File name:

RapportSetup.exe

Full analysis: https://app.any.run/tasks/fa3f2ae3-6f2d-4baf-b26c-86b31bbf5724
Verdict: Malicious activity
Analysis date: July 23, 2025, 17:51:11
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
antivm
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

FB7BAAF98CE8F9B302BD5F344478BBF4

SHA1:

2F3C60B13DCF12B0D787EB4D1CB2B81E4BE9DC9D

SHA256:

3B7FFA3403A103E102F6BCEF3E8ACBE8EE5974F1063240B4396ADA52265981F3

SSDEEP:

6144:PNK7Z9gZuk8B3aCEMfhL61bcgr+9c0HN8gbD4UtmgazeupzeuyD/Pfewz:PNK7Z9gZuko3aCeZcgr+q0K6MgrDewz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • RapportSetup.exe (PID: 6680)
      • RapportSetup.exe (PID: 2992)
      • msiexec.exe (PID: 2288)
      • RapportService.exe (PID: 4560)
      • RapportMgmtService.exe (PID: 2580)
      • ShellExperienceHost.exe (PID: 3652)
      • RapportService.exe (PID: 6544)
    • Application launched itself

      • RapportSetup.exe (PID: 6680)
      • RapportService.exe (PID: 3940)
      • RapportService.exe (PID: 4560)
    • There is functionality for taking screenshot (YARA)

      • RapportSetup.exe (PID: 6680)
      • RapportSetup.exe (PID: 2992)
      • msiexec.exe (PID: 2288)
    • Reads the Windows owner or organization settings

      • RapportSetup.exe (PID: 2992)
      • msiexec.exe (PID: 1212)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 1212)
      • msiexec.exe (PID: 2288)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3400)
      • RapportMgmtService.exe (PID: 2580)
    • Executable content was dropped or overwritten

      • RapportSetup.exe (PID: 2992)
    • Creates files in the driver directory

      • msiexec.exe (PID: 2288)
    • There is functionality for VM detection VirtualBox (YARA)

      • msiexec.exe (PID: 2288)
    • Reads the BIOS version

      • RapportMgmtService.exe (PID: 2580)
      • RapportService.exe (PID: 4560)
    • The process checks if it is being run in the virtual environment

      • RapportMgmtService.exe (PID: 2580)
      • RapportService.exe (PID: 4560)
    • Starts CMD.EXE for commands execution

      • RapportService.exe (PID: 4560)
    • Reads Microsoft Outlook installation path

      • RapportService.exe (PID: 6544)
    • Reads Internet Explorer settings

      • RapportService.exe (PID: 6544)
    • Creates or modifies Windows services

      • RapportMgmtService.exe (PID: 2580)
  • INFO

    • Creates files in the program directory

      • RapportSetup.exe (PID: 2992)
      • RapportMgmtService.exe (PID: 2580)
      • RapportInjService_x64.exe (PID: 4116)
      • RapportInjService_x64.exe (PID: 2876)
    • Reads the computer name

      • RapportSetup.exe (PID: 2992)
      • RapportSetup.exe (PID: 6680)
      • msiexec.exe (PID: 5684)
      • msiexec.exe (PID: 1212)
      • msiexec.exe (PID: 2288)
      • msiexec.exe (PID: 828)
      • RapportMgmtService.exe (PID: 2580)
      • RapportService.exe (PID: 3940)
      • RapportService.exe (PID: 4560)
      • RapportService.exe (PID: 6544)
      • RapportService.exe (PID: 4824)
      • ShellExperienceHost.exe (PID: 3652)
    • Process checks computer location settings

      • RapportSetup.exe (PID: 6680)
    • Checks supported languages

      • RapportSetup.exe (PID: 6680)
      • RapportSetup.exe (PID: 2992)
      • msiexec.exe (PID: 5684)
      • msiexec.exe (PID: 1212)
      • msiexec.exe (PID: 2288)
      • msiexec.exe (PID: 828)
      • RapportMgmtService.exe (PID: 2580)
      • RapportInjService_x64.exe (PID: 4116)
      • RapportService.exe (PID: 3940)
      • RapportService.exe (PID: 4560)
      • RapportInjService_x64.exe (PID: 2876)
      • RapportService.exe (PID: 6544)
      • RapportInjService_x64.exe (PID: 1704)
      • ShellExperienceHost.exe (PID: 3652)
      • RapportService.exe (PID: 4824)
    • Checks proxy server information

      • RapportSetup.exe (PID: 2992)
      • RapportService.exe (PID: 4560)
      • RapportService.exe (PID: 6544)
      • slui.exe (PID: 4200)
    • Reads the machine GUID from the registry

