File name:

Recorder-devices-setup.exe

Full analysis: https://app.any.run/tasks/7be9048a-bf68-4f09-ad51-548b6b0d35b8
Verdict: Malicious activity
Analysis date: February 03, 2025, 11:25:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

E60D5BE585291AA13004AF0805C408A4

SHA1:

600881A9999D7175B317337E01443510F338388B

SHA256:

3DDE888ACD5CEA13B008C7916BF9DDC9219D9DE93D3D39789FE68CDA31AC1A8D

SSDEEP:

49152:Rdixrq3Bdwrl6BqiTashKpTxKlXZvUBZFVQTRL6WjpC34wG0nrhOJ1xGY2BKh012:mrq3BdwmhT5opTaUD/Ql6Wjc4nrxGY2O

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Setup.exe (PID: 7040)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Recorder-devices-setup.tmp (PID: 6444)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Recorder-devices-setup.exe (PID: 6220)
      • vcredist2010_x64.exe (PID: 6984)
      • Recorder-devices-setup.exe (PID: 6424)
      • Recorder-devices-setup.tmp (PID: 6444)
    • Process drops legitimate windows executable

      • Recorder-devices-setup.tmp (PID: 6444)
      • vcredist2010_x64.exe (PID: 6984)
      • msiexec.exe (PID: 7124)
    • Reads security settings of Internet Explorer

      • Recorder-devices-setup.tmp (PID: 6244)
      • Recorder-devices-setup.tmp (PID: 6444)
      • Setup.exe (PID: 7040)
    • Starts a Microsoft application from unusual location

      • vcredist2010_x64.exe (PID: 6984)
    • Creates file in the systems drive root

      • vcredist2010_x64.exe (PID: 6984)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 7040)
      • msiexec.exe (PID: 7124)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7124)
      • Recorder-devices-setup.tmp (PID: 6444)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 7124)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 4520)
      • regsvr32.exe (PID: 2600)
  • INFO

    • Checks supported languages

      • Recorder-devices-setup.exe (PID: 6220)
      • Recorder-devices-setup.tmp (PID: 6244)
      • Recorder-devices-setup.exe (PID: 6424)
      • vcredist2010_x64.exe (PID: 6984)
      • Setup.exe (PID: 7040)
      • msiexec.exe (PID: 7124)
      • Recorder-devices-setup.tmp (PID: 6444)
    • Create files in a temporary directory

      • Recorder-devices-setup.exe (PID: 6220)
      • Recorder-devices-setup.tmp (PID: 6444)
      • Setup.exe (PID: 7040)
      • Recorder-devices-setup.exe (PID: 6424)
    • Checks proxy server information

      • Recorder-devices-setup.tmp (PID: 6444)
    • Reads the software policy settings

      • Recorder-devices-setup.tmp (PID: 6444)
      • Setup.exe (PID: 7040)
      • msiexec.exe (PID: 7124)
    • The sample compiled with english language support

      • Recorder-devices-setup.tmp (PID: 6444)
      • vcredist2010_x64.exe (PID: 6984)
      • msiexec.exe (PID: 7124)
    • Process checks computer location settings

      • Recorder-devices-setup.tmp (PID: 6244)
      • Recorder-devices-setup.tmp (PID: 6444)
    • Reads the computer name

      • Recorder-devices-setup.tmp (PID: 6244)
      • Recorder-devices-setup.exe (PID: 6424)
      • vcredist2010_x64.exe (PID: 6984)
      • Setup.exe (PID: 7040)
      • msiexec.exe (PID: 7124)
      • Recorder-devices-setup.tmp (PID: 6444)
    • Reads the machine GUID from the registry

      • vcredist2010_x64.exe (PID: 6984)
      • Setup.exe (PID: 7040)
      • msiexec.exe (PID: 7124)
    • Detects InnoSetup installer (YARA)

      • Recorder-devices-setup.exe (PID: 6220)
      • Recorder-devices-setup.tmp (PID: 6244)
      • Recorder-devices-setup.exe (PID: 6424)
      • Recorder-devices-setup.tmp (PID: 6444)
    • The sample compiled with japanese language support

      • vcredist2010_x64.exe (PID: 6984)
      • msiexec.exe (PID: 7124)
    • The sample compiled with chinese language support

      • vcredist2010_x64.exe (PID: 6984)
      • msiexec.exe (PID: 7124)
    • Compiled with Borland Delphi (YARA)

      • Recorder-devices-setup.exe (PID: 6220)
      • Recorder-devices-setup.tmp (PID: 6244)
      • Recorder-devices-setup.exe (PID: 6424)
      • Recorder-devices-setup.tmp (PID: 6444)
    • The sample compiled with korean language support

