File name:

DellProvDiagDC.exe

Full analysis: https://app.any.run/tasks/432e2ad3-2912-4b9a-a8c7-44306a6b7fbf
Verdict: Malicious activity
Analysis date: February 05, 2025, 21:18:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
MD5:

CDB9CBEBDF83CC595E5FB63CBD375478

SHA1:

326636B77B635F53E61E9129F95EBD816BAC6891

SHA256:

29B250B12F0B93DD8FECB7B8D15D8D53D4AFEF82CDA426C2E6C5A43F97D833A1

SSDEEP:

6144:tZfQIYZvK1VGn1idZ4xqdYhHgliE3G8h49cVBPJAcQRjEuvMd0hdx6YLp5:tZfQIH1VGn1idb85

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Dynamically loads an assembly (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Changes the Windows auto-update feature

      • DellProvDiagDC.exe (PID: 6444)
    • Creates or modifies Windows services

      • w32tm.exe (PID: 3620)
  • SUSPICIOUS

    • Process checks is Powershell's transcription on

      • DellProvDiagDC.exe (PID: 6444)
    • Process checks is Powershell's Script Block Logging on

      • DellProvDiagDC.exe (PID: 6444)
    • Reads security settings of Internet Explorer

      • DellProvDiagDC.exe (PID: 6444)
    • Gets or sets the security protocol (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Uses base64 encoding (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Uses sleep to delay execution (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Checks Windows Trust Settings

      • DellProvDiagDC.exe (PID: 6444)
    • Gets content of a file (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Reads the Windows owner or organization settings

      • DellProvDiagDC.exe (PID: 6444)
    • Reads the date of Windows installation

      • DellProvDiagDC.exe (PID: 6444)
    • Executable content was dropped or overwritten

      • csc.exe (PID: 1144)
    • Query current time using 'w32tm.exe'

      • DellProvDiagDC.exe (PID: 6444)
      • cmd.exe (PID: 732)
    • Starts CMD.EXE for commands execution

      • DellProvDiagDC.exe (PID: 6444)
    • Searches for installed software

      • reg.exe (PID: 4224)
      • reg.exe (PID: 5628)
    • The process exported the data from the registry

      • licensingdiag.exe (PID: 6488)
      • DellProvDiagDC.exe (PID: 6444)
    • Uses NSLOOKUP.EXE to check DNS info

      • licensingdiag.exe (PID: 6488)
    • Uses REG/REGEDIT.EXE to modify registry

      • DellProvDiagDC.exe (PID: 6444)
  • INFO

    • The sample compiled with english language support

      • DellProvDiagDC.exe (PID: 6444)
    • Checks supported languages

      • DellProvDiagDC.exe (PID: 6444)
      • csc.exe (PID: 1144)
      • cvtres.exe (PID: 3288)
    • Reads the machine GUID from the registry

      • DellProvDiagDC.exe (PID: 6444)
      • csc.exe (PID: 1144)
    • Reads the computer name

      • DellProvDiagDC.exe (PID: 6444)
    • Reads Environment values

      • DellProvDiagDC.exe (PID: 6444)
    • Create files in a temporary directory

      • DellProvDiagDC.exe (PID: 6444)
      • csc.exe (PID: 1144)
      • cvtres.exe (PID: 3288)
      • MdmDiagnosticsTool.exe (PID: 5464)
      • licensingdiag.exe (PID: 6488)
      • reg.exe (PID: 6708)
      • reg.exe (PID: 3808)
      • reg.exe (PID: 4224)
      • reg.exe (PID: 7000)
    • Gets or sets the time when the file was last written to (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Creates files or folders in the user directory

      • DellProvDiagDC.exe (PID: 6444)
      • licensingdiag.exe (PID: 6488)
    • Checks proxy server information

      • DellProvDiagDC.exe (PID: 6444)
      • licensingdiag.exe (PID: 6488)
      • dsregcmd.exe (PID: 6584)
    • Uses string replace method (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Reads the software policy settings

