File name:

AceSetup.exe

Full analysis: https://app.any.run/tasks/3f12d182-8699-4d28-9101-80b309c0981a
Verdict: Malicious activity
Analysis date: May 10, 2025, 02:39:24
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 11 sections
MD5:

2BFB7957861AD151EBEBA9966F2B58BF

SHA1:

98D351733AEFE9A0BEFB80E6986F0666977D787E

SHA256:

35FAEE420A6CD009B8CB6BCD334A9B3087B4161CF0202C96EC2DC51A22E4B7E3

SSDEEP:

98304:R1DfzXX48gaPwOma0q6f0nMrModyLAeJxuSkCUyo5CUosjI85N7RXVrw4DrC4TdC:5o5CUo5t2oHjerXemzo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • AceSetup.exe (PID: 7372)
      • setup.exe (PID: 2088)
      • setup.exe (PID: 5892)
      • mini_installer.exe (PID: 6800)
      • setup.exe (PID: 6476)
      • setup.exe (PID: 5344)
      • ace.exe (PID: 6048)
      • ace.exe (PID: 7364)
      • ace.exe (PID: 7420)
      • ace.exe (PID: 8064)
      • ace.exe (PID: 896)
      • ace.exe (PID: 1388)
      • ace.exe (PID: 1328)
      • ace.exe (PID: 7748)
      • ace.exe (PID: 300)
    • Changes the autorun value in the registry

      • setup.exe (PID: 2088)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • AceSetup.exe (PID: 7372)
    • Reads the date of Windows installation

      • AceSetup.exe (PID: 7372)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 7548)
      • setup.exe (PID: 2088)
      • mini_installer.exe (PID: 6800)
    • Application launched itself

      • AceSetup.exe (PID: 7372)
      • updater.exe (PID: 7548)
      • updater.exe (PID: 7708)
      • updater.exe (PID: 7864)
      • setup.exe (PID: 2088)
      • setup.exe (PID: 5344)
      • ace.exe (PID: 7364)
    • Executes as Windows Service

      • updater.exe (PID: 7864)
      • updater.exe (PID: 7708)
    • Searches for installed software

      • setup.exe (PID: 2088)
      • setup.exe (PID: 5344)
    • Creates a software uninstall entry

      • setup.exe (PID: 2088)
    • Reads Mozilla Firefox installation path

      • ace.exe (PID: 7364)
    • The process checks if it is being run in the virtual environment

      • ace.exe (PID: 7364)
  • INFO

    • Reads the computer name

      • AceSetup.exe (PID: 7372)
      • setup.exe (PID: 2088)
      • mini_installer.exe (PID: 6800)
      • setup.exe (PID: 5344)
      • ace.exe (PID: 896)
      • ace.exe (PID: 8064)
      • ace.exe (PID: 7364)
    • The sample compiled with english language support

      • AceSetup.exe (PID: 7372)
      • updater.exe (PID: 7548)
      • mini_installer.exe (PID: 6800)
      • setup.exe (PID: 2088)
    • Process checks computer location settings

      • AceSetup.exe (PID: 7372)
      • ace.exe (PID: 1388)
      • ace.exe (PID: 300)
      • ace.exe (PID: 7364)
      • ace.exe (PID: 1328)
      • ace.exe (PID: 7748)
    • Checks supported languages

      • AceSetup.exe (PID: 7372)
      • setup.exe (PID: 5892)
      • mini_installer.exe (PID: 6800)
      • setup.exe (PID: 2088)
      • setup.exe (PID: 6476)
      • setup.exe (PID: 5344)
      • ace.exe (PID: 896)
      • ace.exe (PID: 7364)
      • ace.exe (PID: 7420)
      • ace.exe (PID: 8064)
      • ace.exe (PID: 1388)
      • ace.exe (PID: 1328)
      • ace.exe (PID: 300)
      • ace.exe (PID: 6048)
      • ace.exe (PID: 7748)
    • Creates files in the program directory

      • setup.exe (PID: 2088)
      • updater.exe (PID: 7864)
      • setup.exe (PID: 5344)
    • Manual execution by a user

      • ace.exe (PID: 7364)
    • Creates files or folders in the user directory

      • ace.exe (PID: 7364)
      • ace.exe (PID: 896)
    • Reads the machine GUID from the registry

