File name:

FiveM (1).exe

Full analysis: https://app.any.run/tasks/6221ba1f-4dc0-430b-8dd3-53c55cc18a8f
Verdict: Malicious activity
Analysis date: July 07, 2024, 03:59:40
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

C397F272B00FF8221678E28CDF0F7E3A

SHA1:

721E8237EDA2F3EBA05307B50EDB49162B06D0DC

SHA256:

2A17EECCA2D73F4F148C81938F18463887561703CEA09565EBF85DC39E5B2C65

SSDEEP:

98304:Cs1u/BuMzTdCvx4JQfXBAk9XJrCmA1bjgy1klNPB0E+0lnJyKOaB05He/tzFEeeL:u1mL+MFe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FiveM (1).exe (PID: 3968)
      • CitizenFX.exe.new (PID: 2412)
      • FiveM (1).exe (PID: 6172)
      • FiveM.exe (PID: 6300)
      • TiWorker.exe (PID: 7076)
    • Actions looks like stealing of personal data

      • FiveM.exe (PID: 6300)
      • dllhost.exe (PID: 7728)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • FiveM (1).exe (PID: 3968)
      • CitizenFX.exe.new (PID: 2412)
      • FiveM.exe (PID: 6300)
      • GameBar.exe (PID: 6672)
      • filezilla.exe (PID: 8092)
    • Reads the date of Windows installation

      • CitizenFX.exe.new (PID: 2412)
    • Starts application with an unusual extension

      • FiveM (1).exe (PID: 3968)
    • Starts itself from another location

      • CitizenFX.exe.new (PID: 2412)
      • FiveM (1).exe (PID: 6172)
    • Executable content was dropped or overwritten

      • FiveM (1).exe (PID: 6172)
      • CitizenFX.exe.new (PID: 2412)
      • FiveM (1).exe (PID: 3968)
      • FiveM.exe (PID: 6300)
      • TiWorker.exe (PID: 7076)
    • Write to the desktop.ini file (may be used to cloak folders)

      • FiveM.exe (PID: 6300)
    • Process drops legitimate windows executable

      • FiveM.exe (PID: 6300)
      • TiWorker.exe (PID: 7076)
    • Executes as Windows Service

      • vds.exe (PID: 6816)
    • Creates a software uninstall entry

      • FiveM.exe (PID: 6300)
    • The process drops C-runtime libraries

      • FiveM.exe (PID: 6300)
    • The process creates files with name similar to system file names

      • FiveM.exe (PID: 6300)
  • INFO

    • Checks supported languages

      • CitizenFX.exe.new (PID: 2412)
      • FiveM (1).exe (PID: 3968)
      • FiveM (1).exe (PID: 6172)
      • FiveM.exe (PID: 6300)
      • GameBar.exe (PID: 6672)
      • filezilla.exe (PID: 8092)
    • Reads the computer name

      • CitizenFX.exe.new (PID: 2412)
      • FiveM (1).exe (PID: 3968)
      • FiveM (1).exe (PID: 6172)
      • GameBar.exe (PID: 6672)
      • filezilla.exe (PID: 8092)
      • FiveM.exe (PID: 6300)
    • Process checks computer location settings

      • CitizenFX.exe.new (PID: 2412)
    • Creates files or folders in the user directory

      • FiveM (1).exe (PID: 6172)
      • FiveM.exe (PID: 6300)
      • filezilla.exe (PID: 8092)
    • Create files in a temporary directory

      • FiveM (1).exe (PID: 3968)
      • CitizenFX.exe.new (PID: 2412)
    • Manual execution by a user

      • filezilla.exe (PID: 8092)
      • regedit.exe (PID: 7408)
      • regedit.exe (PID: 6844)
    • Reads the software policy settings

      • TiWorker.exe (PID: 7076)
      • slui.exe (PID: 7600)
    • Reads the machine GUID from the registry

