File name:

windows-outbyte-driver-updater.exe

Full analysis: https://app.any.run/tasks/64713c27-ff5c-4099-9c17-7d0d11875282
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: May 17, 2025, 19:48:18
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

3A186EA09647B472D3425378935A04B3

SHA1:

1F9202698CA21133898F6B3972AC5BFD29127F99

SHA256:

3C3204CE0DAA4FD1AF3D4F017FBA57B793651719944C317324B23EF2BB867195

SSDEEP:

393216:0wTacZ3vB5S8VSE+nuUneQztAGnb4fEN:0QDvBM8grDeQp/nlN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • Installer.exe (PID: 6740)
    • Steals credentials from Web Browsers

      • Installer.exe (PID: 6740)
    • Executing a file with an untrusted certificate

      • DriverUpdater.exe (PID: 5452)
      • DriverUpdater.exe (PID: 2064)
      • DriverUpdater.exe (PID: 4164)
      • DriverUpdater.exe (PID: 4212)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
    • Executable content was dropped or overwritten

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
    • Reads the Windows owner or organization settings

      • Installer.exe (PID: 6740)
    • There is functionality for communication over UDP network (YARA)

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 5452)
    • Reads browser cookies

      • Installer.exe (PID: 6740)
    • There is functionality for taking screenshot (YARA)

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 5452)
    • Process drops SQLite DLL files

      • Installer.exe (PID: 6740)
    • Process drops legitimate windows executable

      • Installer.exe (PID: 6740)
    • Creates a software uninstall entry

      • Installer.exe (PID: 6740)
    • Reads the BIOS version

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
  • INFO

    • Checks supported languages

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
      • Installer.exe (PID: 6740)
    • Process checks computer location settings

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
    • The sample compiled with english language support

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
    • Create files in a temporary directory

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
    • Checks proxy server information

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • Installer.exe (PID: 6740)
    • Reads the machine GUID from the registry

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
    • Reads the computer name

      • windows-outbyte-driver-updater.exe (PID: 3304)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
      • Installer.exe (PID: 6740)
    • Reads the software policy settings

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
      • slui.exe (PID: 720)
    • Creates files in the program directory

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 4212)
      • DriverUpdater.exe (PID: 5452)
    • Compiled with Borland Delphi (YARA)

      • Installer.exe (PID: 6740)
      • DriverUpdater.exe (PID: 5452)
    • Manual execution by a user

      • DriverUpdater.exe (PID: 4164)
      • DriverUpdater.exe (PID: 2064)
    • Creates files or folders in the user directory

      • Installer.exe (PID: 6740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (generic) (79.7)
.exe | Win32 Executable (generic) (8.6)
.exe | Win16/32 Executable Delphi generic (3.9)
.exe | Generic Win/DOS Executable (3.8)
.exe | DOS Executable Generic (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:05:26 11:18:03+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 143872
InitializedDataSize: 330240
UninitializedDataSize: -
EntryPoint: 0x24530
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.1.1.60362
ProductVersionNumber: 2.1.1.60362
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Driver Updater
CompanyName: Outbyte
FileDescription: Outbyte Driver Updater Installation File
FileVersion: 2.1.1.60362
LegalCopyright: Copyright © 2016-2020 Outbyte Computing Pty Ltd
OriginalFileName: Outbyte-driver-updater-setup.exe
ProductName: Driver Updater
ProductVersion: 2.x
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
10
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start windows-outbyte-driver-updater.exe sppextcomobj.exe no specs slui.exe installer.exe driverupdater.exe no specs driverupdater.exe no specs slui.exe driverupdater.exe no specs driverupdater.exe windows-outbyte-driver-updater.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
720"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2064"C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exeexplorer.exe
User:
admin
Company:
Outbyte
Integrity Level:
MEDIUM
Description:
Driver Updater
Exit code:
3221226540
Version:
2.1.1.60362
Modules
Images
c:\program files (x86)\outbyte\driver updater\driverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2316C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
3304"C:\Users\admin\AppData\Local\Temp\windows-outbyte-driver-updater.exe" C:\Users\admin\AppData\Local\Temp\windows-outbyte-driver-updater.exe
explorer.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Outbyte Driver Updater Installation File
Exit code:
4343088
Version:
2.1.1.60362
Modules
Images
c:\users\admin\appdata\local\temp\windows-outbyte-driver-updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4164"C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe
explorer.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Driver Updater
Exit code:
0
Version:
2.1.1.60362
Modules
Images
c:\program files (x86)\outbyte\driver updater\driverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4212"C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" /Install /SendInfo /AutoStartC:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exeInstaller.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Driver Updater
Exit code:
0
Version:
2.1.1.60362
Modules
Images
c:\program files (x86)\outbyte\driver updater\driverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
5452"C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" /FromInstaller /AutoScanC:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exeInstaller.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Driver Updater
Exit code:
0
Version:
2.1.1.60362
Modules
Images
c:\program files (x86)\outbyte\driver updater\driverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
5776"C:\Users\admin\AppData\Local\Temp\windows-outbyte-driver-updater.exe" C:\Users\admin\AppData\Local\Temp\windows-outbyte-driver-updater.exeexplorer.exe
User:
admin
Company:
Outbyte
Integrity Level:
MEDIUM
Description:
Outbyte Driver Updater Installation File
Exit code:
3221226540
Version:
2.1.1.60362
Modules
Images
c:\users\admin\appdata\local\temp\windows-outbyte-driver-updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6740"C:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Installer.exe" /spid:3304 /splha:37266240C:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Installer.exe
windows-outbyte-driver-updater.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Installer
Exit code:
0
Version:
2.1.1.60362
Modules
Images
c:\users\admin\appdata\local\temp\is-22291454.tmp\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
6964C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
18 741
Read events
18 686
Write events
52
Delete events
3

