File name:

DellProvDiagDC.exe

Full analysis: https://app.any.run/tasks/432e2ad3-2912-4b9a-a8c7-44306a6b7fbf
Verdict: Malicious activity
Analysis date: February 05, 2025, 21:18:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
MD5:

CDB9CBEBDF83CC595E5FB63CBD375478

SHA1:

326636B77B635F53E61E9129F95EBD816BAC6891

SHA256:

29B250B12F0B93DD8FECB7B8D15D8D53D4AFEF82CDA426C2E6C5A43F97D833A1

SSDEEP:

6144:tZfQIYZvK1VGn1idZ4xqdYhHgliE3G8h49cVBPJAcQRjEuvMd0hdx6YLp5:tZfQIH1VGn1idb85

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the Windows auto-update feature

      • DellProvDiagDC.exe (PID: 6444)
    • Dynamically loads an assembly (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Creates or modifies Windows services

      • w32tm.exe (PID: 3620)
  • SUSPICIOUS

    • Process checks is Powershell's Script Block Logging on

      • DellProvDiagDC.exe (PID: 6444)
    • Process checks is Powershell's transcription on

      • DellProvDiagDC.exe (PID: 6444)
    • Reads security settings of Internet Explorer

      • DellProvDiagDC.exe (PID: 6444)
    • Gets or sets the security protocol (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Checks Windows Trust Settings

      • DellProvDiagDC.exe (PID: 6444)
    • Uses sleep to delay execution (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Uses base64 encoding (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Gets content of a file (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Reads the Windows owner or organization settings

      • DellProvDiagDC.exe (PID: 6444)
    • Reads the date of Windows installation

      • DellProvDiagDC.exe (PID: 6444)
    • Query current time using 'w32tm.exe'

      • DellProvDiagDC.exe (PID: 6444)
      • cmd.exe (PID: 732)
    • Executable content was dropped or overwritten

      • csc.exe (PID: 1144)
    • Starts CMD.EXE for commands execution

      • DellProvDiagDC.exe (PID: 6444)
    • The process exported the data from the registry

      • licensingdiag.exe (PID: 6488)
      • DellProvDiagDC.exe (PID: 6444)
    • Searches for installed software

      • reg.exe (PID: 4224)
      • reg.exe (PID: 5628)
    • Uses NSLOOKUP.EXE to check DNS info

      • licensingdiag.exe (PID: 6488)
    • Uses REG/REGEDIT.EXE to modify registry

      • DellProvDiagDC.exe (PID: 6444)
  • INFO

    • The sample compiled with english language support

      • DellProvDiagDC.exe (PID: 6444)
    • Checks supported languages

      • DellProvDiagDC.exe (PID: 6444)
      • csc.exe (PID: 1144)
      • cvtres.exe (PID: 3288)
    • Reads the computer name

      • DellProvDiagDC.exe (PID: 6444)
    • Reads Environment values

      • DellProvDiagDC.exe (PID: 6444)
    • Reads the machine GUID from the registry

      • DellProvDiagDC.exe (PID: 6444)
      • csc.exe (PID: 1144)
    • Create files in a temporary directory

      • DellProvDiagDC.exe (PID: 6444)
      • csc.exe (PID: 1144)
      • cvtres.exe (PID: 3288)
      • reg.exe (PID: 6708)
      • reg.exe (PID: 3808)
      • reg.exe (PID: 4224)
      • licensingdiag.exe (PID: 6488)
      • MdmDiagnosticsTool.exe (PID: 5464)
      • reg.exe (PID: 7000)
    • Gets or sets the time when the file was last written to (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Uses string replace method (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Reads the software policy settings

      • DellProvDiagDC.exe (PID: 6444)
      • licensingdiag.exe (PID: 6488)
      • MdmDiagnosticsTool.exe (PID: 5464)
    • Checks proxy server information

      • DellProvDiagDC.exe (PID: 6444)
      • licensingdiag.exe (PID: 6488)
      • dsregcmd.exe (PID: 6584)
    • Creates files or folders in the user directory

      • DellProvDiagDC.exe (PID: 6444)
      • licensingdiag.exe (PID: 6488)
    • Reads product name

