File name:

ITC-INFOTECH-snowagent-7.2.0-x64 (1).msi

Full analysis: https://app.any.run/tasks/e1e5f9cd-ed70-44c5-857b-06f5b29b875a
Verdict: Malicious activity
Analysis date: January 02, 2025, 04:52:47
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Snow Inventory Agent for Windows, Author: Snow Software, Keywords: Installer, Comments: This installer database contains the logic and data required to install Snow Inventory Agent for Windows., Template: x64;1033, Revision Number: {0F3DDD24-C6CF-48D6-8223-131A8628DC43}, Create Time/Date: Thu Dec 26 10:25:16 2024, Last Saved Time/Date: Thu Dec 26 10:25:16 2024, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.1.2318), Security: 2
MD5:

4F61EF821AC21CEAF7517BB931A925DC

SHA1:

0CC7A966244F8C13FB82A1679B0C59F94690DFE4

SHA256:

354E8F7C34440377629C4AD6A9FD2BF52D76B9830719F8B2FE70A9843E3257AE

SSDEEP:

98304:Rrz+mA3qijmsn3EEUELHYmE996psoPtTf4zHTFw/EL/EHWp5ed1BRDWvP4QVNmtQ:1zlQ7dJhd3MASzadDTaVOKZuuB7g/P

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 6820)
      • snowagent.exe (PID: 4708)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6764)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6764)
      • snowagent.exe (PID: 4708)
    • Executes application which crashes

      • msiexec.exe (PID: 4944)
    • The process creates files with name similar to system file names

      • WerFault.exe (PID: 4980)
    • Application launched itself

      • snowagent.exe (PID: 4708)
    • Reads the date of Windows installation

      • snowagent.exe (PID: 4708)
  • INFO

    • The sample compiled with english language support

      • msiexec.exe (PID: 6588)
      • msiexec.exe (PID: 6764)
    • Checks proxy server information

      • msiexec.exe (PID: 6588)
    • Reads the software policy settings

      • msiexec.exe (PID: 6588)
      • msiexec.exe (PID: 6764)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 6588)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6588)
    • Manages system restore points

      • SrTasks.exe (PID: 6204)
    • Checks supported languages

      • msiexec.exe (PID: 6764)
      • msiexec.exe (PID: 4944)
      • snowagent.exe (PID: 4652)
      • snowagent.exe (PID: 4708)
    • Reads the computer name

      • msiexec.exe (PID: 6764)
      • msiexec.exe (PID: 4944)
      • snowagent.exe (PID: 4708)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 6764)
      • snowagent.exe (PID: 4708)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6764)
    • Application launched itself

      • msiexec.exe (PID: 6764)
    • Reads Environment values

      • msiexec.exe (PID: 4944)
      • snowagent.exe (PID: 4708)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6764)
    • Creates files in the program directory

      • snowagent.exe (PID: 4708)
    • Reads Windows Product ID

      • snowagent.exe (PID: 4708)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Snow Inventory Agent for Windows
Author: Snow Software
Keywords: Installer
Comments: This installer database contains the logic and data required to install Snow Inventory Agent for Windows.
Template: x64;1033
RevisionNumber: {0F3DDD24-C6CF-48D6-8223-131A8628DC43}
CreateDate: 2024:12:26 10:25:16
ModifyDate: 2024:12:26 10:25:16
Pages: 200
Words: 2
Software: Windows Installer XML Toolset (3.11.1.2318)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
10
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe werfault.exe no specs snowagent.exe snowagent.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2084\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesnowagent.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4652"C:\Program Files\Snow Software\Inventory\Agent\snowagent.exe" query-winlogonC:\Program Files\Snow Software\Inventory\Agent\snowagent.exesnowagent.exe
User:
admin
Company:
Snow Software AB
Integrity Level:
MEDIUM
Description:
Snow Inventory Agent for Windows
Exit code:
0
Version:
7.2.0+build-BUILD_DATE-rev-BUILD_REVISION
Modules
Images
c:\program files\snow software\inventory\agent\snowagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
4708"C:\Program Files\Snow Software\Inventory\Agent\snowagent.exe" -w "C:\Program Files\Snow Software\Inventory\Agent"C:\Program Files\Snow Software\Inventory\Agent\snowagent.exe
services.exe
User:
SYSTEM
Company:
Snow Software AB
Integrity Level:
SYSTEM
Description:
Snow Inventory Agent for Windows
Version:
7.2.0+build-BUILD_DATE-rev-BUILD_REVISION
Modules
Images
c:\program files\snow software\inventory\agent\snowagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
4944C:\Windows\System32\MsiExec.exe -Embedding 0E342F0A9F5B3E645C8CD4FD23AA8143 E Global\MSI0000C:\Windows\System32\msiexec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4980C:\WINDOWS\system32\WerFault.exe -u -p 4944 -s 916C:\Windows\System32\WerFault.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\oleaut32.dll
6192\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6204C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6588"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\ITC-INFOTECH-snowagent-7.2.0-x64 (1).msi"C:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6764C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6820C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
11 501
Read events
11 191
Write events
290
Delete events
20

