File name:

Driver Easy Professional 6.1.2 Build 29728 Multilingual.rar

Full analysis: https://app.any.run/tasks/02149975-3793-4129-b47a-653207754998
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: June 20, 2025, 11:10:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
lumma
stealer
inno
installer
delphi
cpuz
tool
antivm
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

16B5B4558AA30C2A6436C91DCAE4FE4C

SHA1:

29E7BD378261B466AA820339C7D7A3CF38A53CF9

SHA256:

2BB11D3B6E6DF436D52B1020AFBA1F5BAB66BF1A715E1A18F149075DF9AEDE28

SSDEEP:

196608:VgKAEMZfxZAjFLGsqvbSCix4eeZQ1pCVc96D:VgKoxZAtG4Ci76D

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LUMMA mutex has been found

      • DriverEasy_Setup.exe (PID: 4944)
      • DriverEasy_Setup.exe (PID: 2552)
  • SUSPICIOUS

    • Searches for installed software

      • DriverEasy_Setup.exe (PID: 4944)
      • DriverEasy_Setup.exe (PID: 2552)
    • Executable content was dropped or overwritten

      • Update.exe (PID: 6688)
      • Update.exe (PID: 4012)
      • Update.tmp (PID: 4944)
      • DriverEasy.exe (PID: 5620)
    • Reads security settings of Internet Explorer

      • Update.tmp (PID: 4216)
      • DriverEasy.exe (PID: 7092)
      • DriverEasy.exe (PID: 5620)
    • Reads the Windows owner or organization settings

      • Update.tmp (PID: 4944)
    • Drops 7-zip archiver for unpacking

      • Update.tmp (PID: 4944)
    • There is functionality for taking screenshot (YARA)

      • DriverEasy.exe (PID: 7092)
      • DriverEasy.exe (PID: 5620)
    • Reads the date of Windows installation

      • DriverEasy.exe (PID: 7092)
    • Application launched itself

      • DriverEasy.exe (PID: 7092)
    • Drops a system driver (possible attempt to evade defenses)

      • DriverEasy.exe (PID: 5620)
    • The process checks if it is being run in the virtual environment

      • DriverEasy.exe (PID: 5620)
    • There is functionality for VM detection VirtualBox (YARA)

      • DriverEasy.exe (PID: 5620)
  • INFO

    • Manual execution by a user

      • DriverEasy_Setup.exe (PID: 4944)
      • DriverEasy_Setup.exe (PID: 1328)
      • DriverEasy_Setup.exe (PID: 2552)
      • Update.exe (PID: 6688)
      • DriverEasy.exe (PID: 7092)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6188)
    • Reads the computer name

      • DriverEasy_Setup.exe (PID: 4944)
      • DriverEasy_Setup.exe (PID: 2552)
      • Update.tmp (PID: 4216)
      • Update.exe (PID: 4012)
      • Update.tmp (PID: 4944)
      • Easeware.CheckScheduledScan.exe (PID: 316)
      • Easeware.ConfigLanguageFromSetup.exe (PID: 2864)
      • DriverEasy.exe (PID: 7092)
      • DriverEasy.exe (PID: 5620)
    • Checks supported languages

      • DriverEasy_Setup.exe (PID: 4944)
      • DriverEasy_Setup.exe (PID: 2552)
      • Update.exe (PID: 6688)
      • Update.tmp (PID: 4216)
      • Update.exe (PID: 4012)
      • Update.tmp (PID: 4944)
      • Easeware.CheckScheduledScan.exe (PID: 316)
      • Easeware.ConfigLanguageFromSetup.exe (PID: 2864)
      • DriverEasy.exe (PID: 7092)
      • DriverEasy.exe (PID: 5620)
    • Reads the machine GUID from the registry

      • DriverEasy_Setup.exe (PID: 4944)
      • DriverEasy_Setup.exe (PID: 2552)
      • DriverEasy.exe (PID: 7092)
      • DriverEasy.exe (PID: 5620)
    • Reads the software policy settings

      • DriverEasy_Setup.exe (PID: 4944)
      • DriverEasy_Setup.exe (PID: 2552)
      • DriverEasy.exe (PID: 7092)
      • slui.exe (PID: 2512)
    • Create files in a temporary directory

