File name:

Spotify_Premium_For_PC__Spotify.exe

Full analysis: https://app.any.run/tasks/2734cf14-294b-4405-a3a7-fb5de743cb17
Verdict: Malicious activity
Analysis date: January 08, 2025, 16:22:53
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-scr
arch-html
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

226E3B0D49A2252895B30276AE73F411

SHA1:

113D495905F25E40F5DE77085E3E9C358F25B5BB

SHA256:

419E316E8195FF0434FE7C342704B6B4EB75381668578A93578E0A5CE7A4D90B

SSDEEP:

12288:vkoVLFAMPlVrP/fRkH1fveT/9iQjiSPWDIgSn+ch1yH6QBKgPirVYVVVVVSA:9VLFAMPlVjfSVfvenM4+czyaukA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • Checks Windows Trust Settings

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • Process drops legitimate windows executable

      • SpWebInst0.exe (PID: 440)
    • Executable content was dropped or overwritten

      • SpWebInst0.exe (PID: 440)
    • Application launched itself

      • Spotify.exe (PID: 536)
  • INFO

    • Reads the computer name

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
      • SpWebInst0.exe (PID: 440)
    • Reads the software policy settings

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • Checks supported languages

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • Reads the machine GUID from the registry

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • Checks proxy server information

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • The sample compiled with english language support

      • SpWebInst0.exe (PID: 440)
    • Sends debugging messages

      • Spotify.exe (PID: 536)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:02:23 17:48:10+00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.36
CodeSize: 433152
InitializedDataSize: 560640
UninitializedDataSize: -
EntryPoint: 0x3db37
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.2.32.997
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Spotify Ltd
FileDescription: SpotifyInstaller
FileVersion: 0,0,0,0
InternalName: SpotifyInstaller
LegalCopyright: Copyright (c) 2024, Spotify Ltd
OriginalFileName: SpotifyInstaller.exe
ProductName: Spotify
ProductVersion: 1.2.32.997.g4c6498b6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
9
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start spotify_premium_for_pc__spotify.exe spwebinst0.exe spotify.exe spotify.exe no specs spotify.exe no specs spotify.exe spotify.exe no specs spotify.exe no specs spotify.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.53.440" --field-trial-handle=2524,i,7255328140799867212,14114244053258133122,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2544 --mojo-platform-channel-handle=2540 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.53.440
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
440SpWebInst0.exe /webinstallC:\Users\admin\AppData\Roaming\Spotify\SpWebInst0.exe
Spotify_Premium_For_PC__Spotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
SpotifyInstaller
Exit code:
0
Version:
0,0,0,0
Modules
Images
c:\users\admin\appdata\roaming\spotify\spwebinst0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
536Spotify.exeC:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
SpWebInst0.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.53.440
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1140"C:\Users\admin\AppData\Local\Temp\Spotify_Premium_For_PC__Spotify.exe" C:\Users\admin\AppData\Local\Temp\Spotify_Premium_For_PC__Spotify.exe
explorer.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
SpotifyInstaller
Exit code:
0
Version:
0,0,0,0
Modules
Images
c:\users\admin\appdata\local\temp\spotify_premium_for_pc__spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
5308"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=gpu-process --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.53.440" --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=2024,i,7255328140799867212,14114244053258133122,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2040 --mojo-platform-channel-handle=2012 /prefetch:2C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.53.440
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5340C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe --type=crashpad-handler /prefetch:4 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Spotify\User Data\Crashpad" --url=https://crashdump.spotify.com:443/ --annotation=platform=win64 --annotation=product=spotify --annotation=version=1.2.53.440 --initial-client-data=0x3c8,0x3cc,0x3d0,0x3c4,0x3d4,0x7ff821aa8fc8,0x7ff821aa8fd4,0x7ff821aa8fe0C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.53.440
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6068"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.53.440" --field-trial-handle=2184,i,7255328140799867212,14114244053258133122,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2076 --mojo-platform-channel-handle=2316 /prefetch:3C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
Spotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.53.440
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6384"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=renderer --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.53.440" --autoplay-policy=no-user-gesture-required --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=4864,i,7255328140799867212,14114244053258133122,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=4880 --mojo-platform-channel-handle=4876 /prefetch:1C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.53.440
6596"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.53.440" --field-trial-handle=5372,i,7255328140799867212,14114244053258133122,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=5468 --mojo-platform-channel-handle=5284 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Exit code:
0
Version:
1.2.53.440
Total events
4 225
Read events
4 167
Write events
53
Delete events
5

