256:3182110EF408648A7884B1B5031C7DC8BD109267F96B65E1AAEE7365CC85E19B
2392msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_5860AD8F4270EFB91F3E5FD27AAAAB78binary
MD5:A68AC81D6A2665C82319A1DB71873F31
SHA256:2E9596822AB2F327D34290934458194B8AFA4760C07C7A2C98D3609501BA1EF7
7348msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:BDDE8149F6049F356DF81EA4DA191809
SHA256:C57D7814D40ACB00D68AA8D2A08D99DAE34BAB1CABA546F645A408E8F42F1265
2392msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:1234AC9D296D681660B46A30D9335457
SHA256:5CDE7FFEF4C91362E0A7D6263A5EC98326BBD1612BA819F10262A8EB6BFFA326
7348msiexec.exeC:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\dsOpenSSL.dllexecutable
MD5:4090B3BC2B40C246A9EFF61A72EC631B
SHA256:7B1800A79D5D01FA35AE1EA44A5471B9987F85A77D561C9588A568D8575157D7
7348msiexec.exeC:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\x64\dsOpenSSL64.dllexecutable
MD5:19AD46A45F776559D5A0245C0E421AF4
SHA256:A6328A78C733FBFD89702C7431C74A64EFE2500E7E9C127A3AC0B72225A4A7B0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
46
DNS requests
25
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.17.147.64:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2392
msiexec.exe
GET
200
2.16.38.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEApZrg126rO1sbd16expp%2FI%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.16.38.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2392
msiexec.exe
GET
200
2.16.38.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
2392
msiexec.exe
GET
200
2.16.38.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
8044
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.16.38.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
8044
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.16.38.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.17.147.64:80
crl.microsoft.com
Akamai International B.V.
CZ
whitelisted
2.19.217.218:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2392
msiexec.exe
2.16.38.4:80
ocsp.digicert.com
AKAMAI-AS
ES
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.16.38.4:80
ocsp.digicert.com
AKAMAI-AS
ES
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.17.147.64
  • 2.17.147.99
whitelisted
google.com
  • 216.58.206.46
whitelisted
www.microsoft.com
  • 2.19.217.218
whitelisted
ocsp.digicert.com
  • 2.16.38.4
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.31.67
  • 40.126.31.3
  • 20.190.159.75
  • 20.190.159.131
  • 40.126.31.129
  • 40.126.31.131
  • 20.190.159.129
  • 40.126.31.69
whitelisted
go.microsoft.com
  • 23.195.250.165
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info