      • Update.exe (PID: 6688)
      • Update.exe (PID: 4012)
      • Update.tmp (PID: 4944)
    • Process checks computer location settings

      • Update.tmp (PID: 4216)
      • DriverEasy.exe (PID: 7092)
    • The sample compiled with russian language support

      • Update.tmp (PID: 4944)
    • Creates files in the program directory

      • Update.tmp (PID: 4944)
    • Creates a software uninstall entry

      • Update.tmp (PID: 4944)
    • Creates files or folders in the user directory

      • Easeware.ConfigLanguageFromSetup.exe (PID: 2864)
    • Detects InnoSetup installer (YARA)

      • Update.tmp (PID: 4216)
      • Update.exe (PID: 6688)
    • Compiled with Borland Delphi (YARA)

      • Update.tmp (PID: 4216)
      • Update.exe (PID: 6688)
    • Reads security settings of Internet Explorer

      • dllhost.exe (PID: 4920)
    • Reads Environment values

      • DriverEasy.exe (PID: 7092)
      • DriverEasy.exe (PID: 5620)
    • The sample compiled with english language support

      • Update.tmp (PID: 4944)
      • DriverEasy.exe (PID: 5620)
    • The sample compiled with french language support

      • Update.tmp (PID: 4944)
    • Disables trace logs

      • DriverEasy.exe (PID: 7092)
    • Checks proxy server information

      • DriverEasy.exe (PID: 7092)
      • slui.exe (PID: 2512)
    • CPUZ mutex has been found

      • DriverEasy.exe (PID: 5620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
16
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs drivereasy_setup.exe no specs #LUMMA drivereasy_setup.exe #LUMMA drivereasy_setup.exe update.exe update.tmp no specs update.exe update.tmp slui.exe easeware.checkscheduledscan.exe no specs easeware.configlanguagefromsetup.exe no specs conhost.exe no specs Copy/Move/Rename/Delete/Link Object no specs drivereasy.exe drivereasy.exe

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Program Files\Easeware\DriverEasy\Easeware.CheckScheduledScan.exe" -create "Driver Easy Scheduled Scan" "C:\Program Files\Easeware\DriverEasy\DriverEasy.exe"C:\Program Files\Easeware\DriverEasy\Easeware.CheckScheduledScan.exeUpdate.tmp
User:
admin
Company:
Easeware
Integrity Level:
HIGH
Description:
Easeware.CheckScheduledScan
Exit code:
0
Version:
1.0.1.0
Modules
Images
c:\program files\easeware\drivereasy\easeware.checkscheduledscan.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1328"C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\DriverEasy_Setup.exe" C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\DriverEasy_Setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\driver easy professional 6.1.2 build 29728 multilingual\drivereasy_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1352\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeEaseware.ConfigLanguageFromSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2512C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2552"C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\DriverEasy_Setup.exe" C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\DriverEasy_Setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\driver easy professional 6.1.2 build 29728 multilingual\drivereasy_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2864"C:\Program Files\Easeware\DriverEasy\Easeware.ConfigLanguageFromSetup.exe" DriverEasy en True TrueC:\Program Files\Easeware\DriverEasy\Easeware.ConfigLanguageFromSetup.exeUpdate.tmp
User:
admin
Company:
Easeware
Integrity Level:
HIGH
Description:
Easeware.ConfigLanguageFromSetup
Exit code:
0
Version:
1.0.4.0
Modules
Images
c:\program files\easeware\drivereasy\easeware.configlanguagefromsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4012"C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Update.exe" /SPAWNWND=$20292 /NOTIFYWND=$902FE C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Update.exe
Update.tmp
User:
admin
Company:
Easeware
Integrity Level:
HIGH
Description:
Driver Easy Setup
Exit code:
0
Version:
6.1.2.29728
Modules
Images
c:\users\admin\desktop\driver easy professional 6.1.2 build 29728 multilingual\update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
4216"C:\Users\admin\AppData\Local\Temp\is-17IAG.tmp\Update.tmp" /SL5="$902FE,5886360,1001472,C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Update.exe" C:\Users\admin\AppData\Local\Temp\is-17IAG.tmp\Update.tmpUpdate.exe
User:
admin
Company:
Easeware
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-17iag.tmp\update.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4648C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
4920C:\WINDOWS\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
Total events
22 704
Read events
22 653
Write events
51
Delete events
0