      • DellProvDiagDC.exe (PID: 6444)
      • licensingdiag.exe (PID: 6488)
      • MdmDiagnosticsTool.exe (PID: 5464)
    • Reads Windows Product ID

      • DellProvDiagDC.exe (PID: 6444)
      • licensingdiag.exe (PID: 6488)
    • Reads product name

      • DellProvDiagDC.exe (PID: 6444)
    • Process checks computer location settings

      • DellProvDiagDC.exe (PID: 6444)
    • Checks whether the specified file exists (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
    • Reads security settings of Internet Explorer

      • licensingdiag.exe (PID: 6488)
    • Creates files in the program directory

      • MdmDiagnosticsTool.exe (PID: 5464)
    • Gets data length (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:02:06 23:34:59+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 48
CodeSize: 57856
InitializedDataSize: 731648
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 1.0.0.13
ProductVersionNumber: 1.0.0.13
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: -
FileVersion: 1.0.0.13
InternalName: -
LegalCopyright: Copyright (c) 2024 All rights reserved
OriginalFileName: DellProvDiagDC
ProductVersion: 1.0.0.13
AssemblyVersion: 5.1.41.0
CompanyName: Dell Technologies
ProductName: DellProvDiagDC
Comments: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
162
Monitored processes
29
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start dellprovdiagdc.exe conhost.exe no specs csc.exe cvtres.exe no specs tiworker.exe no specs w32tm.exe no specs w32tm.exe no specs w32tm.exe no specs cmd.exe no specs w32tm.exe no specs w32tm.exe no specs w32tm.exe no specs mdmdiagnosticstool.exe no specs conhost.exe no specs licensingdiag.exe conhost.exe no specs reg.exe no specs nslookup.exe dsregcmd.exe no specs certreq.exe no specs conhost.exe no specs certutil.exe no specs conhost.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs dellprovdiagdc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
732"C:\WINDOWS\system32\cmd.exe" /c "w32tm /resync /rediscover 2>&1"C:\Windows\System32\cmd.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
1144"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\xayw2a04\xayw2a04.cmdline"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
DellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1224"C:\WINDOWS\system32\reg.exe" query HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall /sC:\Windows\System32\reg.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1988\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execertreq.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2076"C:\WINDOWS\system32\w32tm.exe" /registerC:\Windows\System32\w32tm.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Time Service Diagnostic Tool
Exit code:
2147943472
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\w32tm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
2420"C:\WINDOWS\system32\w32tm.exe" /configure "/manualpeerlist:time.windows.com time.nist.gov 0.pool.ntp.org 1.pool.ntp.org 2.pool.ntp.org" /syncfromflags:MANUAL /updateC:\Windows\System32\w32tm.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Time Service Diagnostic Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\w32tm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
3288C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES9166.tmp" "c:\Users\admin\AppData\Local\Temp\xayw2a04\CSCFC5E5B6557AC49F2A53D9901865520.TMP"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
14.32.31326.0
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3620"C:\WINDOWS\system32\w32tm.exe" /registerC:\Windows\System32\w32tm.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Time Service Diagnostic Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\w32tm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
3808"C:\WINDOWS\system32\reg.exe" export HKLM\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization C:\WINDOWS\Dell\DellProvDiag\RegistryExports\DeliveryOptimization-RegExport.reg /yC:\Windows\System32\reg.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4224"C:\WINDOWS\system32\reg.exe" export HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall "C:\WINDOWS\Dell\DellProvDiag\RegistryExports\HKLM_Software_Microsoft_Windows_CurrentVersion_Uninstall export.reg" /yC:\Windows\System32\reg.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
28 528
Read events
28 412
Write events
93
Delete events
23