      • RapportSetup.exe (PID: 2992)
      • msiexec.exe (PID: 2288)
      • msiexec.exe (PID: 1212)
      • RapportMgmtService.exe (PID: 2580)
      • RapportInjService_x64.exe (PID: 4116)
      • RapportInjService_x64.exe (PID: 2876)
      • RapportService.exe (PID: 4560)
      • RapportService.exe (PID: 3940)
      • RapportService.exe (PID: 6544)
      • RapportInjService_x64.exe (PID: 1704)
      • RapportService.exe (PID: 4824)
    • Create files in a temporary directory

      • RapportSetup.exe (PID: 2992)
    • Creates files or folders in the user directory

      • RapportSetup.exe (PID: 2992)
      • msiexec.exe (PID: 2288)
      • RapportService.exe (PID: 3940)
      • RapportService.exe (PID: 4560)
      • RapportInjService_x64.exe (PID: 1704)
      • RapportService.exe (PID: 6544)
      • RapportService.exe (PID: 4824)
    • Reads the software policy settings

      • RapportSetup.exe (PID: 2992)
      • msiexec.exe (PID: 1212)
      • RapportMgmtService.exe (PID: 2580)
      • slui.exe (PID: 4200)
    • The sample compiled with english language support

      • RapportSetup.exe (PID: 6680)
      • msiexec.exe (PID: 1212)
      • msiexec.exe (PID: 2288)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1212)
      • msiexec.exe (PID: 2288)
    • Manages system restore points

      • SrTasks.exe (PID: 1160)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1212)
    • Creates or modifies Windows services

      • msiexec.exe (PID: 2288)
    • Creates a new folder

      • cmd.exe (PID: 4724)
    • Manual execution by a user

      • RapportService.exe (PID: 4824)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:05 16:32:41+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 183808
InitializedDataSize: 342016
UninitializedDataSize: -
EntryPoint: 0x12b3b
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.5.2309.290
ProductVersionNumber: 3.5.2309.290
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: IBM Corp.
ProductName: Rapport Installer
FileDescription: Rapport Setup
FileVersion: 3.5.2309.290
LegalCopyright: (c) Copyright 2007, 2014, 2023 IBM Corp.
InternalName: RapportSetup
OriginalFileName: RapportSetup
CodeName: Emerald
ProductVersion: 3.5.2309.290
BuildFlavor: standard-release
BuildConfig: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
171
Monitored processes
22
Malicious processes
4
Suspicious processes
4

Behavior graph

Click at the process to see the details
start rapportsetup.exe no specs rapportsetup.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe slui.exe msiexec.exe no specs rapportmgmtservice.exe rapportinjservice_x64.exe no specs rapportinjservice_x64.exe no specs rapportservice.exe no specs rapportservice.exe no specs rapportinjservice_x64.exe no specs cmd.exe no specs conhost.exe no specs rapportservice.exe no specs shellexperiencehost.exe no specs rundll32.exe no specs rapportservice.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
828C:\Windows\syswow64\MsiExec.exe -Embedding BDDC75EAD04EFD039971D3D358EF8B12 E Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1160C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1212C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1704"c:\program files (x86)\trusteer\rapport\bin\x64\rapportinjservice_x64.exe" -services -injection-serverC:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exeRapportService.exe
User:
admin
Company:
IBM Corp.
Integrity Level:
HIGH
Description:
RapportInjService_x64
Version:
3.5.2309.290
Modules
Images
c:\program files (x86)\trusteer\rapport\bin\x64\rapportinjservice_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2288C:\Windows\syswow64\MsiExec.exe -Embedding 8852705B8BA8873B6941A92F69CF379CC:\Windows\SysWOW64\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2580"C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe"C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\trusteer\rapport\bin\rapportmgmtservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2876"c:\program files (x86)\trusteer\rapport\bin\x64\rapportinjservice_x64.exe" -services -injection-serverC:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exeRapportMgmtService.exe
User:
SYSTEM
Company:
IBM Corp.
Integrity Level:
SYSTEM
Description:
RapportInjService_x64
Version:
3.5.2309.290
Modules
Images
c:\program files (x86)\trusteer\rapport\bin\x64\rapportinjservice_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\program files (x86)\trusteer\rapport\bin\x64\trf_x64.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2992"C:\Users\admin\Desktop\RapportSetup.exe" C:\Users\admin\Desktop\RapportSetup.exe
RapportSetup.exe
User:
admin
Company:
IBM Corp.
Integrity Level:
HIGH
Description:
Rapport Setup
Exit code:
0
Version:
3.5.2309.290
Modules
Images
c:\users\admin\desktop\rapportsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
3400C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3652"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\dxgi.dll
Total events
49 350
Read events
48 851
Write events
485
Delete events
14

