File name:

windows-outbyte-driver-updater.exe

Full analysis: https://app.any.run/tasks/64713c27-ff5c-4099-9c17-7d0d11875282
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: May 17, 2025, 19:48:18
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

3A186EA09647B472D3425378935A04B3

SHA1:

1F9202698CA21133898F6B3972AC5BFD29127F99

SHA256:

3C3204CE0DAA4FD1AF3D4F017FBA57B793651719944C317324B23EF2BB867195

SSDEEP:

393216:0wTacZ3vB5S8VSE+nuUneQztAGnb4fEN:0QDvBM8grDeQp/nlN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • Installer.exe (PID: 6740)
    • Steals credentials from Web Browsers

      • Installer.exe (PID: 6740)
    • Executing a file with an untrusted certificate

      • DriverUpdater.exe (PID: 5452)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 2064)
      • DriverUpdater.exe (PID: 4164)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
    • Executable content was dropped or overwritten

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
    • Reads the Windows owner or organization settings

      • Installer.exe (PID: 6740)
    • Reads the BIOS version

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
    • There is functionality for communication over UDP network (YARA)

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 5452)
    • Process drops legitimate windows executable

      • Installer.exe (PID: 6740)
    • There is functionality for taking screenshot (YARA)

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 5452)
    • Process drops SQLite DLL files

      • Installer.exe (PID: 6740)
    • Reads browser cookies

      • Installer.exe (PID: 6740)
    • Creates a software uninstall entry

      • Installer.exe (PID: 6740)
  • INFO

    • Process checks computer location settings

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
    • Checks supported languages

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
    • The sample compiled with english language support

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
    • Create files in a temporary directory

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
    • Reads the computer name

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
    • Checks proxy server information

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
    • Reads the machine GUID from the registry

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
    • Reads the software policy settings

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • slui.exe (PID: 720)
      • DriverUpdater.exe (PID: 5452)
    • Creates files or folders in the user directory

      • Installer.exe (PID: 6740)
    • Creates files in the program directory

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
    • Compiled with Borland Delphi (YARA)

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 5452)
    • Manual execution by a user

      • DriverUpdater.exe (PID: 4164)
      • DriverUpdater.exe (PID: 2064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (generic) (79.7)
.exe | Win32 Executable (generic) (8.6)
.exe | Win16/32 Executable Delphi generic (3.9)
.exe | Generic Win/DOS Executable (3.8)
.exe | DOS Executable Generic (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:05:26 11:18:03+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 143872
InitializedDataSize: 330240
UninitializedDataSize: -
EntryPoint: 0x24530
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.1.1.60362
ProductVersionNumber: 2.1.1.60362
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Driver Updater
CompanyName: Outbyte
FileDescription: Outbyte Driver Updater Installation File
FileVersion: 2.1.1.60362
LegalCopyright: Copyright © 2016-2020 Outbyte Computing Pty Ltd
OriginalFileName: Outbyte-driver-updater-setup.exe
ProductName: Driver Updater
ProductVersion: 2.x
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
10
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start windows-outbyte-driver-updater.exe sppextcomobj.exe no specs slui.exe installer.exe driverupdater.exe no specs driverupdater.exe no specs slui.exe driverupdater.exe no specs driverupdater.exe windows-outbyte-driver-updater.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
720"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2064"C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exeexplorer.exe
User:
admin
Company:
Outbyte
Integrity Level:
MEDIUM
Description:
Driver Updater
Exit code:
3221226540
Version:
2.1.1.60362
Modules
Images
c:\program files (x86)\outbyte\driver updater\driverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2316C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
3304"C:\Users\admin\AppData\Local\Temp\windows-outbyte-driver-updater.exe" C:\Users\admin\AppData\Local\Temp\windows-outbyte-driver-updater.exe
explorer.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Outbyte Driver Updater Installation File
Exit code:
4343088
Version:
2.1.1.60362
Modules
Images
c:\users\admin\appdata\local\temp\windows-outbyte-driver-updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4164"C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe
explorer.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Driver Updater
Exit code:
0
Version:
2.1.1.60362
Modules
Images
c:\program files (x86)\outbyte\driver updater\driverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4212"C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" /Install /SendInfo /AutoStartC:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exeInstaller.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Driver Updater
Exit code:
0
Version:
2.1.1.60362
Modules
Images
c:\program files (x86)\outbyte\driver updater\driverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
5452"C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" /FromInstaller /AutoScanC:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exeInstaller.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Driver Updater
Exit code:
0
Version:
2.1.1.60362
Modules
Images
c:\program files (x86)\outbyte\driver updater\driverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
5776"C:\Users\admin\AppData\Local\Temp\windows-outbyte-driver-updater.exe" C:\Users\admin\AppData\Local\Temp\windows-outbyte-driver-updater.exeexplorer.exe
User:
admin
Company:
Outbyte
Integrity Level:
MEDIUM
Description:
Outbyte Driver Updater Installation File
Exit code:
3221226540
Version:
2.1.1.60362
Modules
Images
c:\users\admin\appdata\local\temp\windows-outbyte-driver-updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6740"C:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Installer.exe" /spid:3304 /splha:37266240C:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Installer.exe
windows-outbyte-driver-updater.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Installer
Exit code:
0
Version:
2.1.1.60362
Modules
Images
c:\users\admin\appdata\local\temp\is-22291454.tmp\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
6964C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
18 741
Read events
18 686
Write events
52
Delete events
3