Modification events

(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription
Operation:writeName:EnableTranscripting
Value:
0
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging
Operation:writeName:EnableScriptBlockLogging
Value:
0
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\AppHVSI
Operation:writeName:AllowAppHVSI_ProviderSet
Value:
0
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\EdgeUpdate
Operation:writeName:UpdateDefault
Value:
0
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\Network Connections
Operation:writeName:NC_DoNotShowLocalOnlyIcon
Value:
1
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\Windows Feeds
Operation:writeName:EnableFeeds
Value:
0
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:WUServer
Value:
http://neverupdatewindows10.com
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:WUStatusServer
Value:
http://neverupdatewindows10.com
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:UpdateServiceUrlAlternate
Value:
http://neverupdatewindows10.com
(PID) Process:(6444) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4D4015DB-17C6-464C-BC88-E6D2762A3DEA}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:**del.FillEmptyContentUrls
Value:
Executable files
9
Suspicious files
44
Text files
103
Unknown types
0

Dropped files

PID
Process
Filename
Type
6444DellProvDiagDC.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:42CFF42B997443CB256B1289A350B1B6
SHA256:5A0156E23DF8FC05ADD3ECBDC44FB33B70D86FD08DCAFAD7FBB37B2107BB629A
6444DellProvDiagDC.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:B53ADA059BC9E834CA202690FA38FFEB
SHA256:AA78D8591498CEFFB841E797C1874DC081E80BA3F863F998CD042A3EA18D3CB7
6444DellProvDiagDC.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_2dwujxg4.44q.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6444DellProvDiagDC.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ido25gzi.rld.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6444DellProvDiagDC.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:DB4572523BC0B7A17FDE1141195FA82C
SHA256:B80707733111B7B112947F010CD46D1C43700255E1A1274079CC29C08EEC4369
1144csc.exeC:\Users\admin\AppData\Local\Temp\xayw2a04\xayw2a04.dllexecutable
MD5:780EA68061B7C07476E0800801C2C71A
SHA256:F86E6BAE8FD027564495883E2AC624D0E2EF2841E5BF23522542F777FDBEA155
6444DellProvDiagDC.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_4B6E9A969F482A5761F59EDC4783D4FAbinary
MD5:FAC49A49C73B19F651AF8971CA9C8F10
SHA256:8656CF66F26657E568ED4EC59DF5180718B6185EA0C937B966D74165546A7F07
6488licensingdiag.exeC:\Users\admin\AppData\Local\Temp\DESKTOP-JGLLJLD_2025-02-05_diag\SPP\Tokens.dat
MD5:
SHA256:
1144csc.exeC:\Users\admin\AppData\Local\Temp\xayw2a04\xayw2a04.outtext
MD5:21B8A2B914A48E5CC4B0C7024F78470B
SHA256:166D28CD68BFE158A8AE08F9F48ED6CFD287C0330C32F1AC8C1C357E08061968
5604TiWorker.exeC:\Windows\Logs\CBS\CBS.logtext
MD5:0011C42FC78E38146B9B366E74F5EA81
SHA256:844C7FD8FCAB692013AFDCE6859D981CB3AAC82B9C2A029D588B4E82D4292383
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
37
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6444
DellProvDiagDC.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6444
DellProvDiagDC.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6444
DellProvDiagDC.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAwjDwP5HIldKl7pbbAKGOY%3D
unknown
whitelisted
6908
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6908
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6348
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6488
licensingdiag.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.16.110.121:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1076
svchost.exe
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6444
DellProvDiagDC.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
  • 23.52.120.96
  • 95.101.149.131
whitelisted
www.bing.com
  • 2.16.110.121
  • 2.16.110.171
  • 2.16.110.123
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.131
  • 20.190.159.0
  • 40.126.31.73
  • 20.190.159.71
  • 20.190.159.130
  • 20.190.159.68
  • 40.126.31.1
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
time.windows.com
  • 104.40.149.189
whitelisted
0.pool.ntp.org
  • 194.25.134.196
  • 88.198.7.62
  • 89.58.43.2
  • 159.69.64.189
whitelisted
1.pool.ntp.org
  • 31.209.85.243
  • 185.233.107.180
  • 79.133.44.140
  • 141.144.241.16
whitelisted
2.pool.ntp.org
  • 51.75.67.47
  • 185.41.106.152
  • 212.132.97.26
  • 194.164.164.175
whitelisted
time.nist.gov
  • 132.163.97.2
whitelisted

Threats

No threats detected
No debug info