      • vcredist2010_x64.exe (PID: 6984)
      • msiexec.exe (PID: 7124)
    • The sample compiled with french language support

      • vcredist2010_x64.exe (PID: 6984)
      • msiexec.exe (PID: 7124)
    • The sample compiled with Italian language support

      • vcredist2010_x64.exe (PID: 6984)
      • msiexec.exe (PID: 7124)
    • The sample compiled with german language support

      • vcredist2010_x64.exe (PID: 6984)
      • msiexec.exe (PID: 7124)
    • The sample compiled with russian language support

      • vcredist2010_x64.exe (PID: 6984)
      • msiexec.exe (PID: 7124)
    • The sample compiled with spanish language support

      • vcredist2010_x64.exe (PID: 6984)
      • msiexec.exe (PID: 7124)
    • Reads CPU info

      • Setup.exe (PID: 7040)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 7124)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7124)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 7124)
    • Creates files in the program directory

      • Recorder-devices-setup.tmp (PID: 6444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:12 07:26:53+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 685056
InitializedDataSize: 159744
UninitializedDataSize: -
EntryPoint: 0xa83bc
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Recorder Devices for ShareX Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Recorder Devices for ShareX
ProductVersion: 0.12.10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
9
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start recorder-devices-setup.exe recorder-devices-setup.tmp no specs recorder-devices-setup.exe recorder-devices-setup.tmp vcredist2010_x64.exe setup.exe msiexec.exe regsvr32.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2600"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Recorder Devices for ShareX\virtual-audio-capturer-x64.dll"C:\Windows\System32\regsvr32.exeRecorder-devices-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4520"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Recorder Devices for ShareX\screen-capture-recorder-x64.dll"C:\Windows\System32\regsvr32.exeRecorder-devices-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6220"C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Recorder Devices for ShareX Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\recorder-devices-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
6244"C:\Users\admin\AppData\Local\Temp\is-704VD.tmp\Recorder-devices-setup.tmp" /SL5="$502D2,913971,845824,C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" C:\Users\admin\AppData\Local\Temp\is-704VD.tmp\Recorder-devices-setup.tmpRecorder-devices-setup.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-704vd.tmp\recorder-devices-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
6424"C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" /SPAWNWND=$502A6 /NOTIFYWND=$502D2 C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe
Recorder-devices-setup.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Recorder Devices for ShareX Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\recorder-devices-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
6444"C:\Users\admin\AppData\Local\Temp\is-8CTUC.tmp\Recorder-devices-setup.tmp" /SL5="$C022A,913971,845824,C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" /SPAWNWND=$502A6 /NOTIFYWND=$502D2 C:\Users\admin\AppData\Local\Temp\is-8CTUC.tmp\Recorder-devices-setup.tmp
Recorder-devices-setup.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-8ctuc.tmp\recorder-devices-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
6984"C:\Users\admin\AppData\Local\Temp\is-6LCEG.tmp\vcredist2010_x64.exe" /passive /norestartC:\Users\admin\AppData\Local\Temp\is-6LCEG.tmp\vcredist2010_x64.exe
Recorder-devices-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2010 x64 Redistributable Setup
Exit code:
0
Version:
10.0.40219.325
Modules
Images
c:\users\admin\appdata\local\temp\is-6lceg.tmp\vcredist2010_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
7040c:\a930e76cfc4a0191e0fe\Setup.exe /passive /norestartC:\a930e76cfc4a0191e0fe\Setup.exe
vcredist2010_x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Setup Installer
Exit code:
0
Version:
10.0.40219.325 built by: SP1LDR
Modules
Images
c:\a930e76cfc4a0191e0fe\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7124C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
9 505
Read events
8 982
Write events
500
Delete events
23

Modification events

(PID) Process:(7124) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
D41B000083B9A3642E76DB01
(PID) Process:(7124) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
38AF63E8BB3F6E81A00AC47A3026A710BB1313E260FDFF3C799078EBC1300039
(PID) Process:(7124) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(7124) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:c:\Config.Msi\
Value:
(PID) Process:(7124) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:c:\Config.Msi\13aef3.rbs
Value:
31159854
(PID) Process:(7124) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:c:\Config.Msi\13aef3.rbsLow
Value:
(PID) Process:(7124) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\94422102FB8324F41B3E7CD7B422BDC7
Operation:writeName:1926E8D15D0BCE53481466615F760A7F
Value:
c:\?Program Files\Common Files\Microsoft Shared\VC\msdia100.dll
(PID) Process:(7124) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:c:\WINDOWS\system32\atl100.dll
Value:
1
(PID) Process:(7124) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CC55BAE45466EF63487E80325EFD4699
Operation:writeName:1926E8D15D0BCE53481466615F760A7F
Value:
c:\?WINDOWS\system32\atl100.dll
(PID) Process:(7124) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:c:\WINDOWS\system32\msvcr100.dll
Value:
2
Executable files
63
Suspicious files
22
Text files
48
Unknown types
0

