| File name: | TMT7.application |
| Full analysis: | https://app.any.run/tasks/5ec897e8-13ce-4edc-8f9e-6420004f2600 |
| Verdict: | Malicious activity |
| Analysis date: | June 11, 2024, 09:16:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/xml |
| File info: | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (15961), with CRLF line terminators |
| MD5: | 96DEB732ED0431DC9DEC95B9D27A6EE7 |
| SHA1: | 8C3E6DD7F9B748D9D0CCF7692A9BC205370ACC23 |
| SHA256: | 2BFC39E1E23FF400AABEA1622534C815F3226C8C1F61A46A6AFFEFEA4F996E9E |
| SSDEEP: | 384:1ONP9V1kXul12SNunAuqKL/Dy7789CZAhy9gI9dNq3wKPiDDu:st71ku12SNuAurLbh9C1g+qgkiPu |
| .xml | | | Generic XML (UTF-8) (72.7) |
|---|---|---|
| .txt | | | Text - UTF-8 encoded (27.2) |
| AssemblySchemaLocation: | urn:schemas-microsoft-com:asm.v1 assembly.adaptive.xsd |
|---|---|
| AssemblyManifestVersion: | 1 |
| AssemblyXmlns: | urn:schemas-microsoft-com:asm.v2 |
| AssemblyAssemblyIdentityName: | TMT7.application |
| AssemblyAssemblyIdentityVersion: | 7.3.31026.3 |
| AssemblyAssemblyIdentityPublicKeyToken: | ac9f5adfc2cecd90 |
| AssemblyAssemblyIdentityLanguage: | neutral |
| AssemblyAssemblyIdentityProcessorArchitecture: | x86 |
| AssemblyAssemblyIdentityXmlns: | urn:schemas-microsoft-com:asm.v1 |
| AssemblyDescriptionPublisher: | Microsoft Threat Modeling Tool |
| AssemblyDescriptionSuiteName: | Threat Modeling |
| AssemblyDescriptionProduct: | Microsoft Threat Modeling Tool |
| AssemblyDescriptionSupportUrl: | https://aka.ms/tmtfeedback |
| AssemblyDescriptionErrorReportUrl: | https://aka.ms/tmtfeedback |
| AssemblyDescriptionXmlns: | urn:schemas-microsoft-com:asm.v1 |
| AssemblyDeploymentInstall: | |
| AssemblyDeploymentMapFileExtensions: | |
| AssemblyDeploymentMinimumRequiredVersion: | 7.1.50911.2 |
| AssemblyDeploymentTrustURLParameters: | |
| AssemblyDeploymentSubscriptionUpdateBeforeApplicationStartup: | - |
| AssemblyDeploymentDeploymentProviderCodebase: | https://tmtdist.azurewebsites.net/TMT7.application |
| AssemblyDependencyDependentAssemblyDependencyType: | install |
| AssemblyDependencyDependentAssemblyCodebase: | Application Files\TMT7_7_3_31026_3\TMT7.exe.manifest |
| AssemblyDependencyDependentAssemblySize: | 62988 |
| AssemblyDependencyDependentAssemblyAssemblyIdentityName: | TMT7.exe |
| AssemblyDependencyDependentAssemblyAssemblyIdentityVersion: | 7.3.31026.3 |
| AssemblyDependencyDependentAssemblyAssemblyIdentityPublicKeyToken: | ac9f5adfc2cecd90 |
| AssemblyDependencyDependentAssemblyAssemblyIdentityLanguage: | neutral |
| AssemblyDependencyDependentAssemblyAssemblyIdentityProcessorArchitecture: | x86 |
| AssemblyDependencyDependentAssemblyAssemblyIdentityType: | win32 |
| AssemblyDependencyDependentAssemblyHashTransformsTransformAlgorithm: | urn:schemas-microsoft-com:HashTransforms.Identity |
| AssemblyDependencyDependentAssemblyHashDigestMethodAlgorithm: | http://www.w3.org/2000/09/xmldsig#sha1 |
| AssemblyDependencyDependentAssemblyHashDigestValue: | qRT3ApV15WJTpzy/56wlbAFC4Lk= |
