File name:

Spotify_Premium_For_PC__Spotify.exe

Full analysis: https://app.any.run/tasks/d99d3570-1759-40f8-9a25-0d9989116728
Verdict: Malicious activity
Analysis date: November 23, 2024, 08:41:44
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-html
arch-scr
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

226E3B0D49A2252895B30276AE73F411

SHA1:

113D495905F25E40F5DE77085E3E9C358F25B5BB

SHA256:

419E316E8195FF0434FE7C342704B6B4EB75381668578A93578E0A5CE7A4D90B

SSDEEP:

12288:vkoVLFAMPlVrP/fRkH1fveT/9iQjiSPWDIgSn+ch1yH6QBKgPirVYVVVVVSA:9VLFAMPlVjfSVfvenM4+czyaukA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Spotify.exe (PID: 6548)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Spotify_Premium_For_PC__Spotify.exe (PID: 4400)
    • Checks Windows Trust Settings

      • Spotify_Premium_For_PC__Spotify.exe (PID: 4400)
    • Executable content was dropped or overwritten

      • SpWebInst0.exe (PID: 6384)
    • Process drops legitimate windows executable

      • SpWebInst0.exe (PID: 6384)
    • Creates a software uninstall entry

      • SpWebInst0.exe (PID: 6384)
    • Application launched itself

      • Spotify.exe (PID: 6548)
    • The process checks if it is being run in the virtual environment

      • Spotify.exe (PID: 6548)
  • INFO

    • Checks proxy server information

      • Spotify_Premium_For_PC__Spotify.exe (PID: 4400)
      • Spotify.exe (PID: 6548)
    • Creates files or folders in the user directory

      • Spotify_Premium_For_PC__Spotify.exe (PID: 4400)
      • SpWebInst0.exe (PID: 6384)
      • Spotify.exe (PID: 6764)
      • Spotify.exe (PID: 6596)
      • Spotify.exe (PID: 6548)
    • Checks supported languages

      • Spotify_Premium_For_PC__Spotify.exe (PID: 4400)
      • SpWebInst0.exe (PID: 6384)
      • Spotify.exe (PID: 6548)
      • Spotify.exe (PID: 6596)
      • Spotify.exe (PID: 6752)
      • Spotify.exe (PID: 6260)
      • Spotify.exe (PID: 6212)
      • Spotify.exe (PID: 6876)
      • Spotify.exe (PID: 4228)
      • Spotify.exe (PID: 6764)
    • Reads the software policy settings

      • Spotify_Premium_For_PC__Spotify.exe (PID: 4400)
    • Reads the computer name

      • Spotify_Premium_For_PC__Spotify.exe (PID: 4400)
      • SpWebInst0.exe (PID: 6384)
      • Spotify.exe (PID: 6548)
      • Spotify.exe (PID: 6752)
      • Spotify.exe (PID: 6764)
      • Spotify.exe (PID: 6260)
    • Reads the machine GUID from the registry

      • Spotify_Premium_For_PC__Spotify.exe (PID: 4400)
      • Spotify.exe (PID: 6548)
    • Sends debugging messages

      • Spotify.exe (PID: 6548)
    • Process checks computer location settings

      • Spotify.exe (PID: 6212)
      • Spotify.exe (PID: 6548)
    • Create files in a temporary directory

