File name:

Spotify_Premium_For_PC__Spotify.exe

Full analysis: https://app.any.run/tasks/2734cf14-294b-4405-a3a7-fb5de743cb17
Verdict: Malicious activity
Analysis date: January 08, 2025, 16:22:53
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-scr
arch-html
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

226E3B0D49A2252895B30276AE73F411

SHA1:

113D495905F25E40F5DE77085E3E9C358F25B5BB

SHA256:

419E316E8195FF0434FE7C342704B6B4EB75381668578A93578E0A5CE7A4D90B

SSDEEP:

12288:vkoVLFAMPlVrP/fRkH1fveT/9iQjiSPWDIgSn+ch1yH6QBKgPirVYVVVVVSA:9VLFAMPlVjfSVfvenM4+czyaukA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • Process drops legitimate windows executable

      • SpWebInst0.exe (PID: 440)
    • Executable content was dropped or overwritten

      • SpWebInst0.exe (PID: 440)
    • Checks Windows Trust Settings

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • Application launched itself

      • Spotify.exe (PID: 536)
  • INFO

    • Checks supported languages

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • Checks proxy server information

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • Reads the computer name

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
      • SpWebInst0.exe (PID: 440)
    • Reads the software policy settings

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • Reads the machine GUID from the registry

      • Spotify_Premium_For_PC__Spotify.exe (PID: 1140)
    • The sample compiled with english language support

      • SpWebInst0.exe (PID: 440)
    • Sends debugging messages

      • Spotify.exe (PID: 536)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:02:23 17:48:10+00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.36
CodeSize: 433152
InitializedDataSize: 560640
UninitializedDataSize: -
EntryPoint: 0x3db37
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.2.32.997
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Spotify Ltd
FileDescription: SpotifyInstaller
FileVersion: 0,0,0,0
InternalName: SpotifyInstaller
LegalCopyright: Copyright (c) 2024, Spotify Ltd
OriginalFileName: SpotifyInstaller.exe
ProductName: Spotify
ProductVersion: 1.2.32.997.g4c6498b6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
9
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start spotify_premium_for_pc__spotify.exe spwebinst0.exe spotify.exe spotify.exe no specs spotify.exe no specs spotify.exe spotify.exe no specs spotify.exe no specs spotify.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.53.440" --field-trial-handle=2524,i,7255328140799867212,14114244053258133122,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2544 --mojo-platform-channel-handle=2540 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.53.440
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
440SpWebInst0.exe /webinstallC:\Users\admin\AppData\Roaming\Spotify\SpWebInst0.exe
Spotify_Premium_For_PC__Spotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
SpotifyInstaller
Exit code:
0
Version:
0,0,0,0
Modules
Images
c:\users\admin\appdata\roaming\spotify\spwebinst0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
536Spotify.exeC:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
SpWebInst0.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.53.440
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1140"C:\Users\admin\AppData\Local\Temp\Spotify_Premium_For_PC__Spotify.exe" C:\Users\admin\AppData\Local\Temp\Spotify_Premium_For_PC__Spotify.exe
explorer.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
SpotifyInstaller
Exit code:
0
Version:
0,0,0,0
Modules
Images
c:\users\admin\appdata\local\temp\spotify_premium_for_pc__spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
5308"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=gpu-process --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.53.440" --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=2024,i,7255328140799867212,14114244053258133122,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2040 --mojo-platform-channel-handle=2012 /prefetch:2C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.53.440
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5340C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe --type=crashpad-handler /prefetch:4 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Spotify\User Data\Crashpad" --url=https://crashdump.spotify.com:443/ --annotation=platform=win64 --annotation=product=spotify --annotation=version=1.2.53.440 --initial-client-data=0x3c8,0x3cc,0x3d0,0x3c4,0x3d4,0x7ff821aa8fc8,0x7ff821aa8fd4,0x7ff821aa8fe0C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.53.440
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6068"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.53.440" --field-trial-handle=2184,i,7255328140799867212,14114244053258133122,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2076 --mojo-platform-channel-handle=2316 /prefetch:3C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
Spotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.53.440
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6384"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=renderer --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.53.440" --autoplay-policy=no-user-gesture-required --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=4864,i,7255328140799867212,14114244053258133122,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=4880 --mojo-platform-channel-handle=4876 /prefetch:1C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.53.440
6596"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.53.440" --field-trial-handle=5372,i,7255328140799867212,14114244053258133122,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=5468 --mojo-platform-channel-handle=5284 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Exit code:
0
Version:
1.2.53.440
Total events
4 225
Read events
4 167
Write events
53
Delete events
5

