File name:

VMware Workstation Pro - CHIP Installer _5rgfv.exe

Full analysis: https://app.any.run/tasks/a4de4548-8b15-4988-835e-8e5af6c4d495
Verdict: Malicious activity
Analysis date: November 15, 2024, 19:40:18
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-scr
arch-html
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 11 sections
MD5:

F5980F17F44DA870072C5CE396EB01BF

SHA1:

22CE208ACB16875CDD9D42A794557A56068220C2

SHA256:

2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B

SSDEEP:

49152:xhx7dxx15qe01xtgx41J/StY/yuiYWLmgpaRZkDuZdTNACtn:JV1JALgvz4ACtn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • msiexec.exe (PID: 2484)
      • net.exe (PID: 4164)
      • net.exe (PID: 480)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • VMware Workstation Pro - CHIP Installer _5rgfv.exe (PID: 5828)
    • Executable content was dropped or overwritten

      • VMware-workstation-17.6.1-24319023.exe (PID: 5624)
      • vcredist_x86.exe (PID: 3932)
      • vcredist_x86.exe (PID: 4692)
      • vcredist_x64.exe (PID: 3936)
      • vnetlib64.exe (PID: 3432)
      • vcredist_x64.exe (PID: 6992)
      • drvinst.exe (PID: 7004)
      • vnetlib64.exe (PID: 5956)
      • drvinst.exe (PID: 5652)
    • Starts a Microsoft application from unusual location

      • vcredist_x86.exe (PID: 3932)
      • vcredist_x86.exe (PID: 4692)
      • VC_redist.x86.exe (PID: 5948)
      • vcredist_x64.exe (PID: 3936)
      • VC_redist.x64.exe (PID: 624)
      • vcredist_x64.exe (PID: 6992)
    • Process drops legitimate windows executable

      • vcredist_x86.exe (PID: 3932)
      • VMware-workstation-17.6.1-24319023.exe (PID: 5624)
      • vcredist_x86.exe (PID: 4692)
      • vcredist_x64.exe (PID: 3936)
      • vcredist_x64.exe (PID: 6992)
      • msiexec.exe (PID: 3700)
      • msiexec.exe (PID: 2236)
    • Starts itself from another location

      • vcredist_x86.exe (PID: 4692)
      • vcredist_x64.exe (PID: 6992)
    • Executes as Windows Service

      • VSSVC.exe (PID: 4232)
      • vmnat.exe (PID: 6340)
      • vmnetdhcp.exe (PID: 700)
      • vmware-usbarbitrator64.exe (PID: 7056)
      • vmware-authd.exe (PID: 3508)
    • Executes application which crashes

      • msiexec.exe (PID: 6424)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 2236)
      • drvinst.exe (PID: 7004)
      • vnetlib64.exe (PID: 3432)
      • drvinst.exe (PID: 5652)
      • vnetlib64.exe (PID: 5956)
      • msiexec.exe (PID: 3700)
    • Drops 7-zip archiver for unpacking

      • msiexec.exe (PID: 2236)
    • Starts NET.EXE for network exploration

      • net.exe (PID: 480)
      • msiexec.exe (PID: 2484)
  • INFO

    • Checks supported languages

      • VMware Workstation Pro - CHIP Installer _5rgfv.exe (PID: 5828)
    • Reads the computer name

      • VMware Workstation Pro - CHIP Installer _5rgfv.exe (PID: 5828)
    • Sends debugging messages

      • VMware-workstation-17.6.1-24319023.exe (PID: 5624)
      • vmnetdhcp.exe (PID: 700)
      • vmware-usbarbitrator64.exe (PID: 7056)
      • vmnat.exe (PID: 6340)
      • vmware.exe (PID: 1528)
    • Checks proxy server information

      • VMware Workstation Pro - CHIP Installer _5rgfv.exe (PID: 5828)
    • Reads the software policy settings

      • VMware Workstation Pro - CHIP Installer _5rgfv.exe (PID: 5828)
    • Manages system restore points

      • SrTasks.exe (PID: 5356)
      • SrTasks.exe (PID: 1376)
      • SrTasks.exe (PID: 3648)
    • Application launched itself

      • msiexec.exe (PID: 2236)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2236)
      • msiexec.exe (PID: 3700)
      • msiexec.exe (PID: 7108)
    • Manual execution by a user