      • filezilla.exe (PID: 8092)
    • Checks transactions between databases Windows and Oracle

      • filezilla.exe (PID: 8092)
    • Reads security settings of Internet Explorer

      • dllhost.exe (PID: 7728)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:06:25 16:09:06+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.36
CodeSize: 3393024
InitializedDataSize: 1921536
UninitializedDataSize: -
EntryPoint: 0x28e3b0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.8691
ProductVersionNumber: 2.0.0.8691
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Cfx.re
FileDescription: FiveM
InternalName: FiveM
FileVersion: 2.0.0.8691
LegalCopyright: (C) 2015-2022 Cfx.re
OriginalFileName: CitizenMP.exe
ProductName: FiveM
ProductVersion: 2.0.0.8691
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
175
Monitored processes
17
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fivem (1).exe citizenfx.exe.new fivem (1).exe fivem.exe gamebarpresencewriter.exe no specs gamebar.exe no specs vdsldr.exe no specs vds.exe no specs sppextcomobj.exe no specs slui.exe filezilla.exe no specs vdsldr.exe no specs Copy/Move/Rename/Delete/Link Object tiworker.exe slui.exe no specs regedit.exe no specs regedit.exe

Process information

PID
CMD
Path
Indicators
Parent process
2412CitizenFX.exe.new -bootstrap "C:\Users\admin\AppData\Local\Temp\FiveM (1).exe"C:\Users\admin\AppData\Local\Temp\CitizenFX.exe.new
FiveM (1).exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\citizenfx.exe.new
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
c:\windows\system32\win32u.dll
3968"C:\Users\admin\AppData\Local\Temp\FiveM (1).exe" C:\Users\admin\AppData\Local\Temp\FiveM (1).exe
explorer.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.8830
Modules
Images
c:\users\admin\appdata\local\temp\fivem (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6172"C:\Users\admin\AppData\Local\Temp\FiveM (1).exe" C:\Users\admin\AppData\Local\Temp\FiveM (1).exe
CitizenFX.exe.new
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.8830
Modules
Images
c:\users\admin\appdata\local\temp\fivem (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6260C:\WINDOWS\System32\vdsldr.exe -EmbeddingC:\Windows\System32\vdsldr.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Virtual Disk Service Loader
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vdsldr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6300"C:\Users\admin\AppData\Local\FiveM\FiveM.exe"C:\Users\admin\AppData\Local\FiveM\FiveM.exe
FiveM (1).exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
1073807364
Version:
2.0.0.8830
Modules
Images
c:\users\admin\appdata\local\fivem\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
c:\windows\system32\win32u.dll
6560"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
6672"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mcaC:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\program files\windowsapps\microsoft.xboxgamingoverlay_2.34.28001.0_x64__8wekyb3d8bbwe\gamebar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\concrt140_app.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll
6816C:\WINDOWS\System32\vds.exeC:\Windows\System32\vds.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Virtual Disk Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vds.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6844"C:\WINDOWS\regedit.exe" C:\Windows\regedit.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
7076C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -EmbeddingC:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Modules Installer Worker
Version:
10.0.19041.3989 (WinBuild.160101.0800)
Modules
Images
c:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\tiworker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
Total events
53 092
Read events
53 037
Write events
49
Delete events
6

Modification events

(PID) Process:(3968) FiveM (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(2412) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2412) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2412) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2412) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6172) FiveM (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(6300) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.app\
(PID) Process:(6300) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayName
Value:
FiveM
(PID) Process:(6300) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.exe,0
(PID) Process:(6300) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:HelpLink
Value:
https://cfx.re/
Executable files
625
Suspicious files
400
Text files
273
Unknown types
7

