File name:

Recorder-devices-setup.exe

Full analysis: https://app.any.run/tasks/255485d3-48be-4766-98f2-56e58070c65e
Verdict: Malicious activity
Analysis date: January 18, 2025, 14:07:00
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
delphi
inno
installer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

E60D5BE585291AA13004AF0805C408A4

SHA1:

600881A9999D7175B317337E01443510F338388B

SHA256:

3DDE888ACD5CEA13B008C7916BF9DDC9219D9DE93D3D39789FE68CDA31AC1A8D

SSDEEP:

49152:Rdixrq3Bdwrl6BqiTashKpTxKlXZvUBZFVQTRL6WjpC34wG0nrhOJ1xGY2BKh012:mrq3BdwmhT5opTaUD/Ql6Wjc4nrxGY2O

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Setup.exe (PID: 3640)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Recorder-devices-setup.tmp (PID: 6588)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Recorder-devices-setup.exe (PID: 6324)
      • Recorder-devices-setup.exe (PID: 6564)
      • Recorder-devices-setup.tmp (PID: 6588)
      • vcredist2010_x64.exe (PID: 6448)
    • Reads security settings of Internet Explorer

      • Recorder-devices-setup.tmp (PID: 6344)
      • Recorder-devices-setup.tmp (PID: 6588)
      • Setup.exe (PID: 3640)
    • Reads the Windows owner or organization settings

      • Recorder-devices-setup.tmp (PID: 6588)
      • msiexec.exe (PID: 3736)
    • Process drops legitimate windows executable

      • Recorder-devices-setup.tmp (PID: 6588)
      • vcredist2010_x64.exe (PID: 6448)
      • msiexec.exe (PID: 3736)
    • Starts a Microsoft application from unusual location

      • vcredist2010_x64.exe (PID: 6448)
    • Creates file in the systems drive root

      • vcredist2010_x64.exe (PID: 6448)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 3640)
      • msiexec.exe (PID: 3736)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 3736)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3796)
      • regsvr32.exe (PID: 5244)
  • INFO

    • Reads the computer name

      • Recorder-devices-setup.tmp (PID: 6344)
      • Recorder-devices-setup.exe (PID: 6564)
      • Recorder-devices-setup.tmp (PID: 6588)
      • vcredist2010_x64.exe (PID: 6448)
      • Setup.exe (PID: 3640)
      • msiexec.exe (PID: 3736)
    • Checks supported languages

      • Recorder-devices-setup.exe (PID: 6324)
      • Recorder-devices-setup.tmp (PID: 6344)
      • Recorder-devices-setup.exe (PID: 6564)
      • Recorder-devices-setup.tmp (PID: 6588)
      • vcredist2010_x64.exe (PID: 6448)
      • Setup.exe (PID: 3640)
      • msiexec.exe (PID: 3736)
    • Process checks computer location settings

      • Recorder-devices-setup.tmp (PID: 6344)
      • Recorder-devices-setup.tmp (PID: 6588)
    • Create files in a temporary directory

      • Recorder-devices-setup.exe (PID: 6564)
      • Recorder-devices-setup.exe (PID: 6324)
      • Recorder-devices-setup.tmp (PID: 6588)
      • Setup.exe (PID: 3640)
    • has been detected (YARA)

      • Recorder-devices-setup.exe (PID: 6324)
      • Recorder-devices-setup.tmp (PID: 6344)
      • Recorder-devices-setup.tmp (PID: 6588)
      • Recorder-devices-setup.exe (PID: 6564)
    • Compiled with Borland Delphi (YARA)

      • Recorder-devices-setup.exe (PID: 6324)
      • Recorder-devices-setup.tmp (PID: 6344)
      • Recorder-devices-setup.tmp (PID: 6588)
      • Recorder-devices-setup.exe (PID: 6564)
    • Checks proxy server information

      • Recorder-devices-setup.tmp (PID: 6588)
    • Reads the software policy settings

      • Recorder-devices-setup.tmp (PID: 6588)
      • Setup.exe (PID: 3640)
      • msiexec.exe (PID: 3736)
    • The process uses the downloaded file

      • Recorder-devices-setup.tmp (PID: 6588)
    • The sample compiled with english language support

      • Recorder-devices-setup.tmp (PID: 6588)
      • vcredist2010_x64.exe (PID: 6448)
      • msiexec.exe (PID: 3736)
    • Reads the machine GUID from the registry

      • vcredist2010_x64.exe (PID: 6448)
      • Setup.exe (PID: 3640)
      • msiexec.exe (PID: 3736)
    • The sample compiled with chinese language support

      • vcredist2010_x64.exe (PID: 6448)
      • msiexec.exe (PID: 3736)
    • The sample compiled with french language support

      • vcredist2010_x64.exe (PID: 6448)
      • msiexec.exe (PID: 3736)
    • The sample compiled with german language support