      • vmware.exe (PID: 1528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (49.6)
.exe | DOS Executable Generic (49.5)
.vxd | VXD Driver (0.7)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2022:04:16 09:34:08+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 8
CodeSize: 4237824
InitializedDataSize: 1083392
UninitializedDataSize: -
EntryPoint: 0x3f8020
OSVersion: 5.2
ImageVersion: 5.2
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 1.0.100.6
ProductVersionNumber: 1.0.100.6
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: CHIP Digital GmbH
FileDescription: CHIP Secured Installer
FileVersion: 1.0.100.6
LegalCopyright: Copyright 2021 CHIP Digital GmbH
ProductName: LgInstall
ProductVersion: 1.0.100.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
229
Monitored processes
74
Malicious processes
4
Suspicious processes
8

Behavior graph

Click at the process to see the details
start vmware workstation pro - chip installer _5rgfv.exe vmware-workstation-17.6.1-24319023.exe vcredist_x86.exe vcredist_x86.exe vc_redist.x86.exe no specs SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs vcredist_x64.exe vcredist_x64.exe vc_redist.x64.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe msiexec.exe werfault.exe no specs msiexec.exe no specs tiworker.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe vnetlib64.exe no specs vnetlib64.exe no specs drvinst.exe vnetlib64.exe vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs vnetlib64.exe no specs drvinst.exe no specs vnetlib64.exe no specs vmnat.exe vmnetdhcp.exe vnetlib64.exe no specs drvinst.exe no specs drvinst.exe no specs vnetlib64.exe no specs drvinst.exe no specs vnetlib64.exe drvinst.exe drvinst.exe no specs vmware-usbarbitrator64.exe net.exe no specs conhost.exe no specs net1.exe no specs vmware-authd.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs vmware.exe vmware workstation pro - chip installer _5rgfv.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
480net start vmware-view-usbdC:\Windows\SysWOW64\net.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
10.0.19041.1 (WinBuild.160101.0800)
624"C:\WINDOWS\Temp\{24B35C87-FFBF-4D61-914C-E6ECABAE77DD}\.be\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{0B8107A2-007A-4A6D-95E1-C9C507CA6233} {FB151453-BFB5-4D00-B9DF-8A32654528A1} 6992C:\Windows\Temp\{24B35C87-FFBF-4D61-914C-E6ECABAE77DD}\.be\VC_redist.x64.exevcredist_x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532
Exit code:
0
Version:
14.36.32532.0
Modules
Images
c:\windows\temp\{24b35c87-ffbf-4d61-914c-e6ecabae77dd}\.be\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
696"C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exe" -- remove adapter vmnet9C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exemsiexec.exe
User:
SYSTEM
Company:
VMware, Inc.
Integrity Level:
SYSTEM
Description:
VMware network install library executable
Exit code:
4
Version:
17.6.1 build-24319023
Modules
Images
c:\program files (x86)\vmware\vmware workstation\vnetlib64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
700C:\WINDOWS\SysWOW64\vmnetdhcp.exeC:\Windows\SysWOW64\vmnetdhcp.exe
services.exe
User:
SYSTEM
Company:
VMware, Inc.
Integrity Level:
SYSTEM
Description:
VMware VMnet DHCP service
Version:
17.6.1 build-24319023
Modules
Images
c:\windows\syswow64\vmnetdhcp.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ucrtbase.dll
744\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
824"C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exe" -- remove adapter vmnet5C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exemsiexec.exe
User:
SYSTEM
Company:
VMware, Inc.
Integrity Level:
SYSTEM
Description:
VMware network install library executable
Exit code:
4
Version:
17.6.1 build-24319023
Modules
Images
c:\program files (x86)\vmware\vmware workstation\vnetlib64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
848"C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exe" -- remove adapter vmnet1C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exemsiexec.exe
User:
SYSTEM
Company:
VMware, Inc.
Integrity Level:
SYSTEM
Description:
VMware network install library executable
Exit code:
4
Version:
17.6.1 build-24319023
Modules
Images
c:\program files (x86)\vmware\vmware workstation\vnetlib64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1376C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:12C:\Windows\System32\SrTasks.exedllhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1376"C:\Program Files (x86)\Common Files\VMware\USB\DriverCache\vnetlib64.exe" -- install vmusb Win8C:\Program Files (x86)\Common Files\VMware\USB\DriverCache\vnetlib64.exemsiexec.exe
User:
SYSTEM
Company:
VMware, Inc.
Integrity Level:
SYSTEM
Description:
VMware network install library executable
Exit code:
12
Version:
e.x.p build-24127552
Modules
Images
c:\program files (x86)\common files\vmware\usb\drivercache\vnetlib64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1524DrvInst.exe "4" "1" "C:\Program Files (x86)\VMware\VMware Workstation\netadapter.inf" "9" "4d396c847" "00000000000001FC" "WinSta0\Default" "0000000000000204" "208" "C:\Program Files (x86)\VMware\VMware Workstation"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
Total events
50 347
Read events
48 912
Write events
1 348
Delete events
87

