File name:

Bonjour64.msi

Full analysis: https://app.any.run/tasks/b3dae9d8-6623-4087-9552-a19d920646b0
Verdict: Malicious activity
Analysis date: April 19, 2025, 01:50:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Instalador de [ProductName], Author: Apple Inc., Keywords: Installer,MSI,Database, Comments: Bonjour 3.1.0.1, Create Time/Date: Thu Aug 27 01:32:48 2015, Name of Creating Application: Windows Installer XML (3.0.5419.0), Security: 4, Template: x64;1033,1036,1031,1041,1043,1040,1028,2052,1034,1030,1035,1042,1044,1045,2070,1046,1049,1053, Last Saved By: x64;1033,1036,1031,1041,1043,1040,1028,2052,1034,1030,1035,1042,1044,1045,2070,1046,1049,1053, Revision Number: {56DDDFB8-7F79-4480-89D5-25E1F52AB28F}3.1.0.1;{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}3.1.0.1;{46AE3251-43D6-41CF-8CDF-E902C38516D1}, Number of Pages: 300, Number of Characters: 131135
MD5:

86E2B390629665FBC20E06DFBF01A48F

SHA1:

D9F4697A6F4ECEEA24735822CB1DF501268CA0B0

SHA256:

46E31E284DA64D6C2D366352B8A8ABCF7DB28D3E2A870D8FCF15C4A6FE0A6DD1

SSDEEP:

49152:xDazwTevwRV3g79d+YUowu9iXeixErgN8HovTtazZ6COcLi4/uP/t/vh8h7ap83l:owSvSg79AYUowaGW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • mDNSResponder.exe (PID: 7208)
  • SUSPICIOUS

    • Checks for Java to be installed

      • msiexec.exe (PID: 5048)
    • Application launched itself

      • msiexec.exe (PID: 7608)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7736)
      • mDNSResponder.exe (PID: 7208)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 7608)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 7608)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7608)
  • INFO

    • Reads the software policy settings

      • msiexec.exe (PID: 7396)
      • slui.exe (PID: 7500)
      • msiexec.exe (PID: 7608)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 7396)
    • Checks supported languages

      • msiexec.exe (PID: 5048)
      • msiexec.exe (PID: 7608)
      • msiexec.exe (PID: 7324)
      • msiexec.exe (PID: 1912)
      • mDNSResponder.exe (PID: 7208)
      • msiexec.exe (PID: 7648)
    • Checks proxy server information

      • msiexec.exe (PID: 7396)
      • slui.exe (PID: 7500)
      • msiexec.exe (PID: 5048)
    • Reads the computer name

      • msiexec.exe (PID: 7608)
      • msiexec.exe (PID: 7648)
      • msiexec.exe (PID: 7324)
      • msiexec.exe (PID: 1912)
      • mDNSResponder.exe (PID: 7208)
      • msiexec.exe (PID: 5048)
    • The sample compiled with english language support

      • msiexec.exe (PID: 7396)
      • msiexec.exe (PID: 7608)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7396)
      • msiexec.exe (PID: 7608)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 7396)
    • Manages system restore points

