File name:

20950944987.zip

Full analysis: https://app.any.run/tasks/3fe63d5a-8bcd-4883-9f0e-806b5ca37be3
Verdict: Malicious activity
Analysis date: January 27, 2025, 06:19:22
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

90C514B7A2F91336514E992B044F4571

SHA1:

646C2D5B671CF411EB0128C4AAA85C11EEFBCFD0

SHA256:

31D843CCAD9A3D38E4D83E8C9729E47465FD587D573B2C6636F39EF11BD9717E

SSDEEP:

98304:/cyaulaegeDMF2p5FYqwFNc+wyrcQ7Ar2of55dBiXe7pko27Ioikzxx3EodX0p2u:51Y6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • a.exe (PID: 5464)
      • OriginLegacyCLI.exe (PID: 4052)
    • Changes the autorun value in the registry

      • OriginLegacyCLI.exe (PID: 4052)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • a.exe (PID: 5464)
      • irsetup.exe (PID: 5004)
      • AdobeCollabSync.exe (PID: 6576)
      • AdobeCollabSync.exe (PID: 6684)
    • Creates a software uninstall entry

      • irsetup.exe (PID: 5004)
    • Executable content was dropped or overwritten

      • irsetup.exe (PID: 5004)
      • a.exe (PID: 5464)
    • Application launched itself

      • AdobeCollabSync.exe (PID: 6576)
    • Checks Windows Trust Settings

      • AdobeCollabSync.exe (PID: 6684)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 3724)
      • a.exe (PID: 5464)
      • irsetup.exe (PID: 5004)
    • Creates files or folders in the user directory

      • irsetup.exe (PID: 5004)
      • AdobeCollabSync.exe (PID: 6684)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3724)
    • Manual execution by a user

      • a.exe (PID: 5464)
    • Create files in a temporary directory

      • a.exe (PID: 5464)
      • irsetup.exe (PID: 5004)
    • Reads the computer name

      • a.exe (PID: 5464)
      • AdobeCollabSync.exe (PID: 6576)
      • AdobeCollabSync.exe (PID: 6684)
      • FullTrustNotifier.exe (PID: 4328)
      • irsetup.exe (PID: 5004)
    • Creates files in the program directory

      • irsetup.exe (PID: 5004)
    • Process checks computer location settings

      • irsetup.exe (PID: 5004)
      • a.exe (PID: 5464)
    • Checks supported languages

      • OriginLegacyCLI.exe (PID: 4052)
      • AdobeCollabSync.exe (PID: 6684)
      • AdobeCollabSync.exe (PID: 6576)
      • FullTrustNotifier.exe (PID: 4328)
      • a.exe (PID: 5464)
      • irsetup.exe (PID: 5004)
    • Application launched itself

      • Acrobat.exe (PID: 5592)
      • AcroCEF.exe (PID: 6944)
    • Checks proxy server information

      • AdobeCollabSync.exe (PID: 6684)
      • AdobeCollabSync.exe (PID: 6576)
    • Reads the software policy settings

      • AdobeCollabSync.exe (PID: 6684)
    • Reads the machine GUID from the registry

      • AdobeCollabSync.exe (PID: 6684)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x2d134076
ZipCompressedSize: 2014474
ZipUncompressedSize: 2212280
ZipFileName: 5f14648a1153e45b77cf309595e0f91fd41642b1f538cd1bdbf8e70e23e13748
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
22
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1344"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2632 --field-trial-handle=1604,i,8473562714054960041,6927489759731956414,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe—AcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Exit code:
0
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1380"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2200 --field-trial-handle=1604,i,8473562714054960041,6927489759731956414,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe—AcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1512"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2216 --field-trial-handle=1604,i,8473562714054960041,6927489759731956414,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
AcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3724"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\20950944987.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3796\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—waitfor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3988"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" --type=renderer /prefetch:1 "C:\programdata\session\2567_MDES0204_8_20134.pdf"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe—Acrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4052c:\programdata\session\OriginLegacyCLI.exeC:\ProgramData\session\OriginLegacyCLI.exe
irsetup.exe
User:
admin
Company:
Electronic Arts
Integrity Level:
MEDIUM
Description:
OriginLegacyCLI
Exit code:
0
Version:
8,1,0,1556
Modules
Images
c:\programdata\session\originlegacycli.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4328"C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe" GetChannelUriC:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe—AdobeCollabSync.exe
User:
admin
Integrity Level:
LOW
Exit code:
3221225547
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\rdcnotificationclient\fulltrustnotifier.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4640"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=2820 --field-trial-handle=1604,i,8473562714054960041,6927489759731956414,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe—AcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Exit code:
0
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5004"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:1747314 "__IRAFN:C:\Users\admin\Desktop\20950944987\a.exe" "__IRCT:0" "__IRTSS:0" "__IRSID:S-1-5-21-1693682860-607145093-2874071422-1001"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
a.exe
User:
admin
Company:
Indigo Rose Corporation
Integrity Level:
MEDIUM
Description:
Setup Application
Exit code:
0
Version:
9.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\_ir_sf_temp_0\irsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
22 139
Read events
21 949
Write events
172
Delete events
18

