File name:

striata-reader (2).vir

Full analysis: https://app.any.run/tasks/5583f884-a72d-4368-b8dd-f4238363cc07
Verdict: Malicious activity
Analysis date: July 04, 2025, 12:26:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

334D397FD7AEC4F4474EA696D78DCE92

SHA1:

47BDC95DE9484907533AE08A956E2A9FD2260B8D

SHA256:

2D0029ACD8B2A299839EB5ECF0C738294E54BE50016339E6D4A6C84273217200

SSDEEP:

49152:6nm0Z3MmWT9FbPMbeOgNZzA/ube6ZBlxA5+5jCJn+gXudcZxfgpD9in06JQFu0oG:6n/STfbPMbeBZM/9MBlxA5tR+gXuQxf4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • striata-reader (2).vir.exe (PID: 6172)
      • striata-reader (2).vir.exe (PID: 7104)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • striata-reader (2).vir.exe (PID: 6172)
    • The process drops C-runtime libraries

      • striata-reader (2).vir.exe (PID: 6172)
    • Creates a software uninstall entry

      • striata-reader (2).vir.exe (PID: 6172)
    • There is functionality for taking screenshot (YARA)

      • striata-reader (2).vir.exe (PID: 6172)
    • Creates/Modifies COM task schedule object

      • striata-reader (2).vir.exe (PID: 6172)
    • Executable content was dropped or overwritten

      • striata-reader (2).vir.exe (PID: 6172)
  • INFO

    • Create files in a temporary directory

      • striata-reader (2).vir.exe (PID: 6172)
    • Checks supported languages

      • striata-reader (2).vir.exe (PID: 6172)
      • identity_helper.exe (PID: 6840)
    • The sample compiled with english language support

      • striata-reader (2).vir.exe (PID: 6172)
    • Reads the machine GUID from the registry

      • striata-reader (2).vir.exe (PID: 6172)
    • Creates files in the program directory

      • striata-reader (2).vir.exe (PID: 6172)
    • Application launched itself

      • msedge.exe (PID: 5244)
    • Manual execution by a user

      • msedge.exe (PID: 5244)
    • Reads the computer name

      • identity_helper.exe (PID: 6840)
      • striata-reader (2).vir.exe (PID: 6172)
    • Reads Environment values

      • identity_helper.exe (PID: 6840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2021:04:01 07:29:32+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.16
CodeSize: 96256
InitializedDataSize: 1291776
UninitializedDataSize: -
EntryPoint: 0x213c
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 2.31.2.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (1C09)
CharacterSet: Unicode
CompanyName: Doxim LLC
Internet: http://www.striata.com
E-mail: info@striata.com
FileDescription: Striata Reader
FileVersion: 2.31-2
LegalCopyright: Copyright Doxim LLC, 2020-2021
OriginalFileName: striata-reader
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
172
Monitored processes
30
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start striata-reader (2).vir.exe msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs striata-reader (2).vir.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2064"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=7936,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=7924 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2124"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --instant-process --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3640,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=3904 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2876"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3624,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=3656 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3488"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5616,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=5688 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3564"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4280,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=4328 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4752"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5924,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=6064 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4764"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --disable-quic --onnx-enabled-for-ee --string-annotations --always-read-main-dll --field-trial-handle=5752,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=5260 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5184"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2408,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=2404 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5244"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=DefaultC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5432"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2768,i,6927783932211917084,17634461754415375548,262144 --variations-seed-version --mojo-platform-channel-handle=2780 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
7 916
Read events
7 832
Write events
81
Delete events
3

Modification events

(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sed
Operation:delete valueName:PerceivedType
Value:
text
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sed
Operation:delete keyName:(default)
Value:
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Operation:writeName:{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Value:
Striata Encrypted Document
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
19
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Operation:writeName:UninstallString
Value:
rundll32.exe "C:\Program Files\Striata-Reader\keymail.dll",UninstallDll --local-machine
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Operation:writeName:DisplayName
Value:
Striata Reader (64-bit)
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Operation:writeName:URLInfoAbout
Value:
http://www.striata.com
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Operation:writeName:Publisher
Value:
Doxim LLC
(PID) Process:(6172) striata-reader (2).vir.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}
Operation:writeName:DisplayVersion
Value:
2.31-2
Executable files
129
Suspicious files
678
Text files
128
Unknown types
20

Dropped files

PID
Process
Filename
Type
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\striata-reader.runtime.manifestxml
MD5:8470EA5C95D1D00656BBEE5191C9738D
SHA256:4275CC74EC6E12A70BC12AE19B0ED965C79F9FA495F9C92B4EF814D08CA48263
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\dll4B71.tmpcompressed
MD5:48C48773CD43C3F161FAAD6B9720C259
SHA256:48215C3C0A405F0B4C4D85349CEF0CC83F0BC96DBBD8ADC235C3364C4C3A15AC
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\dll4B61.tmpcompressed
MD5:D38DBE54A48CE0E5942C2DA9366423A2
SHA256:71505888D2C184BB9E40BC433F578D71D0A30513F1FD80DA4DE5BB00096F6451
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\dll4B72.tmpcompressed
MD5:BD3C22846DEA46C67EFB6C6B1BFFD493
SHA256:0E3F89F1329A84F3E7F6B687C01E4B59396A3DC4B967B6C89D51E093253FE5A7
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\dll4B83.tmpcompressed
MD5:99F0D17656472D6838E61F1C6E6DCA31
SHA256:6D951E4F12E37287FD99D5B12CD15D6B515ED86348EEB6D24A76BD33C99B3390
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:B7300D7A31BC0C3ABB631F1951CC103A
SHA256:A580C502170462431A197954EADA3A2B92CDDDA8E77D489475A8FA6DA0000349
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\dll4B95.tmpcompressed
MD5:4DE3F62A1B0478B3D2D2FDF1B86CD80F
SHA256:B61EFA11C7D65C3319CFBCA63AF38E42CCD95AA582B13EBD65498863591BB1CF
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:B65D571875079332C81963FF98E62AB3
SHA256:B83A794600A47BE935CC562ACE7A4D531083C76FCC8AC6424D008F1034EEDF96
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\dll4B84.tmpcompressed
MD5:82D319390B13690D8DD04EF2F689554D
SHA256:23415A152B78BA723E4B4CFDCC2E00BC8EB223F5996D34A4637CD78AD6CB34BC
6172striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174b51\striata-reader.runtime\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:31E207B01E67B6563D2CF9110D06A1D2
SHA256:6B31A206C051815BE9F7B366D2A9D2464747A56888A7307A924ECDAC558271E1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
143
DNS requests
120
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2148
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3460
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3460
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5992
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:C4ucROwbHrAs6T1Lr9h8_7GzClVGX9FY399oO9SEM58&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2160
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2148
svchost.exe
40.126.31.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2148
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 172.217.16.206
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
login.live.com
  • 40.126.31.129
  • 20.190.159.128
  • 20.190.159.68
  • 40.126.31.67
  • 40.126.31.3
  • 20.190.159.75
  • 40.126.31.71
  • 20.190.159.23
  • 40.126.31.130
  • 20.190.159.130
  • 20.190.159.73
  • 20.190.159.4
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.22
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted

Threats

PID
Process
Class
Message
5992
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5992
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5992
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5992
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info