File name:

30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88

Full analysis: https://app.any.run/tasks/6c782f89-3e61-4da9-a5a9-23f31658492d
Verdict: Malicious activity
Threats:

Gh0st RAT is a malware with advanced trojan functionality that enables attackers to establish full control over the victim’s system. The spying capabilities of Gh0st RAT made it a go-to tool for numerous criminal groups in high-profile attacks against government and corporate organizations. The most common vector of attack involving this malware begins with spam and phishing emails.

Analysis date: April 12, 2025, 18:30:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
gh0st
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

4FCB5F8DF32359B7066A11BD90C83CB3

SHA1:

523DCFE8A8404E0D723963784223BAA6883F0E3A

SHA256:

30BD19540A19099ABFCCC874EA5CB3E8198BD4405C8F56795AF04F86BAC6DF88

SSDEEP:

98304:4Qf3S4KBxR1SVSg5p5aZKrMqIfC5RHxQUneevbG1AfhnxcANsZb7iBfYyvR5Et6e:bM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GH0ST mutex has been found

      • look2.exe (PID: 7684)
      • svchcst.exe (PID: 7860)
      • svchcst.exe (PID: 7316)
      • svchcst.exe (PID: 1164)
      • svchcst.exe (PID: 5116)
      • svchcst.exe (PID: 7648)
      • svchcst.exe (PID: 7468)
      • svchcst.exe (PID: 1912)
      • svchcst.exe (PID: 8068)
  • SUSPICIOUS

    • Suspicious files were dropped or overwritten

      • look2.exe (PID: 7684)
    • Executable content was dropped or overwritten

      • look2.exe (PID: 7684)
      • 30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exe (PID: 7660)
    • Creates or modifies Windows services

      • look2.exe (PID: 7684)
    • Executes application which crashes

      • svchcst.exe (PID: 7860)
      • svchcst.exe (PID: 8068)
      • svchcst.exe (PID: 1164)
      • svchcst.exe (PID: 7316)
      • svchcst.exe (PID: 5116)
      • svchcst.exe (PID: 7468)
      • svchcst.exe (PID: 7648)
    • There is functionality for taking screenshot (YARA)

      • 30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exe (PID: 7660)
    • Connects to unusual port

      • svchcst.exe (PID: 8068)
      • svchcst.exe (PID: 7316)
      • svchcst.exe (PID: 1164)
      • svchcst.exe (PID: 5116)
      • svchcst.exe (PID: 7648)
      • svchcst.exe (PID: 7468)
      • svchcst.exe (PID: 1912)
      • svchcst.exe (PID: 7860)
  • INFO

    • Checks supported languages

      • look2.exe (PID: 7684)
      • 30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exe (PID: 7660)
      • HD_30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exe (PID: 7752)
    • Reads security settings of Internet Explorer

      • svchcst.exe (PID: 8068)
      • svchcst.exe (PID: 7316)
      • svchcst.exe (PID: 1164)
      • svchcst.exe (PID: 5116)
      • svchcst.exe (PID: 7648)
      • svchcst.exe (PID: 1912)
      • svchcst.exe (PID: 7468)
      • svchcst.exe (PID: 7860)
    • The sample compiled with chinese language support

      • 30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exe (PID: 7660)
    • Reads the computer name

      • look2.exe (PID: 7684)
    • Create files in a temporary directory

      • 30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exe (PID: 7660)
    • The sample compiled with english language support

      • 30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exe (PID: 7660)
    • Reads the software policy settings