      • ace.exe (PID: 7364)
    • Create files in a temporary directory

      • ace.exe (PID: 7364)
    • Checks proxy server information

      • ace.exe (PID: 7364)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:02:05 09:39:59+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14
CodeSize: 3996160
InitializedDataSize: 8064512
UninitializedDataSize: -
EntryPoint: 0x393080
OSVersion: 10
ImageVersion: -
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 132.0.6852.0
ProductVersionNumber: 132.0.6852.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BrowseAI LLC
FileDescription: Ace Installer
FileVersion: 132.0.6852.0
InternalName: Ace Installer (x64)
LegalCopyright: Copyright 2025 The BrowseAI LLC Authors. All rights reserved.
OriginalFileName: UpdaterSetup.exe
ProductName: Ace Installer
ProductVersion: 132.0.6852.0
CompanyShortName: BrowseAI LLC
ProductShortName: AceUpdater
LastChange: 7de43b1cd6c8fa0cbd72b1aead50552822efa5f1
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
24
Malicious processes
6
Suspicious processes
10

Behavior graph

Click at the process to see the details
start acesetup.exe no specs acesetup.exe sppextcomobj.exe no specs slui.exe updater.exe no specs updater.exe no specs updater.exe no specs updater.exe no specs updater.exe no specs updater.exe no specs mini_installer.exe setup.exe setup.exe no specs setup.exe no specs setup.exe no specs ace.exe no specs ace.exe no specs ace.exe no specs ace.exe ace.exe no specs ace.exe no specs ace.exe no specs ace.exe no specs ace.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300"C:\Program Files\Ace\Ace\Application\ace.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=4352,i,4580397066442531427,6435457261412850944,262144 --variations-seed-version --mojo-platform-channel-handle=4832 /prefetch:1C:\Program Files\Ace\Ace\Application\ace.exeace.exe
User:
admin
Company:
BrowseAI LLC
Integrity Level:
LOW
Description:
Ace
Version:
132.0.6852.0
Modules
Images
c:\program files\ace\ace\application\ace.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\ace\ace\application\132.0.6852.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
896"C:\Program Files\Ace\Ace\Application\ace.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations --start-stack-profiler --field-trial-handle=2036,i,4580397066442531427,6435457261412850944,262144 --variations-seed-version --mojo-platform-channel-handle=2292 /prefetch:3C:\Program Files\Ace\Ace\Application\ace.exe
ace.exe
User:
admin
Company:
BrowseAI LLC
Integrity Level:
MEDIUM
Description:
Ace
Version:
132.0.6852.0
Modules
Images
c:\program files\ace\ace\application\ace.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\version.dll
c:\program files\ace\ace\application\132.0.6852.0\chrome_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1328"C:\Program Files\Ace\Ace\Application\ace.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=3232,i,4580397066442531427,6435457261412850944,262144 --variations-seed-version --mojo-platform-channel-handle=3388 /prefetch:1C:\Program Files\Ace\Ace\Application\ace.exeace.exe
User:
admin
Company:
BrowseAI LLC
Integrity Level:
LOW
Description:
Ace
Version:
132.0.6852.0
Modules
Images
c:\program files\ace\ace\application\ace.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\ace\ace\application\132.0.6852.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1388"C:\Program Files\Ace\Ace\Application\ace.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3212,i,4580397066442531427,6435457261412850944,262144 --variations-seed-version --mojo-platform-channel-handle=3268 /prefetch:1C:\Program Files\Ace\Ace\Application\ace.exeace.exe
User:
admin
Company:
BrowseAI LLC
Integrity Level:
LOW
Description:
Ace
Version:
132.0.6852.0
Modules
Images
c:\program files\ace\ace\application\ace.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\ace\ace\application\132.0.6852.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
2088"C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\CR_49DE3.tmp\setup.exe" --install-archive="C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\CR_49DE3.tmp\CHROME.PACKED.7Z" --do-not-launch-chromeC:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\CR_49DE3.tmp\setup.exe
mini_installer.exe
User:
SYSTEM
Company:
BrowseAI LLC
Integrity Level:
SYSTEM
Description:
Ace Installer
Exit code:
0
Version:
132.0.6852.0
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping7864_641232858\cr_49de3.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
5344"C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\CR_49DE3.tmp\setup.exe" --system-level --verbose-logging --create-shortcuts=0 --install-level=1C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\CR_49DE3.tmp\setup.exesetup.exe
User:
SYSTEM
Company:
BrowseAI LLC
Integrity Level:
SYSTEM
Description:
Ace Installer
Exit code:
73
Version:
132.0.6852.0
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping7864_641232858\cr_49de3.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
5892C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\CR_49DE3.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --annotation=plat=Win64 --annotation=prod=Ace --annotation=ver=132.0.6852.0 --initial-client-data=0x288,0x28c,0x290,0x200,0x294,0x7ff612c9a9a8,0x7ff612c9a9b4,0x7ff612c9a9c0C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\CR_49DE3.tmp\setup.exesetup.exe
User:
SYSTEM
Company:
BrowseAI LLC
Integrity Level:
SYSTEM
Description:
Ace Installer
Exit code:
0
Version:
132.0.6852.0
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping7864_641232858\cr_49de3.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
6048"C:\Program Files\Ace\Ace\Application\ace.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --string-annotations --field-trial-handle=2480,i,4580397066442531427,6435457261412850944,262144 --variations-seed-version --mojo-platform-channel-handle=2496 /prefetch:8C:\Program Files\Ace\Ace\Application\ace.exeace.exe
User:
admin
Company:
BrowseAI LLC
Integrity Level:
LOW
Description:
Ace
Version:
132.0.6852.0
Modules
Images
c:\program files\ace\ace\application\ace.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\ace\ace\application\132.0.6852.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
6476C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\CR_49DE3.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --annotation=plat=Win64 --annotation=prod=Ace --annotation=ver=132.0.6852.0 --initial-client-data=0x24c,0x250,0x254,0x228,0x258,0x7ff612c9a9a8,0x7ff612c9a9b4,0x7ff612c9a9c0C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\CR_49DE3.tmp\setup.exesetup.exe
User:
SYSTEM
Company:
BrowseAI LLC
Integrity Level:
SYSTEM
Description:
Ace Installer
Exit code:
0
Version:
132.0.6852.0
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping7864_641232858\cr_49de3.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
6800"C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\mini_installer.exe" --do-not-launch-chromeC:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\mini_installer.exe
updater.exe
User:
SYSTEM
Company:
BrowseAI LLC
Integrity Level:
SYSTEM
Description:
Ace Installer
Exit code:
0
Version:
132.0.6852.0
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping7864_641232858\mini_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
Total events
3 857
Read events
3 714
Write events
140
Delete events
3

