File name:

32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe

Full analysis: https://app.any.run/tasks/19084f88-23e7-4da2-9e75-c1cb8d12fcc2
Verdict: Malicious activity
Analysis date: December 14, 2024, 04:49:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

290905106503753D8BD791403E04FB04

SHA1:

A9BA718E1742482506325C18B3559F2282528343

SHA256:

32E950B63131F1AAF640047618A1AC8E380131C01D5A1A823DCE9711308272E3

SSDEEP:

49152:RTcoT2qHn9lkx0KQ1uBH9jIMfk3+Xc1c7DUiVQoxiWtQHcXBc+kA7hH7AvH5F0g2:T2qHnkxJB9jIMM3+M1c7DUiqoxicQHcL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 4444)
      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 1296)
  • SUSPICIOUS

    • Application launched itself

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 3820)
    • Reads security settings of Internet Explorer

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 3820)
  • INFO

    • Checks proxy server information

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 3820)
    • Reads the software policy settings

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 3820)
    • Reads the computer name

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 3820)
    • The process uses the downloaded file

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 3820)
    • Process checks computer location settings

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 3820)
    • Checks supported languages

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 3820)
    • Application launched itself

      • Acrobat.exe (PID: 5244)
      • AcroCEF.exe (PID: 5872)
    • Disables trace logs

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 3820)
    • Reads the machine GUID from the registry

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 3820)
    • Sends debugging messages

      • Acrobat.exe (PID: 4944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

AssemblyVersion: 1.0.0.0
ProductVersion: 3.5.6.7
ProductName: EBFBIA<6@FG=29CE355@D:?H
OriginalFileName: FINAL_PDF.exe
LegalCopyright: Copyright © 1998 =2>46A4BBI=<2EE:@
InternalName: FINAL_PDF.exe
FileVersion: 3.5.6.7
FileDescription: EBFBIA<6@FG=29CE355@D:?H
CompanyName: =2>46A4BBI=<2EE:@
Comments: 9C84JF2JE82EE;385G?J7J?3
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 3.5.6.7
FileVersionNumber: 3.5.6.7
Subsystem: Windows GUI
SubsystemVersion: 6
ImageVersion: -
OSVersion: 4
EntryPoint: 0x18a35e
UninitializedDataSize: -
InitializedDataSize: 51712
CodeSize: 1606656
LinkerVersion: 80
PEType: PE32
ImageFileCharacteristics: Executable, Large address aware
TimeStamp: 1995:05:25 03:45:10+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
14
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe acrobat.exe no specs acrobat.exe no specs 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe no specs 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3820"C:\Users\admin\AppData\Local\Temp\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe" C:\Users\admin\AppData\Local\Temp\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
explorer.exe
User:
admin
Company:
=2>46A4BBI=<2EE:@
Integrity Level:
MEDIUM
Description:
EBFBIA<6@FG=29CE355@D:?H
Version:
3.5.6.7
Modules
Images
c:\users\admin\appdata\local\temp\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5244"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\admin\Documents\OUCH_SOKHENG.pdf"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4944"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" --type=renderer /prefetch:1 "C:\Users\admin\Documents\OUCH_SOKHENG.pdf"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1296"C:\Users\admin\AppData\Local\Temp\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe"C:\Users\admin\AppData\Local\Temp\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
User:
admin
Company:
=2>46A4BBI=<2EE:@
Integrity Level:
MEDIUM
Description:
EBFBIA<6@FG=29CE355@D:?H
Exit code:
4294967295
Version:
3.5.6.7
Modules
Images
c:\users\admin\appdata\local\temp\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4444"C:\Users\admin\AppData\Local\Temp\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe"C:\Users\admin\AppData\Local\Temp\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
User:
admin
Company:
=2>46A4BBI=<2EE:@
Integrity Level:
MEDIUM
Description:
EBFBIA<6@FG=29CE355@D:?H
Version:
3.5.6.7
5872"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16514043C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4384"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1548 --field-trial-handle=1632,i,8101760419685512454,9651401955171767505,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Exit code:
0
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6636"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2148 --field-trial-handle=1632,i,8101760419685512454,9651401955171767505,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6576"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2172 --field-trial-handle=1632,i,8101760419685512454,9651401955171767505,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
AcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6640"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --first-renderer-process --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2308 --field-trial-handle=1632,i,8101760419685512454,9651401955171767505,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
10 693
Read events
10 636
Write events
52
Delete events
5