Modification events

(PID) Process:(5828) VMware Workstation Pro - CHIP Installer _5rgfv.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5828) VMware Workstation Pro - CHIP Installer _5rgfv.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5828) VMware Workstation Pro - CHIP Installer _5rgfv.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3076) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000914F8C6E9637DB01040C0000DC1B0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5948) VC_redist.x86.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000914F8C6E9637DB013C1700000C170000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3076) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000A130C36E9637DB01040C0000DC1B0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3076) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000A130C36E9637DB01040C0000DC1B0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3076) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000003C94C56E9637DB01040C0000DC1B0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3076) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
480000000000000066ABCC6E9637DB01040C0000DC1B0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3076) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
Executable files
227
Suspicious files
134
Text files
300
Unknown types
2

Dropped files

PID
Process
Filename
Type
5828VMware Workstation Pro - CHIP Installer _5rgfv.exeC:\Users\admin\AppData\Local\Temp\VMware-workstation-17_6_1-24319023_exe_911152024740466162167432\VMware-workstation-17_6_1-24319023_exe.parts
MD5:
SHA256:
5828VMware Workstation Pro - CHIP Installer _5rgfv.exeC:\Users\admin\AppData\Local\Temp\VMware-workstation-17_6_1-24319023_exe_911152024740466162167432\VMware-workstation-17.6.1-24319023.exe
MD5:
SHA256:
5624VMware-workstation-17.6.1-24319023.exeC:\Users\admin\AppData\Local\Temp\{6D4305A8-0DE1-4AB9-893B-D4913D7181BE}~setup\VMwareWorkstation.msi
MD5:
SHA256:
5828VMware Workstation Pro - CHIP Installer _5rgfv.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\30924F1897AA8F5452EA0D0C29524135binary
MD5:EEBC190A0326B70C037039ED8D9ACAAD
SHA256:8353C04FEB98C9DE8E88C393EF0C2040481305AC152DAF663D4C5C238D78C04D
5828VMware Workstation Pro - CHIP Installer _5rgfv.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:3DFCA46E00FFA4795C72A41375F159D3
SHA256:DCBA1A505396539BAC40A7253C9F5DCCF06CBB79957E21D56305E1FC3AF5F40E
5828VMware Workstation Pro - CHIP Installer _5rgfv.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0B8181B549A398A45D986EDB81C19830binary
MD5:FA60C5CA96E3B2AE4F3C8B84D9F71DF5
SHA256:534CE601F6C6AC7AF4C1D2D584F00DE2836C9C7F7B1BA2842A8EF0FFE9112B7C
5828VMware Workstation Pro - CHIP Installer _5rgfv.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\PPD_Bit-Driver-Updater_1[1].pngimage
MD5:4FA788C006BA2C165DFB15A20DD408D8
SHA256:AA0A1A9E282167A2A8BA84CED85760DF64311B6A2F60BF44E7BB17AAD3780C95
5624VMware-workstation-17.6.1-24319023.exeC:\Users\admin\AppData\Local\Temp\{6D4305A8-0DE1-4AB9-893B-D4913D7181BE}~setup\vcredist_x64.exeexecutable
MD5:077F0ABDC2A3881D5C6C774AF821F787
SHA256:917C37D816488545B70AFFD77D6E486E4DD27E2ECE63F6BBAAF486B178B2B888
5624VMware-workstation-17.6.1-24319023.exeC:\Users\admin\AppData\Local\Temp\vminst.logtext
MD5:C99DE7CC24CBAACF75BC09B9129CCD57