Modification events

(PID) Process:(6740) Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{6D484312-C2E8-96B5-2103-43B791F33EFF}\Version
Operation:writeName:Assembly
Value:
6ED89B045A334E85CB0A56B990587F3D6ED89B045A334E85CB0A56B990587F3D88AD8CBB5ED3F66B83A8A2CDF194269C890BB34AEBD806E41A50D3BD9C0B4765219909F09E75DEC0927FF4E8152284CD219909F09E75DEC0927FF4E8152284CD59B5414605BAE21E9735786EB516D3F8DE1283C2AFF9BF99D33ED2740C86BBD2F8157495FE950FA4A01046BB55F00DAD0F20AA1B1ADFE602954529934D03147D
(PID) Process:(6740) Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Outbyte\Driver Updater\2.x\Settings
Operation:writeName:Application.TestsErrorCode
Value:
C:\Users\admin\AppData\Local\Temp\windows-outbyte
(PID) Process:(6740) Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Outbyte\Driver Updater\2.x\Settings
Operation:writeName:GoogleAnalytics.CustomCategory
Value:
2.1.1.60362-null-enu-null-lite
(PID) Process:(6740) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6740) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6740) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3304) windows-outbyte-driver-updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Outbyte\Driver Updater\2.x\Settings
Operation:writeName:General.CustomClientId
Value:
{6C84ADCB-9112-44D9-8384-0CF86D5344A1}
(PID) Process:(3304) windows-outbyte-driver-updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Outbyte\Driver Updater\2.x\Settings
Operation:writeName:General.Tracking.Param_ClientId
Value:
{6C84ADCB-9112-44D9-8384-0CF86D5344A1}
(PID) Process:(3304) windows-outbyte-driver-updater.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3304) windows-outbyte-driver-updater.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
78
Suspicious files
62
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\InstallerUtils.dllexecutable
MD5:7BC5E664892A895D76EECE895C07D257
SHA256:0EC60C93B97DBA679D887051A6F11E08AE8C274EE516362F521E791C1A8D24FC
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\DriverUpdater.exeexecutable
MD5:7209E9DD1C25BAA67058A1C913390D81
SHA256:ADAF8A9270E3A6CB754878F93683AC3132CDE9FF467E138820D159DAF280B096
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\GoogleAnalyticsHelper.dllexecutable
MD5:CDD8115F836C7E333838FFA9F08576E7
SHA256:B72659A19996546B1619ECC5BC9101BCB1AA18247499524F195BD1388F5D5B38
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Lang\deu.lngbinary
MD5:52D79E37360F71F80B92BAD100FFA2EB
SHA256:7498F8B7506483E2714814B354B4C9F9B71D9BA523EE3869606819298CFCE942
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Installer.exebinary
MD5:4E491E8B779BD484734413F4F9B2B740
SHA256:25B7A33585E980A5CF18707E2A1F1299AE5F5AA2D99FAD68D81B50A4AEC733BC
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\AxComponentsVCL.bplbinary
MD5:AD0E779D1C020AEDFA3FAE41DA0FAD86
SHA256:03CFE8893C876EB04C12C885A051BF2DEC44C3F41AA4C89AAD74416EE466255C
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\vcl250.bplexecutable
MD5:56D3550991C210AA818D0606E3D83433
SHA256:17E21138BCEC8E8D0CEAC24A6604FCCDF532503661A746CCFDBDF52AE37E5508
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\AxComponentsRTL.bplexecutable
MD5:06B4F318559B5715C456C02CE750E6CC
SHA256:E22540DF24B78FAE201B3800551AA2105D35BBF1E1D724B2E85561F4A1EB2C0E
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Lang\enu.lngbinary
MD5:8F01D10D50008868021412C80EF44CF6
SHA256:B70C46FAA06EA94D3F9D6334142A6BA4D248696D6BEAA098FCA83ED108108176
3304windows-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-22291454.tmp\Lang\fra.lngbinary
MD5:4777A59A93AC0CA16752C898760A38FB
SHA256:89EA071190DFA64B52D3C8E9019586DC226C84C1782B94480134BCA310003BD7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
26
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6740
Installer.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAjRTyq9jK2%2FExQ7JxznzLE%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.164:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2772
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6740
Installer.exe
POST
200
172.217.18.14:80
http://www.google-analytics.com/collect
unknown
whitelisted
6740
Installer.exe
POST
200
172.217.18.14:80
http://www.google-analytics.com/collect
unknown
whitelisted
6740
Installer.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D
unknown
whitelisted
6740
Installer.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
whitelisted
6740
Installer.exe
POST
200
172.217.18.14:80
http://www.google-analytics.com/collect
unknown
whitelisted
6740
Installer.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQD3gdqA6Jg5hrTz8KU5%2Blzk
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.164:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6740
Installer.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6740
Installer.exe
45.33.97.245:443
outbyte.com
Linode, LLC
US
suspicious
6740
Installer.exe
104.18.38.233:80
ocsp.usertrust.com
CLOUDFLARENET
whitelisted
6544
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.48.23.164
  • 23.48.23.156
  • 23.48.23.173
  • 23.48.23.180
  • 23.48.23.143
  • 23.48.23.145
  • 23.48.23.194
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
outbyte.com
  • 45.33.97.245
unknown
ocsp.usertrust.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.76
  • 20.190.160.14
  • 20.190.160.65
  • 20.190.160.20
  • 20.190.160.22
  • 20.190.160.5
  • 20.190.160.64
whitelisted

Threats

No threats detected
No debug info