      • svchcst.exe (PID: 8068)
      • svchcst.exe (PID: 7316)
      • svchcst.exe (PID: 5116)
      • svchcst.exe (PID: 1164)
      • svchcst.exe (PID: 7468)
      • svchcst.exe (PID: 7648)
      • svchcst.exe (PID: 1912)
      • svchcst.exe (PID: 7860)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (16.3)
.exe | Win64 Executable (generic) (14.5)
.dll | Win32 Dynamic Link Library (generic) (3.4)
.exe | Win32 Executable (generic) (2.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:17 03:22:40+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 520192
InitializedDataSize: 1253376
UninitializedDataSize: -
EntryPoint: 0x60d55
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.9.0.9
ProductVersionNumber: 2.9.0.9
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
FileVersion: 2.9.0.9
FileDescription: 应用程序
ProductName: PopWndL0g
ProductVersion: 2.9.0.9
CompanyName: RuntimeBroker
LegalCopyright: RuntimeBroker
Comments: PopWndL0g
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
155
Monitored processes
20
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exe look2.exe hd_30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exe no specs svchcst.exe werfault.exe no specs svchcst.exe werfault.exe no specs svchcst.exe werfault.exe no specs svchcst.exe werfault.exe no specs svchcst.exe werfault.exe no specs svchcst.exe werfault.exe no specs svchcst.exe werfault.exe no specs svchcst.exe werfault.exe no specs 30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1164C:\WINDOWS\system32\svchcst.exe "c:\windows\system32\1104421.bat",MainThreadC:\Windows\SysWOW64\svchcst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
255
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\svchcst.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1912C:\WINDOWS\system32\svchcst.exe "c:\windows\system32\1104421.bat",MainThreadC:\Windows\SysWOW64\svchcst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\svchcst.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3676C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7316 -s 1328C:\Windows\SysWOW64\WerFault.exesvchcst.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
4976C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5116 -s 1324C:\Windows\SysWOW64\WerFault.exesvchcst.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
5116C:\WINDOWS\system32\svchcst.exe "c:\windows\system32\1104421.bat",MainThreadC:\Windows\SysWOW64\svchcst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
255
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\svchcst.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
5640C:\WINDOWS\SysWOW64\WerFault.exe -u -p 1164 -s 1328C:\Windows\SysWOW64\WerFault.exesvchcst.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7220C:\WINDOWS\SysWOW64\WerFault.exe -u -p 8068 -s 1332C:\Windows\SysWOW64\WerFault.exesvchcst.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7316C:\WINDOWS\system32\svchcst.exe "c:\windows\system32\1104421.bat",MainThreadC:\Windows\SysWOW64\svchcst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
255
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\svchcst.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7468C:\WINDOWS\system32\svchcst.exe "c:\windows\system32\1104421.bat",MainThreadC:\Windows\SysWOW64\svchcst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
255
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\svchcst.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7532C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7468 -s 1328C:\Windows\SysWOW64\WerFault.exesvchcst.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
37 905
Read events
37 841
Write events
43
Delete events
21

Modification events

(PID) Process:(7684) look2.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\svchcst
Operation:writeName:Description
Value:
¹ÜÀí»ùÓÚ×é¼þ¶ÔÏóÄ£Ð͵ĺËÐÄ·þÎñ,Èç¹û·þÎñ±»½ûÓ㬼ÆËã»ú½«ÎÞ·¨Õý³£ÔËÐС£
(PID) Process:(7684) look2.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\svchcst\Parameters
Operation:writeName:ServiceDll
Value:
C:\WINDOWS\system32\1104421.bat
(PID) Process:(7684) look2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Svchost
Operation:writeName:svchcst
Value:
svchcst
(PID) Process:(7984) WerFault.exeKey:\REGISTRY\A\{2d392ec2-b0cd-46f2-a5df-7cc4c164ce5e}\Root\InventoryApplicationFile
Operation:writeName:WritePermissionsCheck
Value:
1
(PID) Process:(7984) WerFault.exeKey:\REGISTRY\A\{2d392ec2-b0cd-46f2-a5df-7cc4c164ce5e}\Root\InventoryApplicationFile\PermissionsCheckTestKey
Operation:delete keyName:(default)
Value:
(PID) Process:(7984) WerFault.exeKey:\REGISTRY\A\{2d392ec2-b0cd-46f2-a5df-7cc4c164ce5e}\Root\InventoryApplicationFile\svchcst.exe|5d020bac932c45f2
Operation:writeName:ProgramId
Value:
0006e09c701521111759bd9b5099571c033d00000904
(PID) Process:(7984) WerFault.exeKey:\REGISTRY\A\{2d392ec2-b0cd-46f2-a5df-7cc4c164ce5e}\Root\InventoryApplicationFile\svchcst.exe|5d020bac932c45f2
Operation:writeName:FileId
Value:
00006f317948fd881fc9ad25292f6d2c021ee9a82a85
(PID) Process:(7984) WerFault.exeKey:\REGISTRY\A\{2d392ec2-b0cd-46f2-a5df-7cc4c164ce5e}\Root\InventoryApplicationFile\svchcst.exe|5d020bac932c45f2
Operation:writeName:LowerCaseLongPath
Value:
c:\windows\syswow64\svchcst.exe
(PID) Process:(7984) WerFault.exeKey:\REGISTRY\A\{2d392ec2-b0cd-46f2-a5df-7cc4c164ce5e}\Root\InventoryApplicationFile\svchcst.exe|5d020bac932c45f2
Operation:writeName:LongPathHash
Value:
svchcst.exe|5d020bac932c45f2
(PID) Process:(7984) WerFault.exeKey:\REGISTRY\A\{2d392ec2-b0cd-46f2-a5df-7cc4c164ce5e}\Root\InventoryApplicationFile\svchcst.exe|5d020bac932c45f2
Operation:writeName:Name
Value:
svchcst.exe
Executable files
4
Suspicious files
11
Text files
11
Unknown types
1

