File name:

striata-reader (2).vir

Full analysis: https://app.any.run/tasks/5583f884-a72d-4368-b8dd-f4238363cc07
Verdict: Malicious activity
Analysis date: July 04, 2025, 12:26:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

334D397FD7AEC4F4474EA696D78DCE92

SHA1:

47BDC95DE9484907533AE08A956E2A9FD2260B8D

SHA256:

2D0029ACD8B2A299839EB5ECF0C738294E54BE50016339E6D4A6C84273217200

SSDEEP:

49152:6nm0Z3MmWT9FbPMbeOgNZzA/ube6ZBlxA5+5jCJn+gXudcZxfgpD9in06JQFu0oG:6n/STfbPMbeBZM/9MBlxA5tR+gXuQxf4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • striata-reader (2).vir.exe (PID: 6172)
      • striata-reader (2).vir.exe (PID: 7104)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • striata-reader (2).vir.exe (PID: 6172)
    • Creates a software uninstall entry

      • striata-reader (2).vir.exe (PID: 6172)
    • The process drops C-runtime libraries

      • striata-reader (2).vir.exe (PID: 6172)
    • Creates/Modifies COM task schedule object

      • striata-reader (2).vir.exe (PID: 6172)
    • Process drops legitimate windows executable

      • striata-reader (2).vir.exe (PID: 6172)
    • There is functionality for taking screenshot (YARA)

      • striata-reader (2).vir.exe (PID: 6172)
  • INFO

    • Checks supported languages

      • striata-reader (2).vir.exe (PID: 6172)
      • identity_helper.exe (PID: 6840)
    • Create files in a temporary directory

      • striata-reader (2).vir.exe (PID: 6172)
    • Reads the machine GUID from the registry

      • striata-reader (2).vir.exe (PID: 6172)
    • Creates files in the program directory

      • striata-reader (2).vir.exe (PID: 6172)
    • The sample compiled with english language support

      • striata-reader (2).vir.exe (PID: 6172)
    • Reads the computer name

      • striata-reader (2).vir.exe (PID: 6172)
      • identity_helper.exe (PID: 6840)
    • Manual execution by a user

      • msedge.exe (PID: 5244)
    • Reads Environment values

      • identity_helper.exe (PID: 6840)
    • Application launched itself

      • msedge.exe (PID: 5244)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2021:04:01 07:29:32+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.16
CodeSize: 96256
InitializedDataSize: 1291776
UninitializedDataSize: -
EntryPoint: 0x213c
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 2.31.2.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (1C09)
CharacterSet: Unicode
CompanyName: Doxim LLC
Internet: http://www.striata.com
E-mail: info@striata.com
FileDescription: Striata Reader
FileVersion: 2.31-2
LegalCopyright: Copyright Doxim LLC, 2020-2021
OriginalFileName: striata-reader
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
172
Monitored processes
30
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start striata-reader (2).vir.exe msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs striata-reader (2).vir.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2064"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=7936,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=7924 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2124"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --instant-process --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3640,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=3904 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2876"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3624,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=3656 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3488"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5616,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=5688 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3564"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4280,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=4328 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4752"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5924,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=6064 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4764"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --disable-quic --onnx-enabled-for-ee --string-annotations --always-read-main-dll --field-trial-handle=5752,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=5260 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5184"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2408,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=2404 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5244"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=DefaultC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5432"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2768,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=2780 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
7 916
Read events
7 832
Write events
81
Delete events
3

Modification events

(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sed
Operation:delete valueName:PerceivedType
Value:
text
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sed
Operation:delete keyName:(default)
Value:
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Operation:writeName:{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Value:
Striata Encrypted Document
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
19
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Operation:writeName:UninstallString
Value:
rundll32.exe "C:\Program Files\Striata-Reader\keymail.dll",UninstallDll --local-machine
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Operation:writeName:DisplayName
Value:
Striata Reader (64-bit)
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Operation:writeName:URLInfoAbout
Value:
http://www.striata.com
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Operation:writeName:Publisher
Value:
Doxim LLC
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Operation:writeName:DisplayVersion
Value:
2.31-2
Executable files
129
Suspicious files
678
Text files
128
Unknown types
20

Dropped files

PID
Process
Filename
Type
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\dll4B61.tmpcompressed
MD5:D38DBE54A48CE0E5942C2DA9366423A2
SHA256:71505888D2C184BB9E40BC433F578D71D0A30513F1FD80DA4DE5BB00096F6451
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\dll4B94.tmpcompressed
MD5:D57C4325B509403B1A307D65B4355ED9
SHA256:ED49A97AFE7D3EDA08DD78B9B7C649BD1427CC7B3837330F5010A81C6CF644D7
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\striata-reader.runtime.manifestxml
MD5:8470EA5C95D1D00656BBEE5191C9738D
SHA256:4275CC74EC6E12A70BC12AE19B0ED965C79F9FA495F9C92B4EF814D08CA48263
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:5A75A7940BC8762E41DAFCCE9C07628B
SHA256:4AAF273C4CB1D93B8C8686843FFBC577D31E1C010E02AE8E72478C5B52DDA06D
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\dll4B72.tmpcompressed
MD5:BD3C22846DEA46C67EFB6C6B1BFFD493
SHA256:0E3F89F1329A84F3E7F6B687C01E4B59396A3DC4B967B6C89D51E093253FE5A7
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\dll4B71.tmpcompressed
MD5:48C48773CD43C3F161FAAD6B9720C259
SHA256:48215C3C0A405F0B4C4D85349CEF0CC83F0BC96DBBD8ADC235C3364C4C3A15AC
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:B65D571875079332C81963FF98E62AB3
SHA256:B83A794600A47BE935CC562ACE7A4D531083C76FCC8AC6424D008F1034EEDF96
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\dll4B83.tmpcompressed
MD5:99F0D17656472D6838E61F1C6E6DCA31
SHA256:6D951E4F12E37287FD99D5B12CD15D6B515ED86348EEB6D24A76BD33C99B3390
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:CB34F8D3A8C9038E14172E2B09C5A91B
SHA256:3975CA725AE8F6F635560329EE00E214F58D6A2C9E8D355756481F92C068CD43
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:B9A429A9FFB3C3309222E6A8FC7A0ADA
SHA256:D62E2DCB011F08B416ADDAA11D07FC295427F57CA31B0098A71CC7ED6FE2E95E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
143
DNS requests
120
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2148
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3460
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3460
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5992
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:C4ucROwbHrAs6T1Lr9h8_7GzClVGX9FY399oO9SEM58&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2160
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2148
svchost.exe
40.126.31.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2148
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 172.217.16.206
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
login.live.com
  • 40.126.31.129
  • 20.190.159.128
  • 20.190.159.68
  • 40.126.31.67
  • 40.126.31.3
  • 20.190.159.75
  • 40.126.31.71
  • 20.190.159.23
  • 40.126.31.130
  • 20.190.159.130
  • 20.190.159.73
  • 20.190.159.4
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.22
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted

Threats

PID
Process
Class
Message
5992
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5992
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5992
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5992
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info