      • Spotify.exe (PID: 6548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:02:23 17:48:10+00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.36
CodeSize: 433152
InitializedDataSize: 560640
UninitializedDataSize: -
EntryPoint: 0x3db37
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.2.32.997
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Spotify Ltd
FileDescription: SpotifyInstaller
FileVersion: 0,0,0,0
InternalName: SpotifyInstaller
LegalCopyright: Copyright (c) 2024, Spotify Ltd
OriginalFileName: SpotifyInstaller.exe
ProductName: Spotify
ProductVersion: 1.2.32.997.g4c6498b6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
10
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start spotify_premium_for_pc__spotify.exe spwebinst0.exe spotify.exe spotify.exe no specs spotify.exe no specs spotify.exe spotify.exe no specs spotify.exe no specs spotify.exe no specs spotify.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4228"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/130.0.6723.117 Spotify/1.2.51.345" --field-trial-handle=5380,i,10327345503908214965,10834147576128930187,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=5812 --mojo-platform-channel-handle=6032 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Exit code:
0
Version:
1.2.51.345
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4400"C:\Users\admin\Desktop\Spotify_Premium_For_PC__Spotify.exe" C:\Users\admin\Desktop\Spotify_Premium_For_PC__Spotify.exe
explorer.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
SpotifyInstaller
Exit code:
0
Version:
0,0,0,0
Modules
Images
c:\users\admin\desktop\spotify_premium_for_pc__spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6212"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=renderer --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/130.0.6723.117 Spotify/1.2.51.345" --autoplay-policy=no-user-gesture-required --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=4816,i,10327345503908214965,10834147576128930187,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=4832 --mojo-platform-channel-handle=4828 /prefetch:1C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.51.345
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6260"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/130.0.6723.117 Spotify/1.2.51.345" --field-trial-handle=5464,i,10327345503908214965,10834147576128930187,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=5484 --mojo-platform-channel-handle=5380 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Exit code:
0
Version:
1.2.51.345
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6384SpWebInst0.exe /webinstallC:\Users\admin\AppData\Roaming\Spotify\SpWebInst0.exe
Spotify_Premium_For_PC__Spotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
SpotifyInstaller
Exit code:
0
Version:
0,0,0,0
Modules
Images
c:\users\admin\appdata\roaming\spotify\spwebinst0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6548Spotify.exeC:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
SpWebInst0.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.51.345
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6596C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe --type=crashpad-handler /prefetch:4 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Spotify\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Spotify\User Data" --url=https://crashdump.spotify.com:443/ --annotation=platform=win64 --annotation=product=spotify --annotation=version=1.2.51.345 --initial-client-data=0x3c8,0x3cc,0x3d0,0x3c4,0x3d4,0x7ff821dd1ef8,0x7ff821dd1f04,0x7ff821dd1f10C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.51.345
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6752"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=gpu-process --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/130.0.6723.117 Spotify/1.2.51.345" --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=1996,i,10327345503908214965,10834147576128930187,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2016 --mojo-platform-channel-handle=1992 /prefetch:2C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.51.345
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6764"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/130.0.6723.117 Spotify/1.2.51.345" --field-trial-handle=1540,i,10327345503908214965,10834147576128930187,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2312 --mojo-platform-channel-handle=2296 /prefetch:3C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
Spotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.51.345
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6876"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/130.0.6723.117 Spotify/1.2.51.345" --field-trial-handle=2544,i,10327345503908214965,10834147576128930187,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2560 --mojo-platform-channel-handle=2556 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.51.345
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
4 396
Read events
4 339
Write events
52
Delete events
5

Modification events

(PID) Process:(4400) Spotify_Premium_For_PC__Spotify.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4400) Spotify_Premium_For_PC__Spotify.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4400) Spotify_Premium_For_PC__Spotify.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6384) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Spotify Web Helper
Value:
(PID) Process:(6384) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
(PID) Process:(6384) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayName
Value:
Spotify
(PID) Process:(6384) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayVersion
Value:
1.2.51.345.gcc39d911
(PID) Process:(6384) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:Version
Value:
1.2.51.345.gcc39d911
(PID) Process:(6384) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallDate
Value:
20241123
(PID) Process:(6384) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\Spotify
Executable files
14
Suspicious files
159
Text files
37
Unknown types
112