Dropped files

PID
Process
Filename
Type
6220Recorder-devices-setup.exeC:\Users\admin\AppData\Local\Temp\is-704VD.tmp\Recorder-devices-setup.tmpexecutable
MD5:28E188F4933524C61E7EC0820FD6F08D
SHA256:63085FBBA5AE8304907A93B904DF80F226966F94B46CFC3F558EE3B0AE2B16BD
6444Recorder-devices-setup.tmpC:\Users\admin\AppData\Local\Temp\is-6LCEG.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6444Recorder-devices-setup.tmpC:\Users\admin\AppData\Local\Temp\is-6LCEG.tmp\is-R3VM7.tmpexecutable
MD5:02A945866CD1B13E2375C024F0E18301
SHA256:F3B7A76D84D23F91957AA18456A14B4E90609E4CE8194C5653384ED38DADA6F3
6984vcredist2010_x64.exeC:\a930e76cfc4a0191e0fe\SetupEngine.dllexecutable
MD5:63E7901D4FA7AC7766076720272060D0
SHA256:A5116CCB17B242713E5645C2374ABF5827C0D2752B31553E3540C9123812E952
6424Recorder-devices-setup.exeC:\Users\admin\AppData\Local\Temp\is-8CTUC.tmp\Recorder-devices-setup.tmpexecutable
MD5:28E188F4933524C61E7EC0820FD6F08D
SHA256:63085FBBA5AE8304907A93B904DF80F226966F94B46CFC3F558EE3B0AE2B16BD
6984vcredist2010_x64.exeC:\a930e76cfc4a0191e0fe\Setup.exeexecutable
MD5:2AF2C1A78542975B12282ACA4300D515
SHA256:531EB45798728CB741043B28B8C1A4F75536DC75F92D100F55F9109D2D63F0D7
6984vcredist2010_x64.exeC:\a930e76cfc4a0191e0fe\sqmapi.dllexecutable
MD5:3F0363B40376047EFF6A9B97D633B750
SHA256:BD6395A58F55A8B1F4063E813CE7438F695B9B086BB965D8AC44E7A97D35A93C
6984vcredist2010_x64.exeC:\a930e76cfc4a0191e0fe\DHtmlHeader.htmlhtml
MD5:CD131D41791A543CC6F6ED1EA5BD257C
SHA256:E139AF8858FE90127095AC1C4685BCD849437EF0DF7C416033554703F5D864BB
6984vcredist2010_x64.exeC:\a930e76cfc4a0191e0fe\watermark.bmpimage
MD5:1A5CAAFACFC8C7766E404D019249CF67
SHA256:2E87D5742413254DB10F7BD0762B6CDB98FF9C46CA9ACDDFD9B1C2E5418638F2
6984vcredist2010_x64.exeC:\a930e76cfc4a0191e0fe\UiInfo.xmlxml
MD5:4F90FCEF3836F5FC49426AD9938A1C60
SHA256:66A0299CE7EE12DD9FC2CFEAD3C3211E59BFB54D6C0627D044D44CEF6E70367B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
40
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7124
msiexec.exe
GET
200
2.16.164.97:80
http://crl.microsoft.com/pki/crl/products/CSPCA.crl
unknown
whitelisted
5472
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4392
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4392
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.147:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
104.126.37.154:443
www.bing.com
Akamai International B.V.
DE
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.147:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
40.126.31.3:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
6444
Recorder-devices-setup.tmp
23.32.101.194:443
download.microsoft.com
AKAMAI-AS
SE
whitelisted
7124
msiexec.exe
2.16.164.97:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 104.126.37.154
  • 104.126.37.144
  • 104.126.37.155
  • 104.126.37.153
  • 104.126.37.152
  • 104.126.37.146
  • 104.126.37.161
  • 104.126.37.160
  • 104.126.37.145
  • 2.21.65.157
  • 2.21.65.132
  • 2.21.65.154
  • 2.21.65.153
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 2.23.77.188
whitelisted
crl.microsoft.com
  • 23.48.23.147
  • 23.48.23.176
  • 23.48.23.166
  • 23.48.23.143
  • 2.16.164.97
  • 2.16.164.120
  • 2.16.164.99
  • 2.16.164.43
  • 2.16.164.81
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
login.live.com
  • 40.126.31.3
  • 40.126.31.1
  • 40.126.31.128
  • 20.190.159.129
  • 40.126.31.0
  • 20.190.159.0
  • 20.190.159.64
  • 40.126.31.69
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
download.microsoft.com
  • 23.32.101.194
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
Process
Message
Setup.exe
The operation completed successfully.