      • DellProvDiagDC.exe (PID: 6444)
    • Checks whether the specified file exists (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Reads Windows Product ID

      • DellProvDiagDC.exe (PID: 6444)
      • licensingdiag.exe (PID: 6488)
    • Reads security settings of Internet Explorer

      • licensingdiag.exe (PID: 6488)
    • Creates files in the program directory

      • MdmDiagnosticsTool.exe (PID: 5464)
    • Process checks computer location settings

      • DellProvDiagDC.exe (PID: 6444)
    • Gets data length (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:02:06 23:34:59+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 48
CodeSize: 57856
InitializedDataSize: 731648
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 1.0.0.13
ProductVersionNumber: 1.0.0.13
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: -
FileVersion: 1.0.0.13
InternalName: -
LegalCopyright: Copyright (c) 2024 All rights reserved
OriginalFileName: DellProvDiagDC
ProductVersion: 1.0.0.13
AssemblyVersion: 5.1.41.0
CompanyName: Dell Technologies
ProductName: DellProvDiagDC
Comments: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
162
Monitored processes
29
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start dellprovdiagdc.exe conhost.exe no specs csc.exe cvtres.exe no specs tiworker.exe no specs w32tm.exe no specs w32tm.exe no specs w32tm.exe no specs cmd.exe no specs w32tm.exe no specs w32tm.exe no specs w32tm.exe no specs mdmdiagnosticstool.exe no specs conhost.exe no specs licensingdiag.exe conhost.exe no specs reg.exe no specs nslookup.exe dsregcmd.exe no specs certreq.exe no specs conhost.exe no specs certutil.exe no specs conhost.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs dellprovdiagdc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
732"C:\WINDOWS\system32\cmd.exe" /c "w32tm /resync /rediscover 2>&1"C:\Windows\System32\cmd.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
1144"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\xayw2a04\xayw2a04.cmdline"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
DellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1224"C:\WINDOWS\system32\reg.exe" query HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall /sC:\Windows\System32\reg.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1988\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execertreq.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2076"C:\WINDOWS\system32\w32tm.exe" /registerC:\Windows\System32\w32tm.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Time Service Diagnostic Tool
Exit code:
2147943472
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\w32tm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
2420"C:\WINDOWS\system32\w32tm.exe" /configure "/manualpeerlist:time.windows.com time.nist.gov 0.pool.ntp.org 1.pool.ntp.org 2.pool.ntp.org" /syncfromflags:MANUAL /updateC:\Windows\System32\w32tm.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Time Service Diagnostic Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\w32tm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
3288C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES9166.tmp" "c:\Users\admin\AppData\Local\Temp\xayw2a04\CSCFC5E5B6557AC49F2A53D9901865520.TMP"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
14.32.31326.0
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3620"C:\WINDOWS\system32\w32tm.exe" /registerC:\Windows\System32\w32tm.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Time Service Diagnostic Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\w32tm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
3808"C:\WINDOWS\system32\reg.exe" export HKLM\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization C:\WINDOWS\Dell\DellProvDiag\RegistryExports\DeliveryOptimization-RegExport.reg /yC:\Windows\System32\reg.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4224"C:\WINDOWS\system32\reg.exe" export HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall "C:\WINDOWS\Dell\DellProvDiag\RegistryExports\HKLM_Software_Microsoft_Windows_CurrentVersion_Uninstall export.reg" /yC:\Windows\System32\reg.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
28 528
Read events
28 412
Write events
93
Delete events
23

Modification events

(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription
Operation:writeName:EnableTranscripting
Value:
0
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging
Operation:writeName:EnableScriptBlockLogging
Value:
0
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\AppHVSI
Operation:writeName:AllowAppHVSI_ProviderSet
Value:
0
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\EdgeUpdate
Operation:writeName:UpdateDefault
Value:
0
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\Network Connections
Operation:writeName:NC_DoNotShowLocalOnlyIcon
Value:
1
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\Windows Feeds
Operation:writeName:EnableFeeds
Value:
0
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:WUServer
Value:
http://neverupdatewindows10.com
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:WUStatusServer
Value:
http://neverupdatewindows10.com
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:UpdateServiceUrlAlternate
Value:
http://neverupdatewindows10.com
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:**del.FillEmptyContentUrls
Value:
Executable files
9
Suspicious files
44
Text files
103
Unknown types
0