| AssemblyCompatibleFrameworksXmlns: | urn:schemas-microsoft-com:clickonce.v2 |
| AssemblyCompatibleFrameworksFrameworkTargetVersion: | 4.8 |
| AssemblyCompatibleFrameworksFrameworkProfile: | Full |
| AssemblyCompatibleFrameworksFrameworkSupportedRuntime: | 4.0.30319 |
| AssemblyPublisherIdentityName: | CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US |
| AssemblyPublisherIdentityIssuerKeyHash: | e6fc5f7bbb220058e4724eb5f421742332e6efac |
| AssemblySignatureId: | StrongNameSignature |
| AssemblySignatureXmlns: | http://www.w3.org/2000/09/xmldsig# |
| AssemblySignatureSignedInfoCanonicalizationMethodAlgorithm: | http://www.w3.org/2001/10/xml-exc-c14n# |
| AssemblySignatureSignedInfoSignatureMethodAlgorithm: | http://www.w3.org/2000/09/xmldsig#rsa-sha256 |
| AssemblySignatureSignedInfoReferenceUri: | - |
| AssemblySignatureSignedInfoReferenceTransformsTransformAlgorithm: | http://www.w3.org/2000/09/xmldsig#enveloped-signature |
| AssemblySignatureSignedInfoReferenceDigestMethodAlgorithm: | http://www.w3.org/2000/09/xmldsig#sha256 |
| AssemblySignatureSignedInfoReferenceDigestValue: | nJQrZ9XrhIW/sbbWPrc+erWLGxxEcridEpBP1mE4eP4= |
| AssemblySignatureSignatureValue: | Z4Uru44N1X373CgbBn1D1eCodsvGmYrAYWRZPHfN+qDzv3V5pCDpQ6Qavu1XH06q0wJBYH0BmPgIqwydj30kA3ZTRMmTsJ/BpcZOgiVqs0A8hweiDEEsIAXfgxlTc17EP7pEX3N9FUcHqYDXrzUAMJGFku45aDzsMqJ1uF/z58hL1BwnfqfMqZpF5gHZrfUD6rSSy6PnyLWlOr23d1qHbgkrKtD29WDZ0vky+xq0eP4Kl+Gim4KG950IMC08Dac0OHsOfkBhnlqdlUko5VBQ/u7WktlT8XQs6x2jWOS5t9MkDnm5LShQUyq9/YABxTGtqUqvSdwL3Q16sLKW2U6lDQ== |
| AssemblySignatureKeyInfoId: | StrongNameKeyInfo |
| AssemblySignatureKeyInfoKeyValueRSAKeyValueModulus: | p6eRFDDiGksqDEAmGvI+mQqbUEuyQZSvoI7yKRFVCXL2YvQyA87ZB8z0/XTEXzE4LXSIECDUAqTFYRDaJcSWVX3qbPHoOKqHtN8OO4esZnhik1CndRSwh95wF/U7mRaaDT4Q3beyovo2PpRZQNlScR4LP1rCg742xRzz64vex/HOb8URHn8CsA+5j83TI7k8da+kRZfSrOeZrxiBE7YwfU9+42A+bqtM3SnQoIGZxISbZpzMwewQj79htVkS0oVWmX01R6Vlbizok+KJKtSLW3wpz2u89GfZzJzJ52C7HHfsAgRkVhA5orFD1gVAhjpECsD3F7hEZkmTDHemqn3JEQ== |
| AssemblySignatureKeyInfoKeyValueRSAKeyValueExponent: | AQAB |
| AssemblySignatureKeyInfoRelDataLicenseGrantManifestInformationHash: | fe783861d64f90129db872441c1b8bb57a3eb73ed6b6b1bf8584ebd5672b949c |
| AssemblySignatureKeyInfoRelDataLicenseGrantManifestInformationDescription: | - |
| AssemblySignatureKeyInfoRelDataLicenseGrantManifestInformationUrl: | - |
| AssemblySignatureKeyInfoRelDataLicenseGrantManifestInformationAssemblyIdentityName: | TMT7.application |
| AssemblySignatureKeyInfoRelDataLicenseGrantManifestInformationAssemblyIdentityVersion: | 7.3.31026.3 |
| AssemblySignatureKeyInfoRelDataLicenseGrantManifestInformationAssemblyIdentityPublicKeyToken: | ac9f5adfc2cecd90 |
| AssemblySignatureKeyInfoRelDataLicenseGrantManifestInformationAssemblyIdentityLanguage: | neutral |
| AssemblySignatureKeyInfoRelDataLicenseGrantManifestInformationAssemblyIdentityProcessorArchitecture: | x86 |