Modification events

(PID) Process:(1140) Spotify_Premium_For_PC__Spotify.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1140) Spotify_Premium_For_PC__Spotify.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1140) Spotify_Premium_For_PC__Spotify.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Spotify Web Helper
Value:
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayName
Value:
Spotify
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayVersion
Value:
1.2.53.440.g7b2f582a
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:Version
Value:
1.2.53.440.g7b2f582a
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallDate
Value:
20250108
(PID) Process:(440) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\Spotify
Executable files
13
Suspicious files
145
Text files
36
Unknown types
123

Dropped files

PID
Process
Filename
Type
1140Spotify_Premium_For_PC__Spotify.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\SpotifyFullSetupX64[1].exe
MD5:
SHA256:
1140Spotify_Premium_For_PC__Spotify.exeC:\Users\admin\AppData\Roaming\Spotify\SpWebInst0.exe
MD5:
SHA256:
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_12_~gmo
MD5:4EEAAF7A5B0BB4D8B9DCEE869DC9B57D
SHA256:CCCDC690828828FCF496A37E0DAF078FD6D6EDD36634A84C2FC174081CD7BE2E
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_4_~binary
MD5:F15E210848C6D8C6C51FA4FFA36B954D
SHA256:8B3DB0C5CD4653373AB1772FD1D9879D3345C480D1B9F4D0499FA01AE5ACFD8E
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_6_~binary
MD5:19BAD258DDF5B876DEABB708810093E6
SHA256:B78C9110523A405EEDC5C693C5D1E0422F3AE1FB5BB312A3F518AD8C7645F8DE
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_14_~binary
MD5:8D2FDBE926FCBF8F7C5A987B94C8D11C
SHA256:6DE3388963D2092E6E2C6105C62A44730E4553393B9FF8F227CF6A8DCFFBBD7E
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_10_~binary
MD5:4DAFC97888D32FE82C99ED435FB113A4
SHA256:911B9A5904F2519735F1691F6898BD8C640B7F334F223549AAA233DEF4609559
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_18_~binary
MD5:FBDB3BA300A2D15AA527B75B0D504BD5
SHA256:5954CF1E3FC0F80FC9B329F36E1031AE123730DE8BFF6136F1250103171BA2E1
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_20_~binary
MD5:326503617C820B4DEE1070EDF97A1A9D
SHA256:B9E09FE6A1E011007C8670CE4AA94A953A398F2B8F084FA6E4CE827DF99A2519
440SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_440_26_~binary
MD5:D51730E0F49B779A8797A84EE2A5DF13
SHA256:D27F2DA3CFD6182670AAD9334253039070FA68951B820A0E2466DC8A33B8A59B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
45
DNS requests
45
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.113:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.16.164.113:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3420
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3420
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5488
SIHClient.exe
GET
200
23.209.210.103:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1140
Spotify_Premium_For_PC__Spotify.exe
GET
200
151.101.194.133:80
http://ocsp2.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEH%2B2oOpV4owETJUuldY0n1w%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
244
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.113:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.113:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
1140
Spotify_Premium_For_PC__Spotify.exe
199.232.210.248:443
download.scdn.co
FASTLY
US
whitelisted
3976
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1140
Spotify_Premium_For_PC__Spotify.exe
151.101.194.133:80
ocsp2.globalsign.com
FASTLY
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted
crl.microsoft.com
  • 2.16.164.113
  • 2.16.164.112
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.209.210.103
whitelisted
download.scdn.co
  • 199.232.210.248
  • 199.232.214.248
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
ocsp2.globalsign.com
  • 151.101.194.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.2.133
whitelisted
www.bing.com
  • 2.23.227.221
  • 2.23.227.208
  • 2.23.227.215
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.160.17
  • 40.126.32.134
  • 40.126.32.136
  • 40.126.32.138
  • 40.126.32.68
  • 40.126.32.140
  • 40.126.32.76
  • 20.190.160.22
whitelisted
go.microsoft.com
  • 23.56.254.14
whitelisted

Threats

No threats detected
Process
Message
Spotify.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local directory exists )