Dropped files

PID
Process
Filename
Type
7984WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_svchcst.exe_bce282bbd7e3136c36930d840f7fd2946601f8d_19de00a8_867e5258-d2a2-4a06-8d55-8471a11a9ada\Report.wer
MD5:
SHA256:
7220WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_svchcst.exe_bce282bbd7e3136c36930d840f7fd2946601f8d_19de00a8_3a0f25ef-3a72-42ed-aeb6-0e6bec66e389\Report.wer
MD5:
SHA256:
766030bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exeC:\Users\admin\AppData\Local\Temp\look2.exeexecutable
MD5:2F3B6F16E33E28AD75F3FDAEF2567807
SHA256:86492EBF2D6F471A5EE92977318D099B3EA86175B5B7AE522237AE01D07A4857
3676WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_svchcst.exe_bce282bbd7e3136c36930d840f7fd2946601f8d_19de00a8_0c7ae70f-6612-4bcc-952d-37da60203599\Report.wer
MD5:
SHA256:
766030bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exeC:\Users\admin\Desktop\HD_30bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exeexecutable
MD5:FB083ACD60FE5C3156DC25442BE815E3
SHA256:F130B3789962D5C8B59AA250D6F26AD5945928F3905B32BF65AA7BD30348A794
7684look2.exeC:\Windows\SysWOW64\1104421.batexecutable
MD5:F2EE6CA8B8749A5D325DDB8CD7090DA9
SHA256:B93F3E5BF73E20D88EDDA05786F4DAFBF082934110D9BB06D309D6041D5865E2
7860svchcst.exeC:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\getip[1].htmhtml
MD5:72FA0FCA20C82853E6DBBC1F13C78100
SHA256:4555DE589FF9B307E20C708D6F112BC47BB377DF29FF0A5914F8FB0932926887
7684look2.exeC:\Windows\SysWOW64\ini.initext
MD5:9E806D26B3CF00B03D1A2313E7AA726F
SHA256:9EA7935AE8C50A9D719B762CBBBC31FE7D1CA3604161B578FDB830083F156FF6
766030bd19540a19099abfccc874ea5cb3e8198bd4405c8f56795af04f86bac6df88.exeC:\Users\admin\AppData\Local\Temp\HD_X.datexecutable
MD5:5D7BED642E12888F7A15BF4AF6165157
SHA256:3348AD210AC86877E023953519CBA103A690D82FF9568B7D70A89CE8E19F8DE7
5640WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_svchcst.exe_bce282bbd7e3136c36930d840f7fd2946601f8d_19de00a8_a1f2ccac-71fa-4b5e-a6d5-f997c8f2ba6a\Report.wer
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
61
TCP/UDP connections
100
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.37:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7860
svchcst.exe
GET
301
163.181.92.222:80
http://www.taobao.com/help/getip.php
unknown
whitelisted
8068
svchcst.exe
GET
301
163.181.92.222:80
http://www.taobao.com/help/getip.php
unknown
whitelisted
GET
304
20.12.23.50:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
7316
svchcst.exe
GET
301
163.181.92.222:80
http://www.taobao.com/help/getip.php
unknown
whitelisted
7260
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
7260
SIHClient.exe
GET
200
23.216.77.38:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
7260
SIHClient.exe
GET
200
23.216.77.38:80
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
unknown
whitelisted
7260
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7260
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.216.77.37:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7860
svchcst.exe
47.238.96.72:442
kinh.xmcxmr.com
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.130
  • 20.190.160.65
  • 20.190.160.67
  • 20.190.160.14
  • 40.126.32.136
  • 40.126.32.134
  • 20.190.160.131
  • 40.126.32.133
whitelisted
google.com
  • 142.250.102.138
  • 142.250.102.139
  • 142.250.102.101
  • 142.250.102.100
  • 142.250.102.113
  • 142.250.102.102
whitelisted
crl.microsoft.com
  • 23.216.77.37
  • 23.216.77.38
  • 23.216.77.16
  • 23.216.77.36
  • 23.216.77.21
  • 23.216.77.5
  • 23.216.77.8
  • 23.216.77.20
  • 23.216.77.39
  • 23.216.77.6
  • 23.216.77.41
  • 23.216.77.42
  • 23.216.77.18
  • 23.216.77.19
  • 23.216.77.25
whitelisted
kinh.xmcxmr.com
  • 47.238.96.72
unknown
www.taobao.com
  • 163.181.92.222
  • 163.181.92.223
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
www.microsoft.com
  • 23.37.237.227
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info