Dropped files

PID
Process
Filename
Type
3968FiveM (1).exeC:\Users\admin\AppData\Local\Temp\CitizenFX.exe.new.tmpexecutable
MD5:EF65EFBC444E7B9F4088981E696F18A5
SHA256:E146CFCAB4F65054859C4124E2CF6EB8F61FECFF92B5E9D6428B1A3EF686F133
3968FiveM (1).exeC:\Users\admin\AppData\Local\Temp\CitizenFX.exe.newexecutable
MD5:EF65EFBC444E7B9F4088981E696F18A5
SHA256:E146CFCAB4F65054859C4124E2CF6EB8F61FECFF92B5E9D6428B1A3EF686F133
6172FiveM (1).exeC:\Users\admin\Desktop\FiveM.lnklnk
MD5:01CBE8079B3A9E977AE717637D8E9128
SHA256:32560DFBCFCEAD5B89CFFB81E2EF3F191FD5E88598E790C6D03CC766559E549F
6300FiveM.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM - Cfx.re Development Kit (FxDK).lnklnk
MD5:3D4CDC9D82C3F3B467053F2926F2FE6F
SHA256:2889000C133CF770D4CCC511966511676BEDDFD8D3647A783095B5B418A71E91
6300FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitiLaunch_TLSDummy.dll.tmpexecutable
MD5:505456B61E71997CF377B168FB495BA6
SHA256:911B21E14E6E0D89A2367F8E7965381B72B85C02ED96E97DFBBCC5F63BF84BAA
6172FiveM (1).exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM.lnklnk
MD5:086FEAEA7D731C53F7B3F75453D23EDC
SHA256:3B50AD86BAB4106F4229447E0632226926A10E66139FCA735C69DA9A4D73A93D
6300FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM - Cfx.re Development Kit (FxDK).lnklnk
MD5:D4E49CA8B5465F3D42B7B19136F838BA
SHA256:1400E77B81F960FB3344610C72BD451B573DC6F04ACE1A8EDB2F4E00E61C13F3
2412CitizenFX.exe.newC:\Users\admin\AppData\Local\Temp\FiveM (1).exeexecutable
MD5:EF65EFBC444E7B9F4088981E696F18A5
SHA256:E146CFCAB4F65054859C4124E2CF6EB8F61FECFF92B5E9D6428B1A3EF686F133
6300FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_chrome.binexecutable
MD5:D24DE909700775C27A0886E37A90D8BA
SHA256:85D2F3C53F4165BA2FC4DA291234B80E1894C31B9B0C2C9871C2E7937D277FB1
6300FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\desktop.initext
MD5:9D2F20E16EC4711FFD07D7BE13BAD063
SHA256:D6967B5C56EDD0A0D0340663EF91E4BD20981752977590B688B18060E7220682
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
93
DNS requests
25
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2808
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
7152
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
7152
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
4016
SystemSettings.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
4016
SystemSettings.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
unknown
6532
SystemSettingsAdminFlows.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
6532
SystemSettingsAdminFlows.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
1192
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
7956
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
3040
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4976
RUXIMICS.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3676
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3968
FiveM (1).exe
104.18.34.171:443
content.cfx.re
CLOUDFLARENET
unknown
4032
svchost.exe
239.255.255.250:1900
whitelisted
900
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4656
SearchApp.exe
104.126.37.145:443
Akamai International B.V.
DE
unknown
2808
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4656
SearchApp.exe
204.79.197.222:443
fp.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2808
svchost.exe
192.229.221.95:80
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
content.cfx.re
  • 104.18.34.171
  • 172.64.153.85
unknown
login.live.com
  • 20.190.159.68
  • 40.126.31.71
  • 20.190.159.75
  • 20.190.159.0
  • 20.190.159.4
  • 20.190.159.23
  • 40.126.31.73
  • 20.190.159.64
whitelisted
fp.msedge.net
  • 204.79.197.222
whitelisted
go.microsoft.com
  • 184.30.17.189
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.14
whitelisted
fp-vs.azureedge.net
  • 152.199.19.161
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.60
unknown
mcr-ring.msedge.net
  • 150.171.70.254
  • 150.171.69.254
unknown
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

No threats detected
No debug info