File name:

winmm.dll

Full analysis: https://app.any.run/tasks/10ae2235-661e-4c42-87c1-54fd8be5999c
Verdict: Malicious activity
Analysis date: March 27, 2026, 04:25:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (DLL) (GUI) x86-64, for MS Windows, 7 sections
MD5:

887982EA1E9CC92933302C286B86194C

SHA1:

84D984421F06B662D40F504F47B8C95FC7F03EF2

SHA256:

3F7688D827D336C3B7332206322AFD9CB03C62714D2751BFC9DA705CFEE1CC37

SSDEEP:

24576:i9GwIsMdu7kOtc9o0FYnznXgNtmRTUbxZGVCLkuJldfdyKWSLI:i9GwcY7kOtc97FYnznXgNtmRTUbxZGVX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • WerFault.exe (PID: 7188)
      • WerFault.exe (PID: 2652)
      • WerFault.exe (PID: 7160)
      • WerFault.exe (PID: 6864)
      • WerFault.exe (PID: 2812)
      • WerFault.exe (PID: 4308)
      • WerFault.exe (PID: 1312)
      • WerFault.exe (PID: 4340)
      • WerFault.exe (PID: 352)
      • WerFault.exe (PID: 7892)
      • WerFault.exe (PID: 7896)
      • WerFault.exe (PID: 1032)
      • WerFault.exe (PID: 5264)
      • WerFault.exe (PID: 3036)
      • WerFault.exe (PID: 7664)
      • WerFault.exe (PID: 4304)
      • WerFault.exe (PID: 1824)
      • WerFault.exe (PID: 4324)
      • WerFault.exe (PID: 7340)
      • WerFault.exe (PID: 3420)
      • WerFault.exe (PID: 6108)
      • WerFault.exe (PID: 3136)
      • WerFault.exe (PID: 5448)
      • WerFault.exe (PID: 7200)
      • WerFault.exe (PID: 5632)
      • WerFault.exe (PID: 2528)
      • WerFault.exe (PID: 2680)
      • WerFault.exe (PID: 204)
      • WerFault.exe (PID: 5304)
      • WerFault.exe (PID: 4328)
      • WerFault.exe (PID: 6508)
      • WerFault.exe (PID: 7760)
      • WerFault.exe (PID: 7336)
      • WerFault.exe (PID: 2940)
      • WerFault.exe (PID: 7752)
      • WerFault.exe (PID: 6180)
      • WerFault.exe (PID: 5884)
      • WerFault.exe (PID: 8100)
      • WerFault.exe (PID: 6432)
      • WerFault.exe (PID: 7176)
      • WerFault.exe (PID: 2528)
      • WerFault.exe (PID: 2680)
      • WerFault.exe (PID: 5708)
      • WerFault.exe (PID: 7764)
      • WerFault.exe (PID: 2032)
      • WerFault.exe (PID: 6504)
      • WerFault.exe (PID: 4212)
      • WerFault.exe (PID: 7892)
      • WerFault.exe (PID: 868)
      • WerFault.exe (PID: 7888)
      • WerFault.exe (PID: 3084)
      • WerFault.exe (PID: 2000)
      • WerFault.exe (PID: 7324)
      • WerFault.exe (PID: 7680)
      • WerFault.exe (PID: 5448)
      • WerFault.exe (PID: 2524)
      • WerFault.exe (PID: 6672)
      • WerFault.exe (PID: 7660)
      • WerFault.exe (PID: 6872)
      • WerFault.exe (PID: 6024)
      • WerFault.exe (PID: 7780)
      • WerFault.exe (PID: 6076)
      • WerFault.exe (PID: 7760)
      • WerFault.exe (PID: 7668)
      • WerFault.exe (PID: 4872)
    • Runs a DLL function by ordinal number