      • vcredist2010_x64.exe (PID: 6448)
      • msiexec.exe (PID: 3736)
    • The sample compiled with Italian language support

      • vcredist2010_x64.exe (PID: 6448)
      • msiexec.exe (PID: 3736)
    • The sample compiled with spanish language support

      • vcredist2010_x64.exe (PID: 6448)
      • msiexec.exe (PID: 3736)
    • The sample compiled with russian language support

      • vcredist2010_x64.exe (PID: 6448)
      • msiexec.exe (PID: 3736)
    • Reads CPU info

      • Setup.exe (PID: 3640)
    • The sample compiled with japanese language support

      • vcredist2010_x64.exe (PID: 6448)
      • msiexec.exe (PID: 3736)
    • The sample compiled with korean language support

      • vcredist2010_x64.exe (PID: 6448)
      • msiexec.exe (PID: 3736)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3736)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 3736)
    • Creates a software uninstall entry

      • Recorder-devices-setup.tmp (PID: 6588)
      • msiexec.exe (PID: 3736)
    • Sends debugging messages

      • Setup.exe (PID: 3640)
    • Creates files in the program directory

      • Recorder-devices-setup.tmp (PID: 6588)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:12 07:26:53+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 685056
InitializedDataSize: 159744
UninitializedDataSize: -
EntryPoint: 0xa83bc
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Recorder Devices for ShareX Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Recorder Devices for ShareX
ProductVersion: 0.12.10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
9
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start recorder-devices-setup.exe recorder-devices-setup.tmp no specs recorder-devices-setup.exe recorder-devices-setup.tmp vcredist2010_x64.exe setup.exe msiexec.exe regsvr32.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3640c:\70b546a96a771fb11b\Setup.exe /passive /norestartC:\70b546a96a771fb11b\Setup.exe
vcredist2010_x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Setup Installer
Exit code:
0
Version:
10.0.40219.325 built by: SP1LDR
Modules
Images
c:\70b546a96a771fb11b\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
3736C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3796"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Recorder Devices for ShareX\screen-capture-recorder-x64.dll"C:\Windows\System32\regsvr32.exeRecorder-devices-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5244"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Recorder Devices for ShareX\virtual-audio-capturer-x64.dll"C:\Windows\System32\regsvr32.exeRecorder-devices-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6324"C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Recorder Devices for ShareX Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\recorder-devices-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
6344"C:\Users\admin\AppData\Local\Temp\is-EJSIE.tmp\Recorder-devices-setup.tmp" /SL5="$90352,913971,845824,C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" C:\Users\admin\AppData\Local\Temp\is-EJSIE.tmp\Recorder-devices-setup.tmpRecorder-devices-setup.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ejsie.tmp\recorder-devices-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
6448"C:\Users\admin\AppData\Local\Temp\is-2QNP9.tmp\vcredist2010_x64.exe" /passive /norestartC:\Users\admin\AppData\Local\Temp\is-2QNP9.tmp\vcredist2010_x64.exe
Recorder-devices-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2010 x64 Redistributable Setup
Exit code:
0
Version:
10.0.40219.325
Modules
Images
c:\users\admin\appdata\local\temp\is-2qnp9.tmp\vcredist2010_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6564"C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" /SPAWNWND=$5034E /NOTIFYWND=$90352 C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe
Recorder-devices-setup.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Recorder Devices for ShareX Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\recorder-devices-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
6588"C:\Users\admin\AppData\Local\Temp\is-RINQM.tmp\Recorder-devices-setup.tmp" /SL5="$602A0,913971,845824,C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" /SPAWNWND=$5034E /NOTIFYWND=$90352 C:\Users\admin\AppData\Local\Temp\is-RINQM.tmp\Recorder-devices-setup.tmp
Recorder-devices-setup.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rinqm.tmp\recorder-devices-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
Total events
9 560
Read events
9 037
Write events
500
Delete events
23

Modification events

(PID) Process:(3736) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
980E000087E9F155B269DB01
(PID) Process:(3736) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
3406B69B15AE4D7C1383EC0607603093D8C914A5DA9B7A5DD0E3D3542192FE3C
(PID) Process:(3736) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(3736) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0480DC222D01C4F37A2077C032048022
Operation:writeName:1926E8D15D0BCE53481466615F760A7F
Value:
02:\SOFTWARE\Microsoft\VisualStudio\10.0\VC\VCRedist\x64\Version
(PID) Process:(3736) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C065BA555D648923380AAA2171113286
Operation:writeName:1926E8D15D0BCE53481466615F760A7F
Value:
02:\SOFTWARE\Microsoft\DevDiv\vc\Servicing\10.0\red\amd64\1033\Install
(PID) Process:(3736) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:c:\Program Files\Common Files\Microsoft Shared\VC\msdia100.dll
Value:
1
(PID) Process:(3736) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\94422102FB8324F41B3E7CD7B422BDC7
Operation:writeName:1926E8D15D0BCE53481466615F760A7F
Value:
c:\?Program Files\Common Files\Microsoft Shared\VC\msdia100.dll
(PID) Process:(3736) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:c:\WINDOWS\system32\atl100.dll
Value:
1
(PID) Process:(3736) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CC55BAE45466EF63487E80325EFD4699
Operation:writeName:1926E8D15D0BCE53481466615F760A7F
Value:
c:\?WINDOWS\system32\atl100.dll
(PID) Process:(3736) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0B27EEBBB25368A34A89A4C36060B816
Operation:writeName:1926E8D15D0BCE53481466615F760A7F
Value:
c:\?WINDOWS\system32\mfc100kor.dll
Executable files
63
Suspicious files
20
Text files
50
Unknown types
0