SHA256:12A71B6E9F4BF0C63DB9B6D7132817B4DE2E86704B11EE5241617267E25BCAAB
4692vcredist_x86.exeC:\Windows\Temp\{C6DA32F8-B8FA-4690-B49D-2655409213BE}\.ba\1028\thm.wxlxml
MD5:472ABBEDCBAD24DBA5B5F5E8D02C340F
SHA256:8E2E660DFB66CB453E17F1B6991799678B1C8B350A55F9EBE2BA0028018A15AD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
85
DNS requests
36
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.131:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2776
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5828
VMware Workstation Pro - CHIP Installer _5rgfv.exe
GET
200
116.203.169.156:80
http://static.chip-secured-download.de/gfx/progress/BitGuardian/PPD_Bit-Driver-Updater_1.png
unknown
unknown
5828
VMware Workstation Pro - CHIP Installer _5rgfv.exe
GET
200
95.101.54.211:80
http://r10.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRpD%2BQVZ%2B1vf7U0RGQGBm8JZwdxcgQUdKR2KRcYVIUxN75n5gZYwLzFBXICEgSN4UViCPaq6i9dycwvhsE0XQ%3D%3D
unknown
whitelisted
632
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5828
VMware Workstation Pro - CHIP Installer _5rgfv.exe
GET
200
95.101.54.99:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgTxYwFIWmiIoVMCsA0oT%2B6h3g%3D%3D
unknown
whitelisted
2936
svchost.exe
GET
304
69.192.161.44:80
http://x1.c.lencr.org/
unknown
whitelisted
632
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1588
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4360
SearchApp.exe
2.23.209.133:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
5828
VMware Workstation Pro - CHIP Installer _5rgfv.exe
83.125.106.237:443
chip-cluster.de
3U TELECOM GmbH
DE
unknown
2776
svchost.exe
20.190.160.14:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2776
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.174
whitelisted
www.bing.com
  • 2.23.209.133
  • 2.23.209.176
  • 2.23.209.179
  • 2.23.209.189
  • 2.23.209.140
  • 2.23.209.185
  • 2.23.209.149
  • 2.23.209.130
  • 2.23.209.182
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
chip-cluster.de
  • 83.125.106.237
unknown
login.live.com
  • 20.190.160.14
  • 40.126.32.136
  • 20.190.160.17
  • 20.190.160.22
  • 40.126.32.134
  • 40.126.32.133
  • 40.126.32.138
  • 40.126.32.76
whitelisted
th.bing.com
  • 2.23.209.150
  • 2.23.209.187
  • 2.23.209.179
  • 2.23.209.185
  • 2.23.209.177
  • 2.23.209.158
  • 2.23.209.189
  • 2.23.209.133
  • 2.23.209.176
whitelisted
go.microsoft.com
  • 184.28.89.167
  • 23.52.181.141
whitelisted
crl.microsoft.com
  • 2.16.164.131
  • 2.16.164.24
  • 2.16.164.129
  • 2.16.164.88
  • 2.16.164.27
  • 2.16.164.130
  • 2.16.164.51
  • 2.16.164.122
  • 2.16.164.33
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted

Threats

No threats detected
Process
Message
VMware-workstation-17.6.1-24319023.exe
Start Pre-load DLLs.
VMware-workstation-17.6.1-24319023.exe
Win32U_GetFileAttributes: GetFileAttributesExW("C:\Users\admin\AppData\Local\Temp\VMware-workstation-17_6_1-24319023_exe_911152024740466162167432\1033.bmp", ...) failed, error: 2
VMware-workstation-17.6.1-24319023.exe
Win32U_GetFileAttributes: GetFileAttributesExW("C:\Users\admin\AppData\Local\Temp\{6D4305A8-0DE1-4AB9-893B-D4913D7181BE}~setup\", ...) failed, error: 2
vmnat.exe
CodeSet_Init: no ICU
vmnetdhcp.exe
CodeSet_Init: no ICU
vmware-usbarbitrator64.exe
CodeSet_Init: no ICU
vmware.exe
VMListReg::Listener - Initial registry scan completed.