      • rundll32.exe (PID: 8008)
  • INFO

    • The sample compiled with english language support

      • rundll32.exe (PID: 8008)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 2652)
      • WerFault.exe (PID: 7188)
      • WerFault.exe (PID: 4308)
      • WerFault.exe (PID: 7160)
      • WerFault.exe (PID: 1312)
      • WerFault.exe (PID: 6864)
      • WerFault.exe (PID: 4340)
      • WerFault.exe (PID: 2812)
      • WerFault.exe (PID: 352)
      • WerFault.exe (PID: 1032)
      • WerFault.exe (PID: 7892)
      • WerFault.exe (PID: 7896)
      • WerFault.exe (PID: 3036)
      • WerFault.exe (PID: 5264)
      • WerFault.exe (PID: 7664)
      • WerFault.exe (PID: 1824)
      • WerFault.exe (PID: 4324)
      • WerFault.exe (PID: 7340)
      • WerFault.exe (PID: 4304)
      • WerFault.exe (PID: 204)
      • WerFault.exe (PID: 5304)
      • WerFault.exe (PID: 3420)
      • WerFault.exe (PID: 3136)
      • WerFault.exe (PID: 6108)
      • WerFault.exe (PID: 7200)
      • WerFault.exe (PID: 5632)
      • WerFault.exe (PID: 5448)
      • WerFault.exe (PID: 2528)
      • WerFault.exe (PID: 2680)
      • WerFault.exe (PID: 4328)
      • WerFault.exe (PID: 6508)
      • WerFault.exe (PID: 7760)
      • WerFault.exe (PID: 7336)
      • WerFault.exe (PID: 2940)
      • WerFault.exe (PID: 7752)
      • WerFault.exe (PID: 6180)
      • WerFault.exe (PID: 5884)
      • WerFault.exe (PID: 8100)
      • WerFault.exe (PID: 6432)
      • WerFault.exe (PID: 7176)
      • WerFault.exe (PID: 868)
      • WerFault.exe (PID: 2528)
      • WerFault.exe (PID: 5708)
      • WerFault.exe (PID: 2680)
      • WerFault.exe (PID: 6504)
      • WerFault.exe (PID: 7764)
      • WerFault.exe (PID: 2032)
      • WerFault.exe (PID: 4212)
      • WerFault.exe (PID: 7892)
      • WerFault.exe (PID: 7888)
      • WerFault.exe (PID: 3084)
      • WerFault.exe (PID: 2000)
      • WerFault.exe (PID: 7324)
      • WerFault.exe (PID: 7680)
      • WerFault.exe (PID: 5448)
      • WerFault.exe (PID: 2524)
      • WerFault.exe (PID: 6672)
      • WerFault.exe (PID: 7660)
      • WerFault.exe (PID: 6872)
      • WerFault.exe (PID: 6024)
      • WerFault.exe (PID: 7760)
      • WerFault.exe (PID: 7780)
      • WerFault.exe (PID: 6076)
      • WerFault.exe (PID: 7668)
      • WerFault.exe (PID: 4872)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2026:03:18 10:59:21+00:00
ImageFileCharacteristics: Executable, Large address aware, DLL
PEType: PE32+
LinkerVersion: 14.44
CodeSize: 398336
InitializedDataSize: 641536
UninitializedDataSize: -
EntryPoint: 0x41700
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.1.0.0
ProductVersionNumber: 1.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: RUNE
FileDescription: PlayStation PC SDK Emulator
FileVersion: 1.1.0.0
LegalCopyright: Copyright (c) 2o25-2o26
ProductName: PlayStation PC SDK Emulator
ProductVersion: 1.1.0.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
266
Monitored processes
67
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rundll32.exe werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
204C:\WINDOWS\system32\WerFault.exe -u -p 8008 -s 12C:\Windows\System32\WerFault.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
352C:\WINDOWS\system32\WerFault.exe -u -p 8008 -s 312C:\Windows\System32\WerFault.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
868C:\WINDOWS\system32\WerFault.exe -u -p 8008 -s 376C:\Windows\System32\WerFault.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
1032C:\WINDOWS\system32\WerFault.exe -u -p 8008 -s 320C:\Windows\System32\WerFault.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\oleaut32.dll
1312C:\WINDOWS\system32\WerFault.exe -u -p 8008 -s 316C:\Windows\System32\WerFault.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\oleaut32.dll
1824C:\WINDOWS\system32\WerFault.exe -u -p 8008 -s 288C:\Windows\System32\WerFault.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
2000C:\WINDOWS\system32\WerFault.exe -u -p 8008 -s 284C:\Windows\System32\WerFault.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
2032C:\WINDOWS\system32\WerFault.exe -u -p 8008 -s 324C:\Windows\System32\WerFault.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
2524C:\WINDOWS\system32\WerFault.exe -u -p 8008 -s 284C:\Windows\System32\WerFault.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
2528C:\WINDOWS\system32\WerFault.exe -u -p 8008 -s 296C:\Windows\System32\WerFault.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
Total events
114 796
Read events
114 796
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
131
Text files
130
Unknown types
0