| AssemblySignatureKeyInfoRelDataLicenseGrantManifestInformationAssemblyIdentityXmlns: | urn:schemas-microsoft-com:asm.v1 |
| AssemblySignatureKeyInfoRelDataLicenseGrantSignedBy: | - |
| AssemblySignatureKeyInfoRelDataLicenseGrantAuthenticodePublisherX509SubjectName: | CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureId: | AuthenticodeSignature |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureXmlns: | http://www.w3.org/2000/09/xmldsig# |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureSignedInfoCanonicalizationMethodAlgorithm: | http://www.w3.org/2001/10/xml-exc-c14n# |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureSignedInfoSignatureMethodAlgorithm: | http://www.w3.org/2000/09/xmldsig#rsa-sha256 |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureSignedInfoReferenceUri: | - |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureSignedInfoReferenceTransformsTransformAlgorithm: | http://www.w3.org/2000/09/xmldsig#enveloped-signature |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureSignedInfoReferenceDigestMethodAlgorithm: | http://www.w3.org/2000/09/xmldsig#sha256 |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureSignedInfoReferenceDigestValue: | ybo3Y06QF1X+taunC7JHLT4rV/xZCsfnz6xaxhYmNBM= |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureSignatureValue: | dKMbASNioLMR3JQmJfYTimi06NtADVu5kOU97ImIY0ybtIZTCOCLLnAcyq9yMXnqOIQIZ9d3fHm557x4qNG+F6C8C6OzVncHoiJaej2+uxXWzoNy0/br5tgnv8pz9mTGjFq8YAjdgznGOff34vaCsQZYZJd2rZ1Zhakswvg1rA6VzYfLUILTB7RgZlFmLnahW47AZ8QbIqqn2wCOxCyJCXpl+tqCk9iCKLOCS67W8omhN2NfobWRg5Srb7QdSmr2hRV4QDk5qBMs/pLUxCyFwcBrQvEYdKUDK9KN1FNVVFC82FRCK2n9ms8oOJW1OetyE9tJWWJdALgPU9gn+5y5jw== |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureKeyInfoKeyValueRSAKeyValueModulus: | p6eRFDDiGksqDEAmGvI+mQqbUEuyQZSvoI7yKRFVCXL2YvQyA87ZB8z0/XTEXzE4LXSIECDUAqTFYRDaJcSWVX3qbPHoOKqHtN8OO4esZnhik1CndRSwh95wF/U7mRaaDT4Q3beyovo2PpRZQNlScR4LP1rCg742xRzz64vex/HOb8URHn8CsA+5j83TI7k8da+kRZfSrOeZrxiBE7YwfU9+42A+bqtM3SnQoIGZxISbZpzMwewQj79htVkS0oVWmX01R6Vlbizok+KJKtSLW3wpz2u89GfZzJzJ52C7HHfsAgRkVhA5orFD1gVAhjpECsD3F7hEZkmTDHemqn3JEQ== |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureKeyInfoKeyValueRSAKeyValueExponent: | AQAB |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureKeyInfoX509DataX509Certificate: | MIIE4zCCA8ugAwIBAgITMwAABStSUWneQCpqzgAAAAAFKzANBgkqhkiG9w0BAQsFADB+MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSgwJgYDVQQDEx9NaWNyb3NvZnQgQ29kZSBTaWduaW5nIFBDQSAyMDEwMB4XDTIzMDQwNjE4MjgzMFoXDTI0MDQwMzE4MjgzMFowdDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEeMBwGA1UEAxMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp6eRFDDiGksqDEAmGvI+mQqbUEuyQZSvoI7yKRFVCXL2YvQyA87ZB8z0/XTEXzE4LXSIECDUAqTFYRDaJcSWVX3qbPHoOKqHtN8OO4esZnhik1CndRSwh95wF/U7mRaaDT4Q3beyovo2PpRZQNlScR4LP1rCg742xRzz64vex/HOb8URHn8CsA+5j83TI7k8da+kRZfSrOeZrxiBE7YwfU9+42A+bqtM3SnQoIGZxISbZpzMwewQj79htVkS0oVWmX01R6Vlbizok+KJKtSLW3wpz2u89GfZzJzJ52C7HHfsAgRkVhA5orFD1gVAhjpECsD3F7hEZkmTDHemqn3JEQIDAQABo4IBYjCCAV4wEwYDVR0lBAwwCgYIKwYBBQUHAwMwHQYDVR0OBBYEFMBDcLe7A9KFTQ1griMEz7UKjFMKMEUGA1UdEQQ+MDykOjA4MR4wHAYDVQQLExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xFjAUBgNVBAUTDTIzMjk1OSs1MDA5NjcwHwYDVR0jBBgwFoAU5vxfe7siAFjkck619CF0IzLm76wwVgYDVR0fBE8wTTBLoEmgR4ZFaHR0cDovL2NybC5taWNyb3NvZnQuY29tL3BraS9jcmwvcHJvZHVjdHMvTWljQ29kU2lnUENBXzIwMTAtMDctMDYuY3JsMFoGCCsGAQUFBwEBBE4wTDBKBggrBgEFBQcwAoY+aHR0cDovL3d3dy5taWNyb3NvZnQuY29tL3BraS9jZXJ0cy9NaWNDb2RTaWdQQ0FfMjAxMC0wNy0wNi5jcnQwDAYDVR0TAQH/BAIwADANBgkqhkiG9w0BAQsFAAOCAQEA6IlXf2il0emv5roMoecu7nKPzoiog+ElgDbhjFJT9CDnFzwlKUy+wE/cYy2/EQ7VyZtK6l9KEiEb65B38pX1t/PXbYOXzZxRdMEWHQPPQ+AAGe/Rll2nFQ0Kr0BPlQ0COQqDbfav1kAJ5x96LBAIE/UQWBD60gY+w88NKUX2refb0UJg5eZA9+6mqTezg2PBcBCibOzfDq0SveC+FbXyiGxht5cEyzOmTftAr2AUsd1sRGxHfEUE3qqwxJoM4uOda8xKuQlG3Lpt4+NthP5G3MXMFTBqNUZ6kwWsbc+Ut/OjB9NNL5wgjAJAWw72t68EQqnykeEYP8d7YdBWELzHDg== |
| AssemblySignatureKeyInfoRelDataLicenseIssuerSignatureObjectTimestamp: | MIIXlgYJKoZIhvcNAQcCoIIXhzCCF4MCAQMxDzANBglghkgBZQMEAgEFADCCAWwGCyqGSIb3DQEJEAEEoIIBWwSCAVcwggFTAgEBBgorBgEEAYRZCgMBMDEwDQYJYIZIAWUDBAIBBQAEIPE+PSsKI6woVc/R0Y1rKM4Yw3Qcxg0ERC7kLMc9JcUeAgZlKI3nSzwYEzIwMjMxMDI2MDkxMzUxLjYyM1owBIACAfQCGG/L2MYWBLyEZxsoD1szl3bSCKHhQzcbIaCB0aSBzjCByzELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjElMCMGA1UECxMcTWljcm9zb2Z0IEFtZXJpY2EgT3BlcmF0aW9uczEnMCUGA1UECxMeblNoaWVsZCBUU1MgRVNOOkRDMDAtMDVFMC1EOTQ3MSUwIwYDVQQDExxNaWNyb3NvZnQgVGltZS1TdGFtcCBTZXJ2aWNloIIR6jCCByAwggUIoAMCAQICEzMAAAHSISQxSli/LREAAQAAAdIwDQYJKoZIhvcNAQELBQAwfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEmMCQGA1UEAxMdTWljcm9zb2Z0IFRpbWUtU3RhbXAgUENBIDIwMTAwHhcNMjMwNTI1MTkxMjIxWhcNMjQwMjAxMTkxMjIxWjCByzELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjElMCMGA1UECxMcTWljcm9zb2Z0IEFtZXJpY2EgT3BlcmF0aW9uczEnMCUGA1UECxMeblNoaWVsZCBUU1MgRVNOOkRDMDAtMDVFMC1EOTQ3MSUwIwYDVQQDExxNaWNyb3NvZnQgVGltZS1TdGFtcCBTZXJ2aWNlMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA3GCIQtECP0j2k+fp2EgbEnYQTztklzONFcsoPBatUz6zDQ88QocVlA+32ysGBkrDjYLY41XneR0oeYpe+YzWnG+k62cLl/kNvvn9v/AgsrvE2NK8RCJw904+dm1s+UEVlUHo33QgP5+mc4p4XGWe/lXpVoE32Au6w64V90wV/PXpal5iEjlSFnl4kSvIfYR+kl4I4UBhkG39m0jO7hpCsyf6Wdi75U86vpjlvYj9o3GBAOG6T3rq6YJS1VEpxhkC5o0Ke0nctcBOdlozynS5wReiW5kkRDPw4/We6JMUTVI2EnYMr2dS1kopYVf8HoGF1UOj/TCo0ZxPAiOSjB5quxLB4SAStAffXRUMnS9b3bgu3lhI88+eWfw8h+h5dkjzn+SmeJR3+jFMLYGn/jHmcZFtIsYf7y9Zl/FbCUx2vAB/tJf/XZ1sxTBRSRRu4PeZxyejJmD635qHijkaMhEEbErrNqgq6TI4Pz92fViQLRRqF2DA9fTa8xuFBT6VW5dzdV7xuP7pXaNfmpwaQ2IcUFO5NYHx5+kMXVFNE7KyfyQry330vPW+FV5SGsZ1RekGYfie8S1DRrRJo+ncD86Any+86g2Sb5rL2DZNZXG8lcTCIAxT6ANn2T1xxe3cWoTNmRuwALd72RIjLQuhP3Ii0XCMM5SawYhxHpyD78VteasCAwEAAaOCAUkwggFFMB0GA1UdDgQWBBQgtp+3J0d06D/5GxGdlyRRZmdZJDAfBgNVHSMEGDAWgBSfpxVdAF5iXYP05dJlpxtTNRnpcjBfBgNVHR8EWDBWMFSgUqBQhk5odHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NybC9NaWNyb3NvZnQlMjBUaW1lLVN0YW1wJTIwUENBJTIwMjAxMCgxKS5jcmwwbAYIKwYBBQUHAQEEYDBeMFwGCCsGAQUFBzAChlBodHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