Modification events

(PID) Process:(1212) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000002B0D8479FAFBDB01BC040000780F0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1212) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
480000000000000077845B79FAFBDB01BC040000780F0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1212) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
480000000000000077845B79FAFBDB01BC040000780F0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1212) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000C0A98179FAFBDB01BC040000780F0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1212) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000C0A98179FAFBDB01BC040000780F0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1212) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
480000000000000040D48879FAFBDB01BC040000780F0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3400) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(3400) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
(PID) Process:(3400) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000002
Operation:delete keyName:(default)
Value:
(PID) Process:(3400) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000002
Operation:writeName:Element
Value:
\EFI\Microsoft\Boot\bootmgfw.efi
Executable files
97
Suspicious files
31
Text files
34
Unknown types
1 353

Dropped files

PID
Process
Filename
Type
2992RapportSetup.exeC:\Users\admin\AppData\Local\Temp\rap1640562\RapportSetup-Full.msi.cmp
MD5:
SHA256:
2992RapportSetup.exeC:\Users\admin\AppData\Local\Temp\rap1640562\RapportSetup-Full.msi
MD5:
SHA256:
1212msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1212msiexec.exeC:\Windows\Installer\198c0a.msi
MD5:
SHA256:
2992RapportSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_8E4037AFF49696037FF97FEB53123AA3der
MD5:B7D2288831A037EEA8CF81DD2349CDFC
SHA256:A402BDF827307A87C109EF57F9CAC413B2C295E1389800C7BC849E30C4E4EF68
2992RapportSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBder
MD5:3D8B77394580FF03F47E751B2F4EB2F0
SHA256:A08231DBEE98DD09122BB8DBCFC3D7D5563B472225D4A7B55F95D42208BF0F85
2992RapportSetup.exeC:\Users\admin\AppData\Local\Temp\MSI3F61.tmpexecutable
MD5:16F9CB4EDEA795404EFC23D378004052
SHA256:3A1878C2981ABBE946ABF94F46D17DBB4988FDAD11F2C34FF1E088955B5C1BEC
2992RapportSetup.exeC:\Users\admin\AppData\Local\Temp\MSI4138.tmpexecutable
MD5:16F9CB4EDEA795404EFC23D378004052
SHA256:3A1878C2981ABBE946ABF94F46D17DBB4988FDAD11F2C34FF1E088955B5C1BEC
2992RapportSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141der
MD5:6C480D681261FCBCBB0C397430A3998C
SHA256:68ADECE02DA1DFB4B3ABF7200A04855A5253027361B606D268F71C79A2EBE646
2992RapportSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_8E4037AFF49696037FF97FEB53123AA3binary
MD5:B7D4B82964B1819FAEEC9C6792718055
SHA256:B41E284962ECF638B4BB4730971D1DD5D7F45EA69F6F0A8CAEAD91309343D4B1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
45
DNS requests
32
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.55.110.211:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2992
RapportSetup.exe
GET
18.173.205.36:80
http://cdn.trusteer.com/Ehaur8Znbh/3.5.2309.290-standard-release-santanderes/RapportSetup-Full_x64.cmp
unknown
whitelisted
2992
RapportSetup.exe
GET
302
18.204.179.240:80
http://updates.trusteer.com/Ehaur8Znbh/3.5.2309.290-standard-release-santanderes/RapportSetup-Full_x64.cmp?x-t=F6BDAACA
unknown
unknown
4800
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2992
RapportSetup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
2992
RapportSetup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
2992
RapportSetup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAp8kaTILmpJnciNZOC7h38%3D
unknown
whitelisted
4948
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4948
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6584
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.55.110.211:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2992
RapportSetup.exe
18.204.179.240:80
updates.trusteer.com
AMAZON-AES
US
suspicious
2992
RapportSetup.exe
18.173.205.36:80
cdn.trusteer.com
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.55.110.211
  • 23.55.110.193
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 184.30.21.171
whitelisted
updates.trusteer.com
  • 18.204.179.240
  • 3.233.90.145
  • 3.81.156.190
  • 3.225.141.254
  • 52.200.184.145
  • 34.196.181.67
unknown
cdn.trusteer.com
  • 18.173.205.36
  • 18.173.205.78
  • 18.173.205.81
  • 18.173.205.75
whitelisted
login.live.com
  • 40.126.31.2
  • 40.126.31.1
  • 40.126.31.73
  • 40.126.31.129
  • 20.190.159.0
  • 20.190.159.73
  • 20.190.159.64
  • 20.190.159.128
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted

Threats

No threats detected
No debug info