File name:

DellProvDiagDC.exe

Full analysis: https://app.any.run/tasks/70d2debb-fe1d-4269-bcf7-19823ec1c32a
Verdict: Malicious activity
Analysis date: February 07, 2025, 07:05:41
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
fody
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
MD5:

CDB9CBEBDF83CC595E5FB63CBD375478

SHA1:

326636B77B635F53E61E9129F95EBD816BAC6891

SHA256:

29B250B12F0B93DD8FECB7B8D15D8D53D4AFEF82CDA426C2E6C5A43F97D833A1

SSDEEP:

6144:tZfQIYZvK1VGn1idZ4xqdYhHgliE3G8h49cVBPJAcQRjEuvMd0hdx6YLp5:tZfQIH1VGn1idb85

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the Windows auto-update feature

      • DellProvDiagDC.exe (PID: 6316)
    • Dynamically loads an assembly (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6316)
    • Creates or modifies Windows services

      • w32tm.exe (PID: 5592)
  • SUSPICIOUS

    • Process checks is Powershell's Script Block Logging on

      • DellProvDiagDC.exe (PID: 6316)
    • Process checks is Powershell's transcription on

      • DellProvDiagDC.exe (PID: 6316)
    • Reads security settings of Internet Explorer

      • DellProvDiagDC.exe (PID: 6316)
    • Gets or sets the security protocol (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6316)
    • Gets content of a file (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6316)
    • Uses base64 encoding (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6316)
    • Uses sleep to delay execution (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6316)
    • Reads the date of Windows installation

      • DellProvDiagDC.exe (PID: 6316)
    • Executable content was dropped or overwritten

      • csc.exe (PID: 6308)
    • Query current time using 'w32tm.exe'

      • DellProvDiagDC.exe (PID: 6316)
      • cmd.exe (PID: 5740)
    • Reads the Windows owner or organization settings

      • DellProvDiagDC.exe (PID: 6316)
    • Starts CMD.EXE for commands execution

      • DellProvDiagDC.exe (PID: 6316)
    • The process exported the data from the registry

      • licensingdiag.exe (PID: 3992)
      • DellProvDiagDC.exe (PID: 6316)
    • Uses NSLOOKUP.EXE to check DNS info

      • licensingdiag.exe (PID: 3992)
    • Searches for installed software

      • reg.exe (PID: 6356)
      • reg.exe (PID: 6312)
    • Checks Windows Trust Settings

      • DellProvDiagDC.exe (PID: 6316)
    • Gets file extension (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6316)
    • Uses SYSTEMINFO.EXE to read the environment

      • DellProvDiagDC.exe (PID: 6316)
    • Process uses IPCONFIG to discover network configuration

      • DellProvDiagDC.exe (PID: 6316)
    • Suspicious use of NETSH.EXE

      • DellProvDiagDC.exe (PID: 6316)
    • Uses REG/REGEDIT.EXE to modify registry

      • DellProvDiagDC.exe (PID: 6316)
  • INFO

    • The sample compiled with english language support

      • DellProvDiagDC.exe (PID: 6316)
    • Checks supported languages

      • DellProvDiagDC.exe (PID: 6316)
      • csc.exe (PID: 6308)
      • cvtres.exe (PID: 5300)
    • Reads the computer name

      • DellProvDiagDC.exe (PID: 6316)
    • Create files in a temporary directory

      • DellProvDiagDC.exe (PID: 6316)
      • cvtres.exe (PID: 5300)
      • csc.exe (PID: 6308)
      • MdmDiagnosticsTool.exe (PID: 6740)
      • licensingdiag.exe (PID: 3992)
      • reg.exe (PID: 4160)
      • reg.exe (PID: 6356)
      • reg.exe (PID: 5004)
      • reg.exe (PID: 1596)
    • Reads the machine GUID from the registry

      • DellProvDiagDC.exe (PID: 6316)
      • csc.exe (PID: 6308)
    • Reads Environment values

      • DellProvDiagDC.exe (PID: 6316)
    • Gets or sets the time when the file was last written to (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6316)
    • Uses string replace method (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6316)
    • Creates files or folders in the user directory

      • DellProvDiagDC.exe (PID: 6316)
      • licensingdiag.exe (PID: 3992)
    • Checks proxy server information

      • DellProvDiagDC.exe (PID: 6316)
      • licensingdiag.exe (PID: 3992)
      • dsregcmd.exe (PID: 4704)
      • dsregcmd.exe (PID: 5320)
    • Reads the software policy settings

      • DellProvDiagDC.exe (PID: 6316)
      • licensingdiag.exe (PID: 3992)
      • MdmDiagnosticsTool.exe (PID: 6740)
    • Reads Windows Product ID

      • DellProvDiagDC.exe (PID: 6316)
      • licensingdiag.exe (PID: 3992)
    • Reads product name