NlcnRzL01pY3Jvc29mdCUyMFRpbWUtU3RhbXAlMjBQQ0ElMjAyMDEwKDEpLmNydDAMBgNVHRMBAf8EAjAAMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMIMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOCAgEAsOYqtBMtC5QHc9j3KnIUcFuXfn4rTSEgr6g9BOlvwMok5PkzN1oWE2sUNqT+jq+Kjlfg7u/y/pNfIGK9aYbIcVTFZ1zXHY3nDLU1lDlQMGyaHlh2gIJJzSDM1yt/s4LhuU1XCxIfwlTMtSeyjxPENAs+ejYFs3fbqxvrIUgypCnYTmD1xfe9DK9RghRaXtaF4xMumkvh3mr6dsJsuuZm7tAHFDjxJ/oWKoo4C10j6r7hZjjqOVJ0leug7+RXZKiu6uQ0XqMfUTxGXB1GvtgVCj46fnUNw+HPSB/O9uyozA/Dl2aJg/QPDK/33A5+RSO5X2XPIIWHO7KWCkzv9GfWEUWpoVVscayLATeS61oftfLKFyfvhHko80mHYBlmD4NeoS/+wMnceCs/1gU1JmxoolVHBPyNGkFNlP9Dc1IiBSFvNEr8Xg1p+iPoclYP7HRUgCz+SU+8AHvM077KyNoTKRFS3UrRQDKmpxWKrcGVORaALKD2e4dRJVpii2ZF5PHj7gC87TWNcrHjtE8HbniBnCMCLa5QWINV6T89fqTIRjFW5Xuih7p2iqOSv5XTjNJkEE+FY4OmW80SFUaA3AK0Of/9PO+YzlLybWMnOx5dOI3Jr4xCFwtx45FGL4BxFi9EBf+H+7ywHIWhGfN/f9xmDnah+VVZ2a1CAUAeg02lCCwwggdxMIIFWaADAgECAhMzAAAAFcXna54Cm0mZAAAAAAAVMA0GCSqGSIb3DQEBCwUAMIGIMQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMTIwMAYDVQQDEylNaWNyb3NvZnQgUm9vdCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkgMjAxMDAeFw0yMTA5MzAxODIyMjVaFw0zMDA5MzAxODMyMjVaMHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xJjAkBgNVBAMTHU1pY3Jvc29mdCBUaW1lLVN0YW1wIFBDQSAyMDEwMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA5OGmTOe0ciELeaLL1yR5vQ7VgtP97pwHB9KpbE51yMo1V/YBf2xK4OK9uT4XYDP/XE/HZveVU3Fa4n5KWv64NmeFRiMMtY0Tz3cywBAY6GB9alKDRLemjkZrBxTzxXb1hlDcwUTIcVxRMTegCjhuje3XD9gmU3w5YQJ6xKr9cmmvHaus9ja+NSZk2pg7uhp7M62AW36MEBydUv626GIl3GoPz130/o5Tz9bshVZN7928jaTjkY+yOSxRnOlwaQ3KNi1wjjHINSi947SHJMPgyY9+tVSP3PoFVZhtaDuaRr3tpK56KTesy+uDRedGbsoy1cCGMFxPLOJiss254o2I5JasAUq7vnGpF1tnYN74kpEeHT39IM9zfUGaRnXNxF803RKJ1v2lIH1+/NmeRd+2ci/bfV+AutuqfjbsNkz2K26oElHovwUDo9Fzpk03dJQcNIIP8BDyt0cY7afomXw/TNuvXsLz1dhzPUNOwTM5TI4CvEJoLhDqhFFG4tG9ahhaYQFzymeiXtcodgLiMxhy16cg8ML6EgrXY28MyTZki1ugpoMhXV8wdJGUlNi5UPkLiWHzNgY1GIRH29wb0f2y1BzFa/ZcUlFdEtsluq9QBXpsxREdcu+N+VLEhReTwDwV2xo3xwgVGD94q0W29R6HXtqPnhZyacaue7e3PmriLq0CAwEAAaOCAd0wggHZMBIGCSsGAQQBgjcVAQQFAgMBAAEwIwYJKwYBBAGCNxUCBBYEFCqnUv5kxJq+gpE8RjUpzxD/LwTuMB0GA1UdDgQWBBSfpxVdAF5iXYP05dJlpxtTNRnpcjBcBgNVHSAEVTBTMFEGDCsGAQQBgjdMg30BATBBMD8GCCsGAQUFBwIBFjNodHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL0RvY3MvUmVwb3NpdG9yeS5odG0wEwYDVR0lBAwwCgYIKwYBBQUHAwgwGQYJKwYBBAGCNxQCBAweCgBTAHUAYgBDAEEwCwYDVR0PBAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wHwYDVR0jBBgwFoAU1fZWy4/oolxiaNE9lJBb186aGMQwVgYDVR0fBE8wTTBLoEmgR4ZFaHR0cDovL2NybC5taWNyb3NvZnQuY29tL3BraS9jcmwvcHJvZHVjdHMvTWljUm9vQ2VyQXV0XzIwMTAtMDYtMjMuY3JsMFoGCCsGAQUFBwEBBE4wTDBKBggrBgEFBQcwAoY+aHR0cDovL3d3dy5taWNyb3NvZnQuY29tL3BraS9jZXJ0cy9NaWNSb29DZXJBdXRfMjAxMC0wNi0yMy5jcnQwDQYJKoZIhvcNAQELBQADggIBAJ1VffwqreEsH2cBMSRb4Z5yS/ypb+pcFLY+TkdkeLEGk5c9MTO1OdfCcTY/2mRsfNB1OW27DzHkwo/7bNGhlBgi7ulmZzpTTd2YurYeeNg2LpypglYAA7AFvonoaeC6Ce5732pvvinLbtg/SHUB2RjebYIM9W0jVOR4U3UkV7ndn/OOPcbzaN9l9qRWqveVtihVJ9AkvUCgvxm2EhIRXT0n4ECWOKz3+SmJw7wXsFSFQrP8DJ6