File name:

WhatsApp Installer.exe

Full analysis: https://app.any.run/tasks/d09e5257-1cb3-466d-b6a2-18561210efe3
Verdict: Malicious activity
Analysis date: April 04, 2025, 16:35:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

18835B89F6FF63967E12A16934EEB2DD

SHA1:

3271992D62CEDE0492A30554D2D12BB5B196871F

SHA256:

307B9E4797380DDF3C2A674A4A03693B420EE96F86B9AD1F95AC9B020F785230

SSDEEP:

12288:G8NAp5eNdtwTKtwKhpvSriYLLnZ1dUu3PzKtwMeM1J:FKp5eNdtw+twKh5SriAuCetwMeM1J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • WhatsApp Installer.exe (PID: 7392)
    • Process drops legitimate windows executable

      • WhatsApp Installer.exe (PID: 7392)
      • firefox.exe (PID: 5280)
    • Reads security settings of Internet Explorer

      • WhatsApp Installer.exe (PID: 7392)
  • INFO

    • Disables trace logs

      • WhatsApp Installer.exe (PID: 7392)
    • Process checks computer location settings

      • WhatsApp Installer.exe (PID: 7392)
    • Reads Environment values

      • WhatsApp Installer.exe (PID: 7392)
    • Reads the computer name

      • WhatsApp Installer.exe (PID: 7392)
    • Reads the machine GUID from the registry

      • WhatsApp Installer.exe (PID: 7392)
    • Checks supported languages

      • WhatsApp Installer.exe (PID: 7392)
    • Checks proxy server information

      • WhatsApp Installer.exe (PID: 7392)
      • slui.exe (PID: 6620)
    • Reads the software policy settings

      • WhatsApp Installer.exe (PID: 7392)
      • slui.exe (PID: 7652)
      • slui.exe (PID: 6620)
    • Manual execution by a user

      • firefox.exe (PID: 7284)
    • Application launched itself

      • firefox.exe (PID: 7284)
      • firefox.exe (PID: 5280)
    • Autorun file from Downloads

      • firefox.exe (PID: 5280)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 5280)
    • Connects to unusual port

      • firefox.exe (PID: 5280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2052:04:22 05:55:47+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 990720
InitializedDataSize: 75776
UninitializedDataSize: -
EntryPoint: 0xf3c12
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 22412.1210.2.0
ProductVersionNumber: 22412.1210.2.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Store Installer
FileVersion: 22412.1210.2.0
InternalName: StoreInstaller.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: StoreInstaller.exe
ProductName: Store Installer
ProductVersion: 22412.1210.02.0+6d95ba5f267bc5310f887034d0b7572710fa93d8
AssemblyVersion: 22412.1210.2.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
151
Monitored processes
24
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start whatsapp installer.exe sppextcomobj.exe no specs slui.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
1240"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2172 -parentBuildID 20240213221259 -prefsHandle 2156 -prefMapHandle 2152 -prefsLen 31031 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7662da83-4e69-4cd7-86a8-83059720ae02} 5280 "\\.\pipe\gecko-crash-server-pipe.5280" 1ef3ac80910 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2148"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6152 -childID 12 -isForBrowser -prefsHandle 6284 -prefMapHandle 6616 -prefsLen 31597 -prefMapSize 244583 -jsInitHandle 1540 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3382d8b2-91db-44f7-ad5e-bee9b0352683} 5280 "\\.\pipe\gecko-crash-server-pipe.5280" 1ef4da17150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2644"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5188 -childID 5 -isForBrowser -prefsHandle 5140 -prefMapHandle 5076 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1540 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {919fe98a-04db-4611-bc1d-17a92951d5ed} 5280 "\\.\pipe\gecko-crash-server-pipe.5280" 1ef518ca150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4224"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6056 -childID 7 -isForBrowser -prefsHandle 6080 -prefMapHandle 6076 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1540 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {9b4649a5-bc37-47d6-8cea-103617ee355e} 5280 "\\.\pipe\gecko-crash-server-pipe.5280" 1ef4f5234d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
4740"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4300 -childID 2 -isForBrowser -prefsHandle 4288 -prefMapHandle 4284 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1540 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4721c593-2617-45da-9bd7-54d13a626674} 5280 "\\.\pipe\gecko-crash-server-pipe.5280" 1ef4e542310 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
5280"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
5756"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1916 -parentBuildID 20240213221259 -prefsHandle 1832 -prefMapHandle 1816 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f475a145-c30b-48ea-83cf-8fb60c0f59be} 5280 "\\.\pipe\gecko-crash-server-pipe.5280" 1ef47becf10 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
6240"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2596 -childID 1 -isForBrowser -prefsHandle 2772 -prefMapHandle 2768 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1540 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {47241139-2d8d-4b00-bd58-7cca312f747e} 5280 "\\.\pipe\gecko-crash-server-pipe.5280" 1ef4c83dd90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140_1.dll
6620C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
34 617
Read events
34 461
Write events
151
Delete events
5