      • DellProvDiagDC.exe (PID: 6316)
    • Process checks computer location settings

      • DellProvDiagDC.exe (PID: 6316)
    • Detects Fody packer (YARA)

      • DellProvDiagDC.exe (PID: 6316)
    • Checks whether the specified file exists (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6316)
    • Reads security settings of Internet Explorer

      • licensingdiag.exe (PID: 3992)
    • Creates files in the program directory

      • MdmDiagnosticsTool.exe (PID: 6740)
    • Gets data length (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6316)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • DellProvDiagDC.exe (PID: 6316)
    • Disables trace logs

      • DellProvDiagDC.exe (PID: 6316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:02:06 23:34:59+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 48
CodeSize: 57856
InitializedDataSize: 731648
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 1.0.0.13
ProductVersionNumber: 1.0.0.13
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: -
FileVersion: 1.0.0.13
InternalName: -
LegalCopyright: Copyright (c) 2024 All rights reserved
OriginalFileName: DellProvDiagDC
ProductVersion: 1.0.0.13
AssemblyVersion: 5.1.41.0
CompanyName: Dell Technologies
ProductName: DellProvDiagDC
Comments: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
34
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start dellprovdiagdc.exe conhost.exe no specs csc.exe cvtres.exe no specs tiworker.exe no specs w32tm.exe no specs w32tm.exe no specs w32tm.exe no specs cmd.exe no specs w32tm.exe no specs w32tm.exe no specs w32tm.exe no specs mdmdiagnosticstool.exe no specs conhost.exe no specs licensingdiag.exe conhost.exe no specs reg.exe no specs nslookup.exe dsregcmd.exe no specs certreq.exe no specs conhost.exe no specs certutil.exe no specs conhost.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs dsregcmd.exe no specs systeminfo.exe no specs ipconfig.exe no specs netsh.exe no specs rundll32.exe no specs dellprovdiagdc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
628"C:\WINDOWS\system32\systeminfo.exe"C:\Windows\System32\systeminfo.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Displays system information
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\systeminfo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1596"C:\WINDOWS\system32\reg.exe" export HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall "C:\WINDOWS\Dell\DellProvDiag\RegistryExports\HKLM_SOFTWARE_WOW6432Node_Microsoft_Windows_CurrentVersion_Uninstall export.reg" /yC:\Windows\System32\reg.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2132"C:\WINDOWS\system32\nslookup.exe" -type=srv _vlmcs._tcpC:\Windows\System32\nslookup.exe
licensingdiag.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
nslookup
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\nslookup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
2612"C:\WINDOWS\system32\ipconfig.exe" /allC:\Windows\System32\ipconfig.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IP Configuration Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\dhcpcsvc.dll
2632"C:\WINDOWS\System32\certutil.exe" -tpminfo -vC:\Windows\System32\certutil.exeMdmDiagnosticsTool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
CertUtil.exe
Exit code:
2148073520
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\certutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
3076"C:\WINDOWS\system32\w32tm.exe" /configure "/manualpeerlist:time.windows.com time.nist.gov 0.pool.ntp.org 1.pool.ntp.org 2.pool.ntp.org" /syncfromflags:MANUAL /updateC:\Windows\System32\w32tm.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Time Service Diagnostic Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\w32tm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
3080w32tm /resync /rediscover C:\Windows\System32\w32tm.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Time Service Diagnostic Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\w32tm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
3260"C:\WINDOWS\system32\w32tm.exe" /unregisterC:\Windows\System32\w32tm.exeDellProvDiagDC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Time Service Diagnostic Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\w32tm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
3564"C:\Users\admin\AppData\Local\Temp\DellProvDiagDC.exe" C:\Users\admin\AppData\Local\Temp\DellProvDiagDC.exeexplorer.exe
User:
admin
Company:
Dell Technologies
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.0.0.13
Modules
Images
c:\users\admin\appdata\local\temp\dellprovdiagdc.exe
c:\windows\system32\ntdll.dll
3832\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exelicensingdiag.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
40 834
Read events
40 700
Write events
109
Delete events
25