LGYnn8AtqgcKBGUIZUnWKNsIdw2FzLixre24/LAl4FOmRsqlb30mjdAy87JGA0j3mSj5mO0+7hvoyGtmW9I/2kQH2zsZ0/fZMcm8Qq3UwxTSwethQ/gpY3UA8x1RtnWN0SCyxTkctwRQEcb9k+SS+c23Kjgm9swFXSVRk2XPXfx5bRAGOWhmRaw2fpCjcZxkoJLo4S5pu+yFUa2pFEUep8beuyOiJXk+d0tBMdrVXVAmxaQFEfnyhYWxz/gq77EFmPWn9y8FBSX5+k77L+DvktxW/tM4+pTFRhLy/AsGConsXHRWJjXD+57XQKBqJC4822rpM+Zv/Cuk0+CQ1ZyvgDbjmjJnW4SLq8CdCPSWU5nR0W2rRnj7tfqAxM328y+l7vzhwRNGQ8cirOoo6CGJ/2XBjU02N7oJtpQUQwXEGahC0HVUzWLOhcGbyoYIDTTCCAjUCAQEwgfmhgdGkgc4wgcsxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xJTAjBgNVBAsTHE1pY3Jvc29mdCBBbWVyaWNhIE9wZXJhdGlvbnMxJzAlBgNVBAsTHm5TaGllbGQgVFNTIEVTTjpEQzAwLTA1RTAtRDk0NzElMCMGA1UEAxMcTWljcm9zb2Z0IFRpbWUtU3RhbXAgU2VydmljZaIjCgEBMAcGBSsOAwIaAxUAiabSwmbBNOjbZh0MweRdU66BUgaggYMwgYCkfjB8MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSYwJAYDVQQDEx1NaWNyb3NvZnQgVGltZS1TdGFtcCBQQ0EgMjAxMDANBgkqhkiG9w0BAQsFAAIFAOjkLtwwIhgPMjAyMzEwMjYwMDE4MzZaGA8yMDIzMTAyNzAwMTgzNlowdDA6BgorBgEEAYRZCgQBMSwwKjAKAgUA6OQu3AIBADAHAgEAAgIc7zAHAgEAAgIUQzAKAgUA6OWAXAIBADA2BgorBgEEAYRZCgQCMSgwJjAMBgorBgEEAYRZCgMCoAowCAIBAAIDB6EgoQowCAIBAAIDAYagMA0GCSqGSIb3DQEBCwUAA4IBAQCpKPSQA1ETEmCORt6B9ZSejX2TCdMgGYqLUG98otxHsRoat9VAdsnFzX8MFL8vP+0isri9qOyrq7TZggmsx6sMTDSzR+kddiDFtwC07zikQxBidLnMKwlfz0/9FD9zOQxI4tDT6taYeOjnVMLbxV8uKdWvZGQl4mpIjjQP0KVIOhtSuapb0OfNQa5TvR6Qn6NKdP7jxlOBGaUe40G/GmMpk94TDyTLe5YyMNNZazGPEXGz6Yak6LLrF936Othtyy0xJ7ag22sAtEuB8OLxGmuIVe6LtULyWV8Q0IZ6PKWQpc6ucgeQLWTzgkF8fZTmPGzT8RYSCbVR5mt3SLCDSaKCMYIEDTCCBAkCAQEwgZMwfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEmMCQGA1UEAxMdTWljcm9zb2Z0IFRpbWUtU3RhbXAgUENBIDIwMTACEzMAAAHSISQxSli/LREAAQAAAdIwDQYJYIZIAWUDBAIBBQCgggFKMBoGCSqGSIb3DQEJAzENBgsqhkiG9w0BCRABBDAvBgkqhkiG9w0BCQQxIgQgfw3AJ1UMh/4OxB0aVumCJCx+Y97v9F9XrewwNYgiRJMwgfoGCyqGSIb3DQEJEAIvMYHqMIHnMIHkMIG9BCDHgCCT399IvWWzhMVOeexsFjWix9GebOuSRYGtg3mkTjCBmDCBgKR+MHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xJjAkBgNVBAMTHU1pY3Jvc29mdCBUaW1lLVN0YW1wIFBDQSAyMDEwAhMzAAAB0iEkMUpYvy0RAAEAAAHSMCIEIJwKbT0dzo6uwFioXTpibCTZ1XyxgJQk7KKecKFCy5v4MA0GCSqGSIb3DQEBCwUABIICAAhM8Z2Sdc9C1HZV8wvZINAlrpuOKLA6CJhRzElAovBZEITUJqmiWpyPKjURhnf2LEqVhO8pFWQPgsQWNQa+PeG026RYc4bJBpamgnvWTNzEJ9hfTGiyUF0czwV5yxSfcbo27nh8M7Ea3vXFb8Ukb17zm+7GBWqguG6lP0Ioc+rw7UoJMUbnn+yI24lGo/B2T7MpiSxLExaKqy/ehlsMhskQ6FTQUQUahRKCcXA74bMU2+9NDxmJEPQWhgtZufqPdS0Q7TCGKEtv2iJjc5zL9tKBZmT5Vt+xF1bilfDY9sJ8BkjDSnEFJPeLlbuPSUppP/FUHX+Cwbvg1ac9Y+z4HBRjqqNWb+OkeEv61OBaG1kaB6CeMVVL3q5hQnHblx7RiagnJCNrd/PoR3H8q6jrYTHgffUrlTaNHV7dPlzq6xSMJPEBbtFGmUZpac4zDI8ZBn9YDt1W+bGEFH9tYiiv6EIZ4SDKULzivRQwRyWnel+7HX9+pcpJ0MXUNnzAaOWzF3dVewnHd1IAfVimRu3ZudY6jzOGMOqiOfuiY7SCyy3FXOd9WV1WTXZwKUJjYCLzn7tuYWrjpMD3ibaCZgfzcOJx7jCLX8kXq2LnrlTW+4JHYZbUF12ICjMSVWHMWMD5PjRVfSgxsntNCtzDRJ2QBN0FhmRDdtksMErLyocldw5R |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1116 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4016 CREDAT:78849 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 1132 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1824 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2404 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe | rundll32.