File name:

WinREUpdateInstaller.exe.7z

Full analysis: https://app.any.run/tasks/e3d22879-32f9-4755-ad13-d93f07968c73
Verdict: Malicious activity
Analysis date: November 13, 2024, 11:41:21
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

DC4E1DEC5B787DB81CF6BD854D6F6306

SHA1:

D8446C5639152C74AB8E25B122A113039484FB78

SHA256:

2B4269FF3EDFC4B6AE5E117A12FC0F7152264AC06BCFB6E9D355A6878AD45E58

SSDEEP:

1536:TDSIiKwtdqQzWgruH3pxPYnQyljowiTYoYtvJRTK:TDSI3Y35ruHZxPwQmXiTYoYs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 4316)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 4316)
      • WinREUpdateInstaller.exe (PID: 6848)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 4316)
      • WinREUpdateInstaller.exe (PID: 4380)
      • WinREUpdateInstaller.exe (PID: 5792)
    • Starts a Microsoft application from unusual location

      • WinREUpdateInstaller.exe (PID: 6848)
      • WinREUpdateInstaller.exe (PID: 2280)
      • WinREUpdateInstaller.exe (PID: 6420)
      • WinREUpdateInstaller.exe (PID: 1376)
      • WinREUpdateInstaller.exe (PID: 7144)
      • WinREUpdateInstaller.exe (PID: 5792)
      • DismHost.exe (PID: 1008)
      • WinREUpdateInstaller.exe (PID: 4380)
      • DismHost.exe (PID: 2196)
    • Checks Windows Trust Settings

      • WinREUpdateInstaller.exe (PID: 6848)
    • Executable content was dropped or overwritten

      • WinREUpdateInstaller.exe (PID: 5792)
      • WinREUpdateInstaller.exe (PID: 4380)
    • Detected use of alternative data streams (AltDS)

      • WinREUpdateInstaller.exe (PID: 5792)
      • WinREUpdateInstaller.exe (PID: 4380)
    • The process creates files with name similar to system file names

      • WinREUpdateInstaller.exe (PID: 5792)
      • WinREUpdateInstaller.exe (PID: 4380)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 4316)
    • Checks supported languages

      • WinREUpdateInstaller.exe (PID: 6848)
    • Sends debugging messages

      • WinREUpdateInstaller.exe (PID: 6848)
      • WinREUpdateInstaller.exe (PID: 2280)
      • WinREUpdateInstaller.exe (PID: 6420)
      • WinREUpdateInstaller.exe (PID: 1376)
      • WinREUpdateInstaller.exe (PID: 5792)
      • WinREUpdateInstaller.exe (PID: 7144)
      • DismHost.exe (PID: 1008)
      • WinREUpdateInstaller.exe (PID: 4380)
      • DismHost.exe (PID: 2196)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4316)
    • Reads the machine GUID from the registry

      • WinREUpdateInstaller.exe (PID: 6848)
    • Reads the computer name

      • WinREUpdateInstaller.exe (PID: 6848)
    • Manual execution by a user

      • WinREUpdateInstaller.exe (PID: 6420)
      • WinREUpdateInstaller.exe (PID: 1376)
      • WinREUpdateInstaller.exe (PID: 7144)
      • WinREUpdateInstaller.exe (PID: 5792)
      • WinREUpdateInstaller.exe (PID: 4380)
    • Create files in a temporary directory

      • WinREUpdateInstaller.exe (PID: 5792)
      • WinREUpdateInstaller.exe (PID: 4380)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2024:11:13 11:37:42+00:00
ArchivedFileName: WinREUpdateInstaller.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
14
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe winreupdateinstaller.exe winreupdateinstaller.exe sppextcomobj.exe no specs slui.exe winreupdateinstaller.exe slui.exe winreupdateinstaller.exe winreupdateinstaller.exe winreupdateinstaller.exe dismhost.exe tiworker.exe no specs winreupdateinstaller.exe dismhost.exe