Modification events

(PID) Process:(6740) Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{6D484312-C2E8-96B5-2103-43B791F33EFF}\Version
Operation:writeName:Assembly
Value:
6ED89B045A334E85CB0A56B990587F3D6ED89B045A334E85CB0A56B990587F3D88AD8CBB5ED3F66B83A8A2CDF194269C890BB34AEBD806E41A50D3BD9C0B4765219909F09E75DEC0927FF4E8152284CD219909F09E75DEC0927FF4E8152284CD59B5414605BAE21E9735786EB516D3F8DE1283C2AFF9BF99D33ED2740C86BBD2F8157495FE950FA4A01046BB55F00DAD0F20AA1B1ADFE602954529934D03147D
(PID) Process:(6740) Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Outbyte\Driver Updater\2.x\Settings
Operation:writeName:Application.TestsErrorCode
Value:
C:\Users\admin\AppData\Local\Temp\windows-outbyte
(PID) Process:(6740) Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Outbyte\Driver Updater\2.x\Settings
Operation:writeName:GoogleAnalytics.CustomCategory
Value:
2.1.1.60362-null-enu-null-lite
(PID) Process:(6740) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6740) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6740) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3304) windows-outbyte-driver-updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Outbyte\Driver Updater\2.x\Settings
Operation:writeName:General.CustomClientId
Value:
{6C84ADCB-9112-44D9-8384-0CF86D5344A1}
(PID) Process:(3304) windows-outbyte-driver-updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Outbyte\Driver Updater\2.x\Settings
Operation:writeName:General.Tracking.Param_ClientId
Value:
{6C84ADCB-9112-44D9-8384-0CF86D5344A1}
(PID) Process:(3304) windows-outbyte-driver-updater.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3304) windows-outbyte-driver-updater.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
78
Suspicious files
62
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Lang\deu.lngbinary
MD5:52D79E37360F71F80B92BAD100FFA2EB
SHA256:7498F8B7506483E2714814B354B4C9F9B71D9BA523EE3869606819298CFCE942
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Lang\fra.lngbinary
MD5:4777A59A93AC0CA16752C898760A38FB
SHA256:89EA071190DFA64B52D3C8E9019586DC226C84C1782B94480134BCA310003BD7
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Lang\ptb.lngbinary
MD5:2D7012F0B451628722EA265CD4EBEF60
SHA256:0D8555A8F01D119E861AE95F7D52B924DE50B5D49A8A49A31034C421BC7EC110
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Lang\ita.lngbinary
MD5:F889387E507A3BE7287CDBD7F29416C7
SHA256:050879A9446AAEB64C13409D90BE8E6991C2681621C97E0668F22BE885CA95E2
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\rtl250.bplexecutable
MD5:E55E34351C51C9EF62593CC98294B6AB
SHA256:5EF32DE82F0004722A478C1E3A8A1A637234DD22DCC119C987E0587764B2EEFF
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Installer.exebinary
MD5:4E491E8B779BD484734413F4F9B2B740
SHA256:25B7A33585E980A5CF18707E2A1F1299AE5F5AA2D99FAD68D81B50A4AEC733BC
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\vcl250.bplexecutable
MD5:56D3550991C210AA818D0606E3D83433
SHA256:17E21138BCEC8E8D0CEAC24A6604FCCDF532503661A746CCFDBDF52AE37E5508
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Localizer.dllexecutable
MD5:692B62281B5AF952F482377AD05CBDDE
SHA256:9434621D1245632CFDBEF5D6E28EBED958CB05C330D408B74B7B1C8040FBA541
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\vclimg250.bplexecutable
MD5:6654051A567DD87EC54FB446986DD244
SHA256:B2D78F9F21343C3EAF51EF9F3E4A0F4F24DB79FC26647E1DD5B0520FC7529F16
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\AxComponentsVCL.bplbinary
MD5:AD0E779D1C020AEDFA3FAE41DA0FAD86
SHA256:03CFE8893C876EB04C12C885A051BF2DEC44C3F41AA4C89AAD74416EE466255C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
26
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.164:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6740
Installer.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAjRTyq9jK2%2FExQ7JxznzLE%3D
unknown
whitelisted
6740
Installer.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D
unknown
whitelisted
6740
Installer.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
whitelisted
6740
Installer.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQD3gdqA6Jg5hrTz8KU5%2Blzk
unknown
whitelisted
2772
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2772
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6740
Installer.exe
POST
200
172.217.18.14:80
http://www.google-analytics.com/collect
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.164:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6740
Installer.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6740
Installer.exe
45.33.97.245:443
outbyte.com
Linode, LLC
US
suspicious
6740
Installer.exe
104.18.38.233:80
ocsp.usertrust.com
CLOUDFLARENET
whitelisted
6544
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.48.23.164
  • 23.48.23.156
  • 23.48.23.173
  • 23.48.23.180
  • 23.48.23.143
  • 23.48.23.145
  • 23.48.23.194
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
outbyte.com
  • 45.33.97.245
unknown
ocsp.usertrust.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.76
  • 20.190.160.14
  • 20.190.160.65
  • 20.190.160.20
  • 20.190.160.22
  • 20.190.160.5
  • 20.190.160.64
whitelisted

Threats

No threats detected
No debug info