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: ClickOnce Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 2428 | "rundll32.exe" dfshim.dll,ShOpenVerbApplication C:\Users\admin\AppData\Local\Temp\TMT7.application | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2792 | "C:\Users\admin\AppData\Local\Apps\2.0\OQVLXTZK.4P5\AK6KX289.K1P\tmt7..tion_ac9f5adfc2cecd90_0007.0003_1c9507ddcd408b3c\TMT7.exe" | C:\Users\admin\AppData\Local\Apps\2.0\OQVLXTZK.4P5\AK6KX289.K1P\tmt7..tion_ac9f5adfc2cecd90_0007.0003_1c9507ddcd408b3c\TMT7.exe | dfsvc.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Threat Modeling Tool Version: 7.3.31026.3 Modules
| |||||||||||||||
| 3972 | "C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open C:\Users\admin\AppData\Local\Temp\TMT7.application.xml | C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: XML Editor Exit code: 0 Version: 14.0.4750.1000 Modules
| |||||||||||||||
| 4016 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | MSOXMLED.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 4060 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4016 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3972) MSOXMLED.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3972) MSOXMLED.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3972) MSOXMLED.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (4016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (4016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: 281490640 | |||
| (PID) Process: | (4016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31112160 | |||
| (PID) Process: | (4016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 581803140 | |||
| (PID) Process: | (4016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31112160 | |||
| (PID) Process: | (4016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (4016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4016 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\VersionManager\versionlist.xml | xml | |
MD5:CBD0581678FA40F0EDCBC7C59E0CAD10 | SHA256:159BD4343F344A08F6AF3B716B6FA679859C1BD1D7030D26FF5EF0255B86E1D9 | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\StructuredQuery.log | text | |
MD5:AD55BD80EE59AB8391FA9E5E43F56B30 | SHA256:1D0CEFA75DFDA6ED48F90F66719D2BDAFAFD5CC6BF81185F5069364D50AFD40E | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_C0427F5F77D9B3A439FC620EDAAB6177 | binary | |
MD5:03199BD9680CE3057D3EC049E14AD593 | SHA256:565F02D211A726230D0EB7214AF163F5AB19286958307F22CED3C6FCB832E518 | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118A | der | |
MD5:0AF469F9DC0DBD2391136095BC3B1557 | SHA256:F416AFA4E33E235B1489E22913983FDDAB1542BC0ADA9117B762182A33DFCC84 | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:F5C40F693AA6F72A3A72B687AA0498F5 | SHA256:8B8381CA4EBCA156C7DFD29B49BDB287363C1866EB0B9D6F9756B7E269D71731 | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118A | binary | |