Modification events

(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\20950944987.zip
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
7
Suspicious files
185
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
5004irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPGimage
MD5:3220A6AEFB4FC719CC8849F060859169
SHA256:988CF422CBF400D41C48FBE491B425A827A1B70691F483679C1DF02FB9352765
3724WinRAR.exeC:\Users\admin\Desktop\20950944987\5f14648a1153e45b77cf309595e0f91fd41642b1f538cd1bdbf8e70e23e13748executable
MD5:DFE0C87B2B2B7FC18A7BF6FF372FE6A1
SHA256:5F14648A1153E45B77CF309595E0F91FD41642B1F538CD1BDBF8E70E23E13748
5464a.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exeexecutable
MD5:F1309DF61E1DC5DF781B90894C2E7DAC
SHA256:69A23AA500C5350612A42EA2B0297DE3F344C7C97A47B98EA770510DE69AFFEE
5004irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.datbinary
MD5:E0456345518547FEFB19DD8E172EEACF
SHA256:A0677537B272A197C49EAE86B039371FCB39877C4867CF8381F5C51E21E82D1D
5004irsetup.exeC:\ProgramData\session\2567_MDES0204_8_20134.pdfpdf
MD5:E584A5C9323AF86CF4A33B61C08B55A2
SHA256:0A40CAEF07B7C4DC1CC1339712391FA5F75FC00F33B4E791328EC23EAB0B0C9D
5004irsetup.exeC:\ProgramData\session\lua5.1.dllexecutable
MD5:B5FC476C1BF08D5161346CC7DD4CB0BA
SHA256:12CB9B8F59C00EF40EA8F28BFC59A29F12DC28332BF44B1A5D8D6A8823365650
5004irsetup.exeC:\ProgramData\session\uninstall.exeexecutable
MD5:F1309DF61E1DC5DF781B90894C2E7DAC
SHA256:69A23AA500C5350612A42EA2B0297DE3F344C7C97A47B98EA770510DE69AFFEE
5004irsetup.exeC:\ProgramData\session\Uninstall\uniBB83.tmpbinary
MD5:32BB4D11A207D7B5B3A7CA8795D99905
SHA256:111460F7124D4B001418E9AC2088BF7BCEA5A3566983D02D0CBCE9C3A210DFD0
5004irsetup.exeC:\ProgramData\session\Uninstall\uninstall.datbinary
MD5:D1684E03CD0A60A7A2807936C270F76E
SHA256:D839F47D4066A72D2F314872E4634AD0FF17A694F434599180234EF92AC05AF7
5004irsetup.exeC:\ProgramData\session\OriginLegacyCLI.exeexecutable
MD5:1714E4D37E67EF972B5A53E19B9297D9
SHA256:91357E6E5A8DB3D9D3B23CE4368425A148683287D917D927EE2BB6E835C87EBE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
86
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
—
—
GET
200
23.216.77.26:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
—
—
GET
200
2.16.97.136:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
624
SIHClient.exe
GET
200
2.16.97.136:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
408 b
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
312 b
whitelisted
624
SIHClient.exe
GET
200
2.16.97.136:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
6280
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
DE
binary
471 b
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
5592
Acrobat.exe
POST
200
2.17.190.73:80
http://ocsp.digicert.com/
DE
binary
727 b
whitelisted
5592
Acrobat.exe
POST
200
2.17.190.73:80
http://ocsp.digicert.com/
DE
binary
727 b
whitelisted
5592
Acrobat.exe
POST
200
2.17.190.73:80
http://ocsp.digicert.com/
DE
binary
727 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
880
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
—
—
—
whitelisted
—
—
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
—
—
23.216.77.26:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
—
—
2.16.97.136:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
—
—
—
whitelisted
5064
SearchApp.exe
104.126.37.171:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1176
svchost.exe
20.190.160.14:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 23.216.77.26
  • 23.216.77.39
  • 23.216.77.16
  • 23.216.77.30
  • 23.216.77.21
  • 23.216.77.17
  • 23.216.77.27
  • 23.216.77.43
  • 23.216.77.37
whitelisted
www.microsoft.com
  • 2.16.97.136
whitelisted
www.bing.com
  • 104.126.37.171
  • 104.126.37.155
  • 104.126.37.160
  • 104.126.37.177
  • 104.126.37.163
  • 104.126.37.144
  • 104.126.37.153
  • 104.126.37.179
  • 104.126.37.145
whitelisted
login.live.com
  • 20.190.160.14
  • 40.126.32.133
  • 40.126.32.76
  • 20.190.160.17
  • 40.126.32.140
  • 20.190.160.22
  • 40.126.32.74
  • 40.126.32.138
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 40.127.240.158
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted

Threats

No threats detected
No debug info