Modification events

(PID) Process:(2088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ace\Update\ClientState\{908aaf3d-6daa-4f36-a9b0-538d90bec8c1}
Operation:writeName:InstallerProgress
Value:
19
(PID) Process:(2088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ace\Update\ClientState\{908aaf3d-6daa-4f36-a9b0-538d90bec8c1}
Operation:writeName:InstallerProgress
Value:
25
(PID) Process:(2088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ace\Update\ClientState\{908aaf3d-6daa-4f36-a9b0-538d90bec8c1}
Operation:writeName:InstallerProgress
Value:
39
(PID) Process:(2088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ace\Update\ClientState\{908aaf3d-6daa-4f36-a9b0-538d90bec8c1}
Operation:writeName:InstallerProgress
Value:
46
(PID) Process:(2088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ace\Update\ClientState\{908aaf3d-6daa-4f36-a9b0-538d90bec8c1}
Operation:writeName:InstallerProgress
Value:
53
(PID) Process:(2088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ace\Update\ClientState\{908aaf3d-6daa-4f36-a9b0-538d90bec8c1}
Operation:writeName:InstallerProgress
Value:
59
(PID) Process:(2088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ace\Update\Clients\{908AAF3D-6DAA-4F36-A9B0-538D90BEC8C1}\Commands\on-os-upgrade
Operation:writeName:CommandLine
Value:
"C:\Program Files\Ace\Ace\Application\132.0.6852.0\Installer\setup.exe" --on-os-upgrade --system-level --verbose-logging %1
(PID) Process:(2088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ace\Update\Clients\{908AAF3D-6DAA-4F36-A9B0-538D90BEC8C1}\Commands\on-os-upgrade
Operation:writeName:AutoRunOnOSUpgrade
Value:
1
(PID) Process:(2088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33A69274-FA45-4654-8704-3A9645B388D0}\LocalServer32
Operation:writeName:ServerExecutable
Value:
C:\Program Files\Ace\Ace\Application\132.0.6852.0\notification_helper.exe
(PID) Process:(2088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{773FE669-69ED-4029-AED1-BD57595C8358}
Operation:writeName:AppID
Value:
{773FE669-69ED-4029-AED1-BD57595C8358}
Executable files
10
Suspicious files
94
Text files
38
Unknown types
7