MD5:A731CE8BEDF715CA6D2E18684EFCE00E | SHA256:AAF7E600D84EAD091ACCD2F9421381A545D8A8387E9DAB322F9FB40297FC3230 | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776 | binary | |
MD5:ADA3E96714FB955FC60B02B9C4383E7D | SHA256:B2E11BE0F518C91B8F61D84CEB897209A291343F0925CEBD6AD7E6B817442FAE | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\VersionManager\verB6DE.tmp | xml | |
MD5:CBD0581678FA40F0EDCBC7C59E0CAD10 | SHA256:159BD4343F344A08F6AF3B716B6FA679859C1BD1D7030D26FF5EF0255B86E1D9 | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\urlblockindex[1].bin | binary | |
MD5:FA518E3DFAE8CA3A0E495460FD60C791 | SHA256:775853600060162C4B4E5F883F9FD5A278E61C471B3EE1826396B6D129499AA7 | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{4E657293-27D3-11EF-9E36-12A9866C77DE}.dat | binary | |
MD5:FBE61F9072D8CC15177D70A303B1D85F | SHA256:76DA293A2FB453AD7BDAE12C9E445828522A1E06E2FE3587C48A0779E0037960 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4016 | iexplore.exe | GET | 304 | 199.232.214.172:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e89a37fe52d1f203 | US | — | — | unknown |
4016 | iexplore.exe | GET | 304 | 199.232.210.172:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d29c6e76b438851f | US | — | — | unknown |
4016 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D | US | binary | 314 b | unknown |
4016 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | unknown |
1088 | svchost.exe | GET | 304 | 199.232.214.172:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f33259cc05673396 | US | — | — | unknown |
4016 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D | US | binary | 471 b | unknown |
4016 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | US | binary | 471 b | unknown |
4016 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D | US | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4016 | iexplore.exe | 2.23.209.141:443 | www.bing.com | Akamai International B.V. | GB | unknown |
4016 | iexplore.exe | 199.232.214.172:80 | ctldl.windowsupdate.com | FASTLY | US | unknown |
4016 | iexplore.exe | 199.232.210.172:80 | ctldl.windowsupdate.com | FASTLY | US | unknown |
4016 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4016 | iexplore.exe | 152.199.19.161:443 | r20swj13mr.microsoft.com | EDGECAST | US | whitelisted |
1088 | svchost.exe | 199.232.214.172:80 | ctldl.windowsupdate.com | FASTLY | US | unknown |
Domain | IP | Reputation |
|---|---|---|
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
ieonline.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
www.msn.com |
| whitelisted |
tmtdist.azurewebsites.net |
| unknown |
Process | Message |
|---|---|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
|
dfsvc.exe |
*** Status originated: -1073741811
*** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
|