Modification events

(PID) Process:(1140) Spotify_Premium_For_PC__Spotify.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1140) Spotify_Premium_For_PC__Spotify.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1140) Spotify_Premium_For_PC__Spotify.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Spotify Web Helper
Value:
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayName
Value:
Spotify
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayVersion
Value:
1.2.53.440.g7b2f582a
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:Version
Value:
1.2.53.440.g7b2f582a
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallDate
Value:
20250108
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\Spotify
Executable files
13
Suspicious files
145
Text files
36
Unknown types
123

Dropped files

PID
Process
Filename
Type
1140Spotify_Premium_For_PC__Spotify.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\SpotifyFullSetupX64[1].exe
MD5:
SHA256:
1140Spotify_Premium_For_PC__Spotify.exeC:\Users\admin\AppData\Roaming\Spotify\SpWebInst0.exe
MD5:
SHA256:
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_2_~compressed
MD5:D6A4C897CC1976B5AF454E18CFC85531
SHA256:AC39AFEA74CFA667615B4CC9B8082CEAD9A9F7D50CED52A150F2475ADCE0D9AF
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_6_~binary
MD5:19BAD258DDF5B876DEABB708810093E6
SHA256:B78C9110523A405EEDC5C693C5D1E0422F3AE1FB5BB312A3F518AD8C7645F8DE
1140Spotify_Premium_For_PC__Spotify.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_4D90A79F4986A67200F4F4B3378FFAD0binary
MD5:A21FD624259896355FBD552A559CDF09
SHA256:DE85D912391CB9DE2F0A84146F6B1BDB6E4CB37A38EFEF5B1280596DDC5E850C
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_8_~binary
MD5:B6A2ADFC87A19D6B33EE14009C962C61
SHA256:90E80D6A90D5E5A5481452AAA46A39BDF4D8E33BC34C5BB34EC3B2B0AEAC34D8
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_0_~compressed
MD5:23DCF6CA3AF295CD12CFD14CE7FFC6BB
SHA256:4B334C2A786A13D0B4040641166871A7FE8A656CB5C827FA5355E446AFC57DDF
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_16_~gmo
MD5:1CA307AE3A4BEF36F49AEFF37A3FD2CC
SHA256:4D498B2FD63284D6980E8EBF0289649E5F04632181DDA1D4CD476DA47CD4E2AC
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_4_~binary
MD5:F15E210848C6D8C6C51FA4FFA36B954D
SHA256:8B3DB0C5CD4653373AB1772FD1D9879D3345C480D1B9F4D0499FA01AE5ACFD8E
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_14_~binary
MD5:8D2FDBE926FCBF8F7C5A987B94C8D11C
SHA256:6DE3388963D2092E6E2C6105C62A44730E4553393B9FF8F227CF6A8DCFFBBD7E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
45
DNS requests
45
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.113:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.113:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1140
Spotify_Premium_For_PC__Spotify.exe
GET
200
151.101.194.133:80
http://ocsp2.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEH%2B2oOpV4owETJUuldY0n1w%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5488
SIHClient.exe
GET
200
23.209.210.103:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5488
SIHClient.exe
GET
200
23.209.210.103:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3420
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
244
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.113:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.113:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
1140
Spotify_Premium_For_PC__Spotify.exe
199.232.210.248:443
download.scdn.co
FASTLY
US
whitelisted
3976
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1140
Spotify_Premium_For_PC__Spotify.exe
151.101.194.133:80
ocsp2.globalsign.com
FASTLY
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted
crl.microsoft.com
  • 2.16.164.113
  • 2.16.164.112
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.209.210.103
whitelisted
download.scdn.co
  • 199.232.210.248
  • 199.232.214.248
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
ocsp2.globalsign.com
  • 151.101.194.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.2.133
whitelisted
www.bing.com
  • 2.23.227.221
  • 2.23.227.208
  • 2.23.227.215
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.160.17
  • 40.126.32.134
  • 40.126.32.136
  • 40.126.32.138
  • 40.126.32.68
  • 40.126.32.140
  • 40.126.32.76
  • 20.190.160.22
whitelisted
go.microsoft.com
  • 23.56.254.14
whitelisted

Threats

No threats detected
Process
Message
Spotify.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local directory exists )