Process information

PID
CMD
Path
Indicators
Parent process
1008C:\Users\admin\AppData\Local\Temp\3629C76F-98EB-4E4F-ACF4-C8B9D6A5727D\dismhost.exe {844BBBF9-058D-4EB3-83A3-E1A2DCA32CE2}C:\Users\admin\AppData\Local\Temp\3629C76F-98EB-4E4F-ACF4-C8B9D6A5727D\DismHost.exe
WinREUpdateInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Dism Host Servicing Process
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\3629c76f-98eb-4e4f-acf4-c8b9d6a5727d\dismhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1376"C:\Users\admin\Desktop\WinREUpdateInstaller.exe" C:\Users\admin\Desktop\WinREUpdateInstaller.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Recovery Environment Update Installer
Exit code:
5
Version:
10.0.19041.5129 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\desktop\winreupdateinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp_win.dll
1732C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
2196C:\Users\admin\AppData\Local\Temp\BDED8D0A-7653-4E1F-B068-9AC8ABA95FA4\dismhost.exe {94DC4134-84E0-400E-ACF6-00170C60F2F3}C:\Users\admin\AppData\Local\Temp\BDED8D0A-7653-4E1F-B068-9AC8ABA95FA4\DismHost.exe
WinREUpdateInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Dism Host Servicing Process
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\bded8d0a-7653-4e1f-b068-9ac8aba95fa4\dismhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2280"C:\Users\admin\AppData\Local\Temp\Rar$EXb4316.43311\WinREUpdateInstaller.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb4316.43311\WinREUpdateInstaller.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Recovery Environment Update Installer
Exit code:
5
Version:
10.0.19041.5129 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb4316.43311\winreupdateinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp_win.dll
4316"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\WinREUpdateInstaller.exe.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4380"C:\Users\admin\Desktop\WinREUpdateInstaller.exe" C:\Users\admin\Desktop\WinREUpdateInstaller.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Recovery Environment Update Installer
Exit code:
13
Version:
10.0.19041.5129 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\desktop\winreupdateinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4464"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5792"C:\Users\admin\Desktop\WinREUpdateInstaller.exe" C:\Users\admin\Desktop\WinREUpdateInstaller.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Recovery Environment Update Installer
Exit code:
13
Version:
10.0.19041.5129 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\desktop\winreupdateinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6420"C:\Users\admin\Desktop\WinREUpdateInstaller.exe" C:\Users\admin\Desktop\WinREUpdateInstaller.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Recovery Environment Update Installer
Exit code:
5
Version:
10.0.19041.5129 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\desktop\winreupdateinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
13 048
Read events
13 025
Write events
23
Delete events
0

Modification events

(PID) Process:(4316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(4316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\WinREUpdateInstaller.exe.7z
(PID) Process:(4316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(4316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
1
(PID) Process:(6492) TiWorker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing
Operation:writeName:SessionIdHigh
Value:
31143361
(PID) Process:(6492) TiWorker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing
Operation:writeName:SessionIdLow
Value:
Executable files
103
Suspicious files
0
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
4316WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4316.46807\WinREUpdateInstaller.exeexecutable
MD5:8DC05137F71B14CD5BB13656B2941C30
SHA256:B4CF2F1804FAC5BE631A41F4BD2E7639B779E83AE9D0111F4EB415432B2F62D3
5792WinREUpdateInstaller.exeC:\Users\admin\AppData\Local\Temp\3629C76F-98EB-4E4F-ACF4-C8B9D6A5727D\AppxProvider.dllexecutable
MD5:396C483D62FEA5FA0FD442C8DC99D4EF
SHA256:36F2AF43F10FD76FEEF65BF574D79D3E27FD40DAF61249880511543C1F17AD91
4316WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb4316.40985\WinREUpdateInstaller.exeexecutable
MD5:8DC05137F71B14CD5BB13656B2941C30
SHA256:B4CF2F1804FAC5BE631A41F4BD2E7639B779E83AE9D0111F4EB415432B2F62D3
4316WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb4316.43311\WinREUpdateInstaller.exeexecutable
MD5:8DC05137F71B14CD5BB13656B2941C30
SHA256:B4CF2F1804FAC5BE631A41F4BD2E7639B779E83AE9D0111F4EB415432B2F62D3
5792WinREUpdateInstaller.exeC:\Users\admin\AppData\Local\Temp\3629C76F-98EB-4E4F-ACF4-C8B9D6A5727D\CbsProvider.dllexecutable
MD5:14932441A96E254B3D29D452CE1263A0
SHA256:8FFF21CB7C88A0DD8C8E7B386604001F2974E75D229369A87BEE0BA18DA575F3
5792WinREUpdateInstaller.exeC:\Windows\Logs\DISM\dism.logtext
MD5:EE082071DBA12D487850BB2248D27DF2
SHA256:0ECD997A6C7889492718654C8F9C6761F8BAF243B41E30F788F0948B815565B8
5792WinREUpdateInstaller.exeC:\Users\admin\AppData\Local\Temp\3629C76F-98EB-4E4F-ACF4-C8B9D6A5727D\DismCore.dllexecutable
MD5:681186B5696BA7D46B6681C027A659AD
SHA256:FBB5135DE4F6A5C9422A0B218D676930DB9BC9A2AEA0F7219077862912455914
5792WinREUpdateInstaller.exeC:\Users\admin\AppData\Local\Temp\3629C76F-98EB-4E4F-ACF4-C8B9D6A5727D\DismHost.exeexecutable
MD5:97CB1E2FCAB378421C4B91DF0C9F8310
SHA256:E36BCF02BC11F560761E943D0FAD37417078F6CBB473F85C72FCBC89E2600C58
5792WinREUpdateInstaller.exeC:\Users\admin\AppData\Local\Temp\3629C76F-98EB-4E4F-ACF4-C8B9D6A5727D\en-US\DismCore.dll.muiexecutable
MD5:7A15F6E845F0679DE593C5896FE171F9
SHA256:F91E3C35B472F95D7B1AE3DC83F9D6BFDE33515AA29E8B310F55D9FE66466419
5792WinREUpdateInstaller.exeC:\Users\admin\AppData\Local\Temp\3629C76F-98EB-4E4F-ACF4-C8B9D6A5727D\en-US\DmiProvider.dll.muiexecutable
MD5:B7252234AA43B7295BB62336ADC1B85C
SHA256:73709C25DC5300A435E53DF97FC01A7DC184B56796CAE48EE728D54D26076D6C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
42
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6228
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6944
svchost.exe
GET
200
2.16.164.97:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7028
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6304
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6228
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1584
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6944
svchost.exe
2.16.164.97:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
6944
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
2.23.209.185:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.46
whitelisted
crl.microsoft.com
  • 2.16.164.97
  • 2.16.164.51
  • 2.16.164.81
  • 2.16.164.43
  • 2.16.164.106
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 95.101.149.131
whitelisted
www.bing.com
  • 2.23.209.185
  • 2.23.209.182
  • 2.23.209.188
  • 2.23.209.192
  • 2.23.209.181
  • 2.23.209.191
  • 2.23.209.179
  • 2.23.209.183
  • 2.23.209.187
  • 2.16.110.145
  • 2.16.110.139
  • 2.16.110.171
  • 2.16.110.154
  • 2.16.110.121
  • 2.16.110.168
  • 2.16.110.146
  • 2.16.110.131
  • 2.16.110.203
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.68
  • 40.126.31.71
  • 20.190.159.2
  • 20.190.159.0
  • 40.126.31.69
  • 40.126.31.73
  • 20.190.159.71
  • 20.190.159.75
whitelisted
th.bing.com
  • 2.23.209.160
  • 2.23.209.142
  • 2.23.209.150
  • 2.23.209.143
  • 2.23.209.149
  • 2.23.209.161
  • 2.23.209.158
  • 2.23.209.166
  • 2.23.209.144
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted

Threats

No threats detected
Process
Message
WinREUpdateInstaller.exe
Warn: [WinREUpdInst] WinREAgent.dll module in sandbox failed trust verification, falling back to loading from System32
WinREUpdateInstaller.exe
Warn: [WinREUpdInst] Unable to verify WinRE Agent Module Path [C:\Users\admin\AppData\Local\Temp\Rar$EXb4316.40985\WinREAgent.dll], attempting to load from System32: [0x8009202B]
WinREUpdateInstaller.exe
0x8000ffff in PushButtonReset::Logging::BeginFileLog (base\reset\util\src\logging.cpp:59): WdsInitialize failed
WinREUpdateInstaller.exe
0x8000ffff in WinREAgent::LogAutoRelease::LogAutoRelease (base\diagnosis\srt\winreagent\dll\logautorelease.cpp:48): Failed to initialize log file
WinREUpdateInstaller.exe
0x80070005 in PbrDeleteDirectory (base\reset\util\src\filesystem.cpp:2948): Failed to delete directory [\\?\C:\$WinREAgent\Scratch]
WinREUpdateInstaller.exe
0x80070005 in WinREAgent::WorkDir::CleanupScratchDir (base\diagnosis\srt\winreagent\lib\operations\src\workdir.cpp:155): Failed to delete scratch dir
WinREUpdateInstaller.exe
0x80070005 in PushButtonReset::Directory::Delete (base\reset\util\src\filesystem.cpp:2981): Failed to recursively delete [C:\$WinREAgent\Scratch]
WinREUpdateInstaller.exe
0x80070005 in GetWinREServicingManager (base\diagnosis\srt\winreagent\tools\winreupdateinstaller\servicinghelper.cpp:96): [WinREUpdInst] Failed to create WinREServicingManager
WinREUpdateInstaller.exe
0x80070005 in PushButtonReset::Directory::Delete (base\reset\util\src\filesystem.cpp:2981): Failed to recursively delete [C:\$WinREAgent]
WinREUpdateInstaller.exe
0x80070005 in WinREAgent::WorkDir::CreateDirs (base\diagnosis\srt\winreagent\lib\operations\src\workdir.cpp:54): Failed to create root dir [C:\$WinREAgent]