Dropped files

PID
Process
Filename
Type
6564Recorder-devices-setup.exeC:\Users\admin\AppData\Local\Temp\is-RINQM.tmp\Recorder-devices-setup.tmpexecutable
MD5:28E188F4933524C61E7EC0820FD6F08D
SHA256:63085FBBA5AE8304907A93B904DF80F226966F94B46CFC3F558EE3B0AE2B16BD
6448vcredist2010_x64.exeC:\70b546a96a771fb11b\DHtmlHeader.htmlhtml
MD5:CD131D41791A543CC6F6ED1EA5BD257C
SHA256:E139AF8858FE90127095AC1C4685BCD849437EF0DF7C416033554703F5D864BB
6448vcredist2010_x64.exeC:\70b546a96a771fb11b\Setup.exeexecutable
MD5:2AF2C1A78542975B12282ACA4300D515
SHA256:531EB45798728CB741043B28B8C1A4F75536DC75F92D100F55F9109D2D63F0D7
6448vcredist2010_x64.exeC:\70b546a96a771fb11b\SetupUi.dllexecutable
MD5:0D214CED87BF0B55883359160A68DACB
SHA256:29CF99D7E67B4C54BAFD109577A385387A39301BCDEC8AE4BA1A8A0044306713
6448vcredist2010_x64.exeC:\70b546a96a771fb11b\UiInfo.xmlxml
MD5:4F90FCEF3836F5FC49426AD9938A1C60
SHA256:66A0299CE7EE12DD9FC2CFEAD3C3211E59BFB54D6C0627D044D44CEF6E70367B
6588Recorder-devices-setup.tmpC:\Users\admin\AppData\Local\Temp\is-2QNP9.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6448vcredist2010_x64.exeC:\70b546a96a771fb11b\DisplayIcon.icoimage
MD5:F9657D290048E169FFABBBB9C7412BE0
SHA256:B74AD253B9B8F9FCADE725336509143828EE739CC2B24782BE3ECFF26F229160
6448vcredist2010_x64.exeC:\70b546a96a771fb11b\header.bmpimage
MD5:3AD1A8C3B96993BCDF45244BE2C00EEF
SHA256:133B86A4F1C67A159167489FDAEAB765BFA1050C23A7AE6D5C517188FB45F94A
6448vcredist2010_x64.exeC:\70b546a96a771fb11b\Strings.xmlxml
MD5:332ADF643747297B9BFA9527EAEFE084
SHA256:E49545FEEAE22198728AD04236E31E02035AF7CC4D68E10CBECFFD08669CBECA
6448vcredist2010_x64.exeC:\70b546a96a771fb11b\1033\LocalizedData.xmlxml
MD5:5486FF60B072102EE3231FD743B290A1
SHA256:5CA3ECAA12CA56F955D403CA93C4CB36A7D3DCDEA779FC9BDAA0CDD429DAB706
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
31
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.164:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4536
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
3736
msiexec.exe
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/CSPCA.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
23.48.23.164:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
104.126.37.145:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
184.30.18.9:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.48.23.164
  • 23.48.23.143
  • 23.48.23.176
  • 23.48.23.156
  • 23.48.23.166
  • 23.48.23.147
  • 23.48.23.173
  • 23.48.23.177
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.186.78
whitelisted
www.bing.com
  • 104.126.37.145
  • 104.126.37.155
  • 104.126.37.144
  • 104.126.37.139
  • 104.126.37.161
  • 104.126.37.154
  • 104.126.37.129
  • 104.126.37.137
  • 104.126.37.128
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
go.microsoft.com
  • 184.30.18.9
whitelisted
login.live.com
  • 40.126.31.69
  • 20.190.159.73
  • 20.190.159.4
  • 20.190.159.71
  • 20.190.159.64
  • 20.190.159.68
  • 40.126.31.73
  • 40.126.31.71
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
download.microsoft.com
  • 2.18.160.223
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted

Threats

No threats detected
Process
Message
Setup.exe
The operation completed successfully.