Dropped files

PID
Process
Filename
Type
4400Spotify_Premium_For_PC__Spotify.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\SpotifyFullSetupX64[1].exe
MD5:
SHA256:
4400Spotify_Premium_For_PC__Spotify.exeC:\Users\admin\AppData\Roaming\Spotify\SpWebInst0.exe
MD5:
SHA256:
4400Spotify_Premium_For_PC__Spotify.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_4D90A79F4986A67200F4F4B3378FFAD0binary
MD5:58E011E9850A559C01EAA4444BB2CE66
SHA256:8368563EE3B62590B39A7CB71AE1132F5C05AF31558EAB01DFED523F083CED3E
4400Spotify_Premium_For_PC__Spotify.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_4D90A79F4986A67200F4F4B3378FFAD0der
MD5:AA1653E75F6CA6BB4D850FB6D9A76661
SHA256:9C4AB5D0085A63AFC1F5A5A9EC94DA2A167558F1556D467DB7311022A6E98058
6384SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6384_12_~binary
MD5:4EEAAF7A5B0BB4D8B9DCEE869DC9B57D
SHA256:CCCDC690828828FCF496A37E0DAF078FD6D6EDD36634A84C2FC174081CD7BE2E
6384SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6384_2_~compressed
MD5:EBCF3A7A7CB776E175BC0BA1A3A07FAB
SHA256:BBCC22AEBC7AADCFFA8A78EE7097C8D82B0B349016C9B8DA3685C491D849CF03
6384SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6384_10_~gmo
MD5:4DAFC97888D32FE82C99ED435FB113A4
SHA256:911B9A5904F2519735F1691F6898BD8C640B7F334F223549AAA233DEF4609559
6384SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6384_0_~compressed
MD5:870FB84DEBD15E3DD5861B312C65E2C8
SHA256:B6575138AF9C4C3650818EE4C2368A2FEE4B9902B2E06BE809FCB620F3899458
6384SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6384_14_~binary
MD5:8D2FDBE926FCBF8F7C5A987B94C8D11C
SHA256:6DE3388963D2092E6E2C6105C62A44730E4553393B9FF8F227CF6A8DCFFBBD7E
6384SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6384_16_~gmo
MD5:1CA307AE3A4BEF36F49AEFF37A3FD2CC
SHA256:4D498B2FD63284D6980E8EBF0289649E5F04632181DDA1D4CD476DA47CD4E2AC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
37
DNS requests
46
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.18.121.147:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3664
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/japrfto3glzuybauq4wkmtrqte_2024.11.18.0/niikhdgajlphfehepabhhblakbdgeefj_2024.11.18.00_all_acj3wrlm6xavgplit7omufnappaa.crx3
unknown
whitelisted
5268
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6408
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6408
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3664
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/japrfto3glzuybauq4wkmtrqte_2024.11.18.0/niikhdgajlphfehepabhhblakbdgeefj_2024.11.18.00_all_acj3wrlm6xavgplit7omufnappaa.crx3
unknown
whitelisted
3664
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/japrfto3glzuybauq4wkmtrqte_2024.11.18.0/niikhdgajlphfehepabhhblakbdgeefj_2024.11.18.00_all_acj3wrlm6xavgplit7omufnappaa.crx3
unknown
whitelisted
3664
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/japrfto3glzuybauq4wkmtrqte_2024.11.18.0/niikhdgajlphfehepabhhblakbdgeefj_2024.11.18.00_all_acj3wrlm6xavgplit7omufnappaa.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2144
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.18.121.147:80
crl.microsoft.com
AKAMAI-AS
FR
whitelisted
2.18.121.147:80
crl.microsoft.com
AKAMAI-AS
FR
whitelisted
4712
MoUsoCoreWorker.exe
23.200.189.225:80
www.microsoft.com
Moratelindo Internet Exchange Point
ID
whitelisted
23.200.189.225:80
www.microsoft.com
Moratelindo Internet Exchange Point
ID
whitelisted
5064
SearchApp.exe
2.16.106.207:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4400
Spotify_Premium_For_PC__Spotify.exe
199.232.214.248:443
download.scdn.co
FASTLY
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.18.121.147
  • 2.18.121.151
  • 2.18.121.139
whitelisted
www.microsoft.com
  • 23.200.189.225
  • 88.221.169.152
whitelisted
google.com
  • 142.250.74.206
whitelisted
www.bing.com
  • 2.16.106.207
  • 2.16.106.196
  • 2.16.106.200
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
download.scdn.co
  • 199.232.214.248
  • 199.232.210.248
whitelisted
ocsp2.globalsign.com
  • 151.101.194.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.2.133
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.72
  • 40.126.32.140
  • 40.126.32.68
  • 40.126.32.76
  • 20.190.160.22
  • 40.126.32.133
  • 40.126.32.134
whitelisted
go.microsoft.com
  • 23.53.113.159
whitelisted

Threats

No threats detected
Process
Message
Spotify.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local directory exists )