Dropped files

PID
Process
Filename
Type
7188WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_win_a08f7ff9908d572749355eff26e533ac556b38_5e487f1f_ae92a790-53bb-4186-bf4d-249b1f2d1c30\Report.wer
MD5:
SHA256:
2652WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_win_a0f7a1644b508229c74795250784ea7aafc3b74_5e487f1f_a49ac6db-a924-46b6-8dff-a69e99baf5fb\Report.wer
MD5:
SHA256:
7160WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_win_a0f7a1644b508229c74795250784ea7aafc3b74_5e487f1f_7a5db52f-c159-4411-9b69-7df3b671c268\Report.wer
MD5:
SHA256:
4308WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_win_a0f7a1644b508229c74795250784ea7aafc3b74_5e487f1f_8093d94c-63ec-4e6a-93fd-84d3cecb5861\Report.wer
MD5:
SHA256:
6864WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_win_a0f7a1644b508229c74795250784ea7aafc3b74_5e487f1f_d9a3e3f3-542d-4a86-9c77-3d8b406fde42\Report.wer
MD5:
SHA256:
7188WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\rundll32.exe.8008.dmpbinary
MD5:5F5EBB502C7EF373072439FC22EC2A7F
SHA256:7602E7AE753BCD9F51A54836F5C82BB0B0C7490D5A340F48D0EAEC3B5397F1BF
7160WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER933.tmp.dmpbinary
MD5:0C99C876D53842DAE12E6067C888BE05
SHA256:E547C3EC370323D39D7F028EC416491CE1E4019EF57D5717E0263A294EDDD24D
7160WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER992.tmp.WERInternalMetadata.xmlxml
MD5:E23B85859C8ABBAB128908BBFEF4694D
SHA256:63CDCA22A2AA6153B9A4CD6631E35C72E6ED3BFD21ACBC7E3357A13D7C5FD9E6
2652WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\rundll32.exe(1).8008.dmpbinary
MD5:13122F8375BC2881E31DBCB25346F4E7
SHA256:03C26A88C9137814C8C906189AAA57E887AD56F19AD580FF41135C4087EE536F
2812WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_win_a0f7a1644b508229c74795250784ea7aafc3b74_5e487f1f_f9e24dbf-6639-448d-8596-e4aa2415375a\Report.wer
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
24
DNS requests
19
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
6628
SIHClient.exe
GET
304
135.232.92.137:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
3616
svchost.exe
POST
200
135.233.45.223:443
https://watson.events.data.microsoft.com/Telemetry.Request
US
xml
968 b
whitelisted
5316
svchost.exe
POST
400
20.190.160.5:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
6628
SIHClient.exe
GET
200
135.232.92.97:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
6628
SIHClient.exe
GET
200
135.232.92.137:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
6628
SIHClient.exe
GET
304
135.232.92.137:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5316
svchost.exe
POST
200
20.190.160.5:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
5316
svchost.exe
POST
400
20.190.160.5:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
680
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
128.24.231.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3616
svchost.exe
135.233.45.223:443
watson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3616
svchost.exe
23.216.77.6:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
3616
svchost.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
3428
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
20.190.160.5:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
activation-v2.sls.microsoft.com
  • 128.24.231.65
whitelisted
google.com
  • 142.251.141.110
whitelisted
watson.events.data.microsoft.com
  • 135.233.45.223
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.160.5
  • 40.126.32.133
  • 40.126.32.72
  • 20.190.160.128
  • 40.126.32.140
  • 20.190.160.66
  • 40.126.32.134
  • 40.126.32.68
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
slscr.update.microsoft.com
  • 135.232.92.137
whitelisted

Threats

PID
Process
Class
Message
3616
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info