Dropped files

PID
Process
Filename
Type
7864updater.exeC:\Windows\SystemTemp\chrome_url_fetcher_7864_1137753365\mini_installer_1_a1xjCdH.crx3
MD5:
SHA256:
7864updater.exeC:\Program Files (x86)\Ace\AceUpdater\crx_cache\{908aaf3d-6daa-4f36-a9b0-538d90bec8c1}_1.727721af1c3313f311bdaa78da7c06462c108f26870a200faff87ac531cec6fd
MD5:
SHA256:
7864updater.exeC:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\mini_installer.exe
MD5:
SHA256:
6800mini_installer.exeC:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping7864_641232858\CR_49DE3.tmp\CHROME.PACKED.7Z
MD5:
SHA256:
7548updater.exeC:\Program Files (x86)\Ace\AceUpdater\prefs.jsonbinary
MD5:0DBA0A201B32E6AC338C910BF0C6422C
SHA256:25032D6B1F04A20501E1D417B4FDD201ACD655FA6BE3BE4C636BCBD240A67465
2088setup.exeC:\Program Files\Ace\Ace\Application\chrome.VisualElementsManifest.xmltext
MD5:6013747DB053EF0A58AA42CFA5460804
SHA256:73B16498595B89CA5FFA51968B161F09E0FAB5752BC97BC88754138145B814CC
2088setup.exeC:\Program Files\Ace\Ace\Application\ace.exeexecutable
MD5:7DD237EB5C5CF1ED1F7670D2D190EA13
SHA256:64F9EB1472A3E9D748CA797974444E63F519871FEBCF40428D464D6BABF2530D
7548updater.exeC:\Program Files (x86)\Ace\AceUpdater\d62fd7df-fe2f-407a-8da7-e90239775f81.tmpbinary
MD5:0DBA0A201B32E6AC338C910BF0C6422C
SHA256:25032D6B1F04A20501E1D417B4FDD201ACD655FA6BE3BE4C636BCBD240A67465
2088setup.exeC:\Program Files\Ace\Ace\Application\132.0.6852.0\Installer\chrome.7z
MD5:
SHA256:
7548updater.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B5FC60CCA5D8CF767A7572C65728CD6_80AA51F10C2F500DEBC45F3B2A97930Cbinary
MD5:496802350FDFE665CF78B5B480A87266
SHA256:9753D034D679911DEEB65BDCD448569F4A9C4E4ABB23710A0EBDA7CE5DEF3906
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
23
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5512
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
142.250.186.35:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
GET
200
142.250.186.35:80
http://o.pki.goog/we2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEA85wFTvuwmlCdtY0UxEIqg%3D
unknown
whitelisted
5512
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
23.216.77.18:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
142.250.186.35:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.18:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
104.22.33.172:443
update.ace.ai
CLOUDFLARENET
unknown
20.190.160.14:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.18
  • 23.216.77.21
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 172.217.16.206
whitelisted
update.ace.ai
  • 104.22.33.172
  • 104.22.32.172
  • 172.67.22.216
unknown
login.live.com
  • 20.190.160.14
  • 20.190.160.131
  • 20.190.160.66
  • 20.190.160.132
  • 40.126.32.133
  • 20.190.160.67
  • 20.190.160.128
  • 40.126.32.76
whitelisted
dl.google.com
  • 142.250.185.238
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
c.pki.goog
  • 142.250.186.35
whitelisted
o.pki.goog
  • 142.250.186.35
whitelisted

Threats

No threats detected
No debug info