Modification events

(PID) Process:(7392) WhatsApp Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7392) WhatsApp Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7392) WhatsApp Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7392) WhatsApp Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WhatsApp Installer_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7392) WhatsApp Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WhatsApp Installer_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7392) WhatsApp Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WhatsApp Installer_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7392) WhatsApp Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WhatsApp Installer_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7392) WhatsApp Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WhatsApp Installer_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7392) WhatsApp Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WhatsApp Installer_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7392) WhatsApp Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WhatsApp Installer_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
Executable files
4
Suspicious files
344
Text files
35
Unknown types
3

Dropped files

PID
Process
Filename
Type
5280firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
7392WhatsApp Installer.exeC:\Users\admin\AppData\Local\Temp\Tmp1B3.tmptext
MD5:A10F31FA140F2608FF150125F3687920
SHA256:28C871238311D40287C51DC09AEE6510CAC5306329981777071600B1112286C6
5280firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.binbinary
MD5:C95DDC2B1A525D1A243E4C294DA2F326
SHA256:3A5919E086BFB31E36110CF636D2D5109EB51F2C410B107F126126AB25D67363
5280firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
5280firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
5280firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:297E88D7CEB26E549254EC875649F4EB
SHA256:8B75D4FB1845BAA06122888D11F6B65E6A36B140C54A72CC13DF390FD7C95702
7392WhatsApp Installer.exeC:\Users\admin\AppData\Local\Temp\Tmp155.tmptext
MD5:A10F31FA140F2608FF150125F3687920
SHA256:28C871238311D40287C51DC09AEE6510CAC5306329981777071600B1112286C6
5280firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
5280firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
5280firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
57
TCP/UDP connections
190
DNS requests
215
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8180
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8180
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
23.48.23.188:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5280
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
5280
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
5280
firefox.exe
POST
200
2.16.206.148:80
http://r10.o.lencr.org/
unknown
whitelisted
5280
firefox.exe
POST
200
2.16.206.148:80
http://r10.o.lencr.org/
unknown
whitelisted
5280
firefox.exe
POST
200
142.250.186.35:80
http://o.pki.goog/s/wr3/cgo
unknown
whitelisted
5280
firefox.exe
POST
200
2.16.206.148:80
http://r11.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
23.48.23.188:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
3884
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
3216
svchost.exe
20.7.1.246:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7392
WhatsApp Installer.exe
69.192.161.195:443
storesdk.dsx.mp.microsoft.com
AKAMAI-AS
DE
whitelisted
7392
WhatsApp Installer.exe
2.16.253.169:443
store-images.s-microsoft.com
Akamai International B.V.
NL
whitelisted
7392
WhatsApp Installer.exe
20.82.154.241:443
displaycatalog.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.238
whitelisted
crl.microsoft.com
  • 23.48.23.188
  • 23.48.23.193
  • 23.48.23.191
  • 23.48.23.178
  • 23.48.23.180
  • 23.48.23.134
  • 23.48.23.177
  • 23.48.23.179
  • 23.48.23.181
whitelisted
client.wns.windows.com
  • 20.7.1.246
  • 20.7.2.167
whitelisted
storesdk.dsx.mp.microsoft.com
  • 69.192.161.195
whitelisted
store-images.s-microsoft.com
  • 2.16.253.169
whitelisted
displaycatalog.mp.microsoft.com
  • 20.82.154.241
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.0
  • 40.126.31.128
  • 20.190.159.75
  • 20.190.159.68
  • 20.190.159.73
  • 40.126.31.2
  • 40.126.31.73
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 184.30.131.245
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted

Threats

No threats detected
No debug info