Modification events

(PID) Process:(6188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Driver Easy Professional 6.1.2 Build 29728 Multilingual.rar
(PID) Process:(6188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(4944) Update.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\drivereasy
Operation:writeName:URL Protocol
Value:
C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Executable files
53
Suspicious files
7
Text files
80
Unknown types
0

Dropped files

PID
Process
Filename
Type
6188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6188.14234\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Crack\DriverEasy.exeexecutable
MD5:2AD4C29143EDAB662B5628B406C69997
SHA256:C19F96F1152AF35079EB0518F1D37DF4943B487CE129D42AB06428E15056C35D
6188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6188.14234\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Crack\Easeware.Driver.Core.dllexecutable
MD5:5FBED1A129A4B373540FBC1ABB139BD1
SHA256:1366C09D3205A0811B34505D0838AECA9BA608E536720011D894C9E0C0AD2D9C
6188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6188.14234\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Readme.txttext
MD5:4D6EFB754425805ACB799486198AB25A
SHA256:4E7F065810DCD6BB07F91D441F5311C68F5BB05355EEFE3AA2A8A5936F022A06
6188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6188.14234\Driver Easy Professional 6.1.2 Build 29728 Multilingual\DriverEasy_Setup.exeexecutable
MD5:508C9F6F267F8225A036A099B8EF00EA
SHA256:89EABA5095758C079AD0741FAB8265B33F2E54C59D120C3D39E2BE1E6D8DAA87
4944Update.tmpC:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
4944Update.tmpC:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\progressbar_installing_bg.pngimage
MD5:F89C33EA10E1E74A5800825D61F2D9CB
SHA256:19E715E35AD72909E62D955D5937D64777835A29893E906778E07BC390AEF8D0
4944Update.tmpC:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\installation_custom_bg.pngimage
MD5:F8019142C2F57318722815C32A8A6C8A
SHA256:405061A501456495890F7FC9D68BF2F0BA14AF9CBC57A5368FE20DBD8BD9AA55
4944Update.tmpC:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\checkbox_license_selected.pngimage
MD5:C482CC0A34C3DB2CC13184077E5D47DB
SHA256:EA6EFC70A57E8AD44F466181BBFA5C56059E4EEB4161A2B15E8651C86A100D09
4944Update.tmpC:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\progressbar_bg.pngimage
MD5:3FCE8F03DC579CBCE9D449BBBF8646B7
SHA256:61F7B00AE88F700A3D864D2B91A48F463430086B778C16C7197A5523B0A46934
4944Update.tmpC:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\circle.pngimage
MD5:A80F464B60816479334B6C5B39DBFF18
SHA256:B532762A4C797E209C5DA897F4A0BCED5DFA19D34DB66BAFC7455FA019BA4E17
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
47
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3100
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.55.104.172:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7092
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7092
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4692
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2940
svchost.exe
GET
200
23.209.209.135:80
http://x1.c.lencr.org/
unknown
whitelisted
3720
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2468
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2336
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
3100
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3100
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4944
DriverEasy_Setup.exe
85.90.196.155:443
gewgb.xyz
UA
unknown
5944
MoUsoCoreWorker.exe
23.55.104.172:80
crl.microsoft.com
Akamai International B.V.
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.46
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.159.68
  • 40.126.31.71
  • 40.126.31.69
  • 20.190.159.131
  • 40.126.31.131
  • 20.190.159.71
  • 20.190.159.128
  • 20.190.159.23
  • 40.126.31.0
  • 20.190.159.130
  • 20.190.159.75
  • 20.190.159.2
  • 40.126.31.2
  • 20.190.159.129
  • 20.190.159.4
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
gewgb.xyz
  • 85.90.196.155
unknown
nexusrules.officeapps.live.com
  • 52.111.236.23
whitelisted
crl.microsoft.com
  • 23.55.104.172
  • 23.55.104.190
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted

Threats

No threats detected
No debug info