Dropped files

PID
Process
Filename
Type
6444DellProvDiagDC.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:DB4572523BC0B7A17FDE1141195FA82C
SHA256:B80707733111B7B112947F010CD46D1C43700255E1A1274079CC29C08EEC4369
6444DellProvDiagDC.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:B53ADA059BC9E834CA202690FA38FFEB
SHA256:AA78D8591498CEFFB841E797C1874DC081E80BA3F863F998CD042A3EA18D3CB7
6444DellProvDiagDC.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_2dwujxg4.44q.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6444DellProvDiagDC.exeC:\Windows\Dell\DellProvDiag\QFE_PatchesApplied.csvcsv
MD5:3AD6BAA3A8A275D70E0A440695F6F0D9
SHA256:EED0B526829E9784EF0B42593BE1ED5632C56C52A5F41B61BC55210F7BE12036
3288cvtres.exeC:\Users\admin\AppData\Local\Temp\RES9166.tmpbinary
MD5:0BF4A72712289A6E7F9E3BDF5CBA863F
SHA256:467F9558145A723D15A24ED37C72E7BE8E3E5D637C4D94E9F9528057A4420D7A
6444DellProvDiagDC.exeC:\Users\admin\AppData\Local\Temp\xayw2a04\xayw2a04.0.cstext
MD5:55C2DF50B39C10616831CDF1F6006E6F
SHA256:756B828BBEF76248B7541BEB2A658B234BD1EF29C90FBB25E3412271CF0B42E3
6444DellProvDiagDC.exeC:\Users\admin\AppData\Local\Temp\xayw2a04\xayw2a04.cmdlinetext
MD5:8BFF0751234E0E058764BEE6B6D9F21A
SHA256:462FBB7599B4ABA9DF35C8ED72B458EFF0DC0A8D2E0F0D3D036F3FBC4C179A04
6488licensingdiag.exeC:\Users\admin\AppData\Local\Temp\DESKTOP-JGLLJLD_2025-02-05_diag\SPP\Tokens.dat
MD5:
SHA256:
1144csc.exeC:\Users\admin\AppData\Local\Temp\xayw2a04\xayw2a04.dllexecutable
MD5:780EA68061B7C07476E0800801C2C71A
SHA256:F86E6BAE8FD027564495883E2AC624D0E2EF2841E5BF23522542F777FDBEA155
1144csc.exeC:\Users\admin\AppData\Local\Temp\xayw2a04\CSCFC5E5B6557AC49F2A53D9901865520.TMPbinary
MD5:C48E1588115FA7FF6FED0F6DAE2E1B79
SHA256:B6516230A9D4A9C8B571224998B20D1BA6695FAE2C471048F8498314908D8D4E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
37
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6444
DellProvDiagDC.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6444
DellProvDiagDC.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6444
DellProvDiagDC.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAwjDwP5HIldKl7pbbAKGOY%3D
unknown
whitelisted
6908
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6488
licensingdiag.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
6908
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6348
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.16.110.121:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1076
svchost.exe
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6444
DellProvDiagDC.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
  • 23.52.120.96
  • 95.101.149.131
whitelisted
www.bing.com
  • 2.16.110.121
  • 2.16.110.171
  • 2.16.110.123
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.131
  • 20.190.159.0
  • 40.126.31.73
  • 20.190.159.71
  • 20.190.159.130
  • 20.190.159.68
  • 40.126.31.1
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
time.windows.com
  • 104.40.149.189
whitelisted
0.pool.ntp.org
  • 194.25.134.196
  • 88.198.7.62
  • 89.58.43.2
  • 159.69.64.189
whitelisted
1.pool.ntp.org
  • 31.209.85.243
  • 185.233.107.180
  • 79.133.44.140
  • 141.144.241.16
whitelisted
2.pool.ntp.org
  • 51.75.67.47
  • 185.41.106.152
  • 212.132.97.26
  • 194.164.164.175
whitelisted
time.nist.gov
  • 132.163.97.2
whitelisted

Threats

No threats detected
No debug info