Modification events

(PID) Process:(3820) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3820) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(3820) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3820) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3820) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3820) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3820) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3820) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3820) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(3820) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
0
Suspicious files
134
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
382032e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeC:\Users\admin\Documents\OUCH_SOKHENG.pdfpdf
MD5:A1F5622DDD5E328E8873DBBCF9203F6D
SHA256:A1E96ED0D011F7731B7DABCDDF559A19DD1B3C7C453122D44F8477CF21507E7B
4944Acrobat.exeC:\Users\admin\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.1.20093.6 2024-12-14 04-50-27-589.logtext
MD5:460C6041966002D8384A18C895A65EB0
SHA256:C83EC6E8FB3EC62481289C033238C1D9B08DB8076EAAD304099FD7A7F594F1B9
5872AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old~RF1422f7.TMPtext
MD5:7383516745DEC1E86152192435F92D1F
SHA256:E22D34BBD915EEB277D4F4138D176EACE5577CF035EF7C2C80A4BC4D9B6C0E1D
5872AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old~RF142190.TMPtext
MD5:D012E5B4EB91B61F6E8AE2F8EC3C623E
SHA256:1BDA750084F20306722008016420E1912BA608CA8EFB9C661F7E7EFCF5E89673
4944Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTINGbinary
MD5:DC84B0D741E5BEAE8070013ADDCC8C28
SHA256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
5872AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old~RF142307.TMPtext
MD5:ED7D8AAE48211E2BFAF557130572C62A
SHA256:A5CF8D8ADC86DCA357396AF7E3A24A116072D5C1E5552EEB76601AE2673DED6E
4944Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SharedDataEventsbinary
MD5:C5B4FC604EFCD9F6E1A14A66CBC218D5
SHA256:0AC01A203C160533D32F0D75079EDA2BE1C3B28DB893127CE95993BA975905FD
4944Acrobat.exeC:\Users\admin\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txttext
MD5:00BB29EEAE61DB541F053ED4CBDD8322
SHA256:CB6C620F325A36FFAD58CE37B2F75511E1024C23F5EAA1CB0BD63060828EAF3A
5244Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt23.lstbinary
MD5:366B140BAFC863B7E366AA1E51604759
SHA256:CBC8B288DBD2C72432081CF33CEF431572A94C7FB89DBCD59973B99E3871814E
5872AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0binary
MD5:3BEBB3C385ACD5E57E4FBDEBC93601CB
SHA256:4C34DD1722AE2230FFCD0016CE3FE5335CEB1A98EF291FD0CE6DE957460FBC79
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
35
DNS requests
22
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
436
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7104
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
436
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7104
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:137
whitelisted
640
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5064
SearchApp.exe
2.23.209.187:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
3820
32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
91.134.10.127:443
i.ibb.co
OVH SAS
FR
shared

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.110
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.106
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
www.bing.com
  • 2.23.209.187
  • 2.23.209.133
  • 2.23.209.189
  • 2.23.209.182
  • 2.23.209.140
  • 2.23.209.179
  • 2.23.209.149
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
i.ibb.co
  • 91.134.10.127
  • 91.134.10.168
  • 91.134.10.182
  • 91.134.9.159
  • 91.134.82.79
  • 91.134.9.160
shared
go.microsoft.com
  • 184.28.89.167
whitelisted
login.live.com
  • 20.190.160.20
  • 20.190.160.22
  • 40.126.32.74
  • 40.126.32.68
  • 40.126.32.72
  • 20.190.160.14
  • 40.126.32.76
  • 40.126.32.134
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] Image hosting service ImgBB
No debug info