Modification events

(PID) Process:(6764) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000F18B8532D25CDB016C1A0000941A0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6764) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000F18B8532D25CDB016C1A0000941A0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6764) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000570ACD32D25CDB016C1A0000941A0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6764) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000570ACD32D25CDB016C1A0000941A0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6764) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000002E6DCF32D25CDB016C1A0000941A0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6764) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000005A34D432D25CDB016C1A0000941A0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6764) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6764) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
480000000000000046E34133D25CDB016C1A0000941A0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6764) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000000C464433D25CDB016C1A0000141B0000E80300000100000000000000000000001DEB5B04955E99498A02F4EEEA12281F00000000000000000000000000000000
(PID) Process:(6820) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000098285033D25CDB01A41A0000341B0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
5
Suspicious files
26
Text files
18
Unknown types
3

Dropped files

PID
Process
Filename
Type
6764msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6764msiexec.exeC:\Windows\Installer\139bf5.msi
MD5:
SHA256:
6588msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141der
MD5:C4F75F06F0E3C76FF4BF45DCC5E611B5
SHA256:E506906848BF5C685C17D3AD63865EF286055B93A969C627E296A0460C9DFD82
6588msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_BCAD9640A0F902FA561B64F4157C051Dder
MD5:5F63E9C6A793911571A667481B27D4DC
SHA256:485855DBED99937424D5D07C9378AA522E83B3F4791C5CB732E2CB35CB737C60
6588msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:1FB9DDF8FC88C1C82628860CC6F7B855
SHA256:C528438AF7B362BBC11A6825EF9B06DEE350028A71323014C375BAE2E216C98F
6764msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:2AB8BBDCD8BCA5C9F90D1276D4D61CC9
SHA256:096F76386B58C9D6290BA1C6B99624A97C6CF3DE2F1C4CBD54BA6B80E4044AC9
6588msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:7589FF8486C5DD6807EE2FD354F22BBE
SHA256:79748F651712C7F4B34F6C49007BCBBC01AEE4F83E2A757FAD74B5321635B5D7
6764msiexec.exeC:\Windows\Temp\~DFB7D912ED163745AD.TMPbinary
MD5:F835B8F49E9E1EB097B3E789AFBEC484
SHA256:A820F87925D7495788C9CAF7CC528109C394665E29CCDCB80714131C6CF2EA47
6588msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:19191CC604E30A3150430C479655AB0E
SHA256:C2DA696759A1A1717589E40001CF7BB195BCA7B30DDA4ADC106CF35D67A2E388
6764msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{045beb1d-5e95-4999-8a02-f4eeea12281f}_OnDiskSnapshotPropbinary
MD5:2AB8BBDCD8BCA5C9F90D1276D4D61CC9
SHA256:096F76386B58C9D6290BA1C6B99624A97C6CF3DE2F1C4CBD54BA6B80E4044AC9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
34
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6588
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
6588
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6588
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAzpQ5EYx0TZ8BnzmGkSrBw%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7136
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7136
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6412
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:137
whitelisted
440
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
5064
SearchApp.exe
104.126.37.136:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
whitelisted
google.com
  • 142.250.185.206
whitelisted
www.bing.com
  • 104.126.37.136
  • 104.126.37.128
  • 104.126.37.123
  • 104.126.37.154
  • 104.126.37.155
  • 104.126.37.161
  • 104.126.37.153
  • 104.126.37.131
  • 104.126.37.163
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.71
  • 20.190.159.75
  • 20.190.159.64
  • 40.126.31.69
  • 20.190.159.2
  • 20.190.159.73
whitelisted
go.microsoft.com
  • 184.30.17.189
unknown
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info