Modification events

(PID) Process:(6316) DellProvDiagDC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription
Operation:writeName:EnableTranscripting
Value:
0
(PID) Process:(6316) DellProvDiagDC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging
Operation:writeName:EnableScriptBlockLogging
Value:
0
(PID) Process:(6316) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A62EF79F-9370-40E0-9CC1-972D0E5B0010}Machine\Software\Policies\Microsoft\AppHVSI
Operation:writeName:AllowAppHVSI_ProviderSet
Value:
0
(PID) Process:(6316) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A62EF79F-9370-40E0-9CC1-972D0E5B0010}Machine\Software\Policies\Microsoft\EdgeUpdate
Operation:writeName:UpdateDefault
Value:
0
(PID) Process:(6316) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A62EF79F-9370-40E0-9CC1-972D0E5B0010}Machine\Software\Policies\Microsoft\Windows\Network Connections
Operation:writeName:NC_DoNotShowLocalOnlyIcon
Value:
1
(PID) Process:(6316) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A62EF79F-9370-40E0-9CC1-972D0E5B0010}Machine\Software\Policies\Microsoft\Windows\Windows Feeds
Operation:writeName:EnableFeeds
Value:
0
(PID) Process:(6316) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A62EF79F-9370-40E0-9CC1-972D0E5B0010}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:WUServer
Value:
http://neverupdatewindows10.com
(PID) Process:(6316) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A62EF79F-9370-40E0-9CC1-972D0E5B0010}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:WUStatusServer
Value:
http://neverupdatewindows10.com
(PID) Process:(6316) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A62EF79F-9370-40E0-9CC1-972D0E5B0010}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:UpdateServiceUrlAlternate
Value:
http://neverupdatewindows10.com
(PID) Process:(6316) DellProvDiagDC.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A62EF79F-9370-40E0-9CC1-972D0E5B0010}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
Operation:writeName:**del.FillEmptyContentUrls
Value:
Executable files
9
Suspicious files
47
Text files
106
Unknown types
0

Dropped files

PID
Process
Filename
Type
6316DellProvDiagDC.exeC:\Windows\Dell\DellProvDiag\DO_Information\DO_PerfSnap.logtext
MD5:DF1C5474E0DDDBF2F2022C02456A2EDE
SHA256:FCB49318DA15987A39B3B2187C628ABB0EA9013C8B97CB077E5C8A77996462F5
6308csc.exeC:\Users\admin\AppData\Local\Temp\m1oacys1\m1oacys1.outtext
MD5:B291289758C69A4AEE7B501AAAACE6CA
SHA256:B8727717F0635C7EDA2640BD0CBBB5193C6DC2135FA455F31E788DF46820FD3E
6316DellProvDiagDC.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:632999300242B2BB2EEE15304CE23E96
SHA256:2870635D96330740A9630AC864C6C9805A36215ADBAC19C681748488B4A9EF91
6316DellProvDiagDC.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_xnbbx1p0.22c.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6316DellProvDiagDC.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_4B6E9A969F482A5761F59EDC4783D4FAbinary
MD5:F66E756FF7F96AB194A0E960E114C626
SHA256:8C8B1410532B0A2CE05E4DA46E22A72BA37E99D33360C845F65EE4424E17C8E4
6316DellProvDiagDC.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:4DC543ADE5D8B66BE03DB927FE601100
SHA256:1E59AD5946830562D88A0F020031C2363BE3183861CA5C059958F2B6D20B3C0E
6316DellProvDiagDC.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_rn5tvsjo.xfb.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
3992licensingdiag.exeC:\Users\admin\AppData\Local\Temp\DESKTOP-JGLLJLD_2025-02-07_diag\SPP\Tokens.dat
MD5:
SHA256:
6316DellProvDiagDC.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:DBB76E74E018C5905B8634D3D909B6A0
SHA256:B59B62EC587F1C1FEECCA295F576B794AF947546710EA308F895FA11E0BAA496
6316DellProvDiagDC.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:C7187584BBCEA4F96751077447515E8B
SHA256:CC6704CC4CA24D778F91B9AD2FE903ADE51FE2AB07DBF07C3B3F8A17E9645ED6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
42
DNS requests
57
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5208
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5208
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6316
DellProvDiagDC.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
6316
DellProvDiagDC.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6316
DellProvDiagDC.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAwjDwP5HIldKl7pbbAKGOY%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5208
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5208
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
20.190.160.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.17.190.73:80
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
  • 2.16.164.120
  • 2.16.164.72
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
login.live.com
  • 20.190.160.64
  • 20.190.160.3
  • 20.190.160.128
  • 20.190.160.66
  • 20.190.160.132
  • 20.190.160.130
  • 40.126.32.68
  • 40.126.32.133
  • 20.190.160.131
  • 20.190.160.2
  • 20.190.160.20
  • 20.190.160.4
  • 40.126.32.136
  • 40.126.32.74
  • 20.190.160.17
  • 40.126.32.72
  • 20.190.160.22
  • 20.190.160.14
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
time.windows.com
  • 104.40.149.189
whitelisted
0.pool.ntp.org
  • 185.232.69.65
  • 88.198.53.80
  • 5.45.104.115
  • 213.239.234.28
whitelisted
1.pool.ntp.org
  • 129.70.132.33
  • 185.228.138.224
  • 130.162.220.39
  • 131.234.220.231
whitelisted
2.pool.ntp.org
  • 173.249.58.145
  • 185.11.138.90
  • 116.202.118.202
  • 51.75.67.47
whitelisted
time.nist.gov
  • 132.163.96.2
whitelisted

Threats

PID
Process
Class
Message
6316
DellProvDiagDC.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
6316
DellProvDiagDC.exe
Misc activity
ET INFO Microsoft Connection Test
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Blob Storage (.blob .core .windows .net)
No debug info