      • SrTasks.exe (PID: 5156)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 7608)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 7608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: [ProductName] Installer
Author: Apple Inc.
Keywords: Installer,MSI,Database
Comments: Bonjour 3.1.0.1
Template: x64;1033,1036,1031,1041,1043,1040,1028,2052,1034,1030,1035,1042,1044,1045,2070,1046,1049,1053
RevisionNumber: {3AAD0BA7-C31B-4C75-ABEA-B4D5227892E4}
CreateDate: 2015:08:27 01:30:54
ModifyDate: 2015:08:27 01:30:54
Pages: 300
Words: 2
Software: Windows Installer XML (3.0.5419.0)
Security: Read-only recommended
LastModifiedBy: x64;1033,1036,1031,1041,1043,1040,1028,2052,1034,1030,1035,1042,1044,1045,2070,1046,1049,1053
Characters: 131135
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
13
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs mdnsresponder.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
1660\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1912C:\Windows\syswow64\MsiExec.exe -Embedding 0B71E4B5359698377962D6B4DD07E723 E Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5048C:\Windows\System32\MsiExec.exe -Embedding 82FCAAFE86E33097143E3D21A23D47D7C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5156C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7208"C:\Program Files\Bonjour\mDNSResponder.exe"C:\Program Files\Bonjour\mDNSResponder.exe
services.exe
User:
SYSTEM
Company:
Apple Inc.
Integrity Level:
SYSTEM
Description:
Bonjour Service
Version:
3,1,0,1
Modules
Images
c:\program files\bonjour\mdnsresponder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7268"C:\Windows\System32\MsiExec.exe" /Y "C:\Program Files\Bonjour\mdnsNSP.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7324C:\Windows\syswow64\MsiExec.exe -Embedding CC49A260BC9D6E8FB31E78A23F234C37C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7336"C:\Windows\syswow64\MsiExec.exe" /Y "C:\Program Files (x86)\Bonjour\mdnsNSP.dll"C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7396"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\Desktop\Bonjour64.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7500C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
15 862
Read events
15 336
Write events
497
Delete events
29

Modification events

(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
48000000000000000A9F457DCDB0DB01B81D0000281E0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000000A9F457DCDB0DB01B81D0000281E0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
48000000000000004D918F7DCDB0DB01B81D0000281E0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000004D918F7DCDB0DB01B81D0000281E0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000BEE1917DCDB0DB01B81D0000281E0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000006C46947DCDB0DB01B81D0000281E0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000009DE60D7ECDB0DB01B81D0000901E0000E803000001000000000000000000000006CBDA302F4451448E79B15B546B292100000000000000000000000000000000
(PID) Process:(7736) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Leave)
Value:
48000000000000004B56237ECDB0DB01381E0000541E0000E80300000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7736) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Leave)
Value:
480000000000000089B9257ECDB0DB01381E0000AC1E0000E80300000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
26
Suspicious files
28
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
7608msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
7608msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{30dacb06-442f-4451-8e79-b15b546b2921}_OnDiskSnapshotPropbinary
MD5:B0B069C2423721194AE2B0E3C721A751
SHA256:F0444992F9C038D480252B0C088D63AF12A98D1A45D5F1A1543E0DDB7D40421B
7608msiexec.exeC:\Windows\Installer\MSI41DB.tmpexecutable
MD5:6F8E3E4F72620BDDC633F0175F47161E
SHA256:2ADF199F6BAF245F0B07D31A3A1401D4262C3E6C98B8F10DF923CEB2C937291E
7396msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6binary
MD5:EBD00D04C35534BB4F8E97827958DE56
SHA256:A3CA843D76A5720928E528205313E7190693BBFD805C6FA25BACB5BE50682559
7396msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A89DFCC31C360BA5CBD616749B1B1C5Dbinary
MD5:20BFE0E29A05B67BBCEFDFF6A5A438B0
SHA256:1B7A0E908BD94EF35176C972D1B9077C4F64D4C181D08DDE93B1E074C16FFB92
7396msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92Fbinary
MD5:7D55CFF80DEB88D19108598182DFDD3D
SHA256:E5FA4D484549385C78AD678BB311AED05B4914BF9EDE850CBAB6A92C301FFC6A
7608msiexec.exeC:\Windows\Installer\MSI3FF4.tmpexecutable
MD5:950087E828E1B7426F703678E446C799
SHA256:8A41EAA0D699F48661C2560AEFFE4B0432CF755F1B15E31AC9AFF667D498B3EE
7396msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9A19ADAD9D098E039450ABBEDD5616EB_8882E6641F4980577F6015B0188D2368binary
MD5:4814AE4A64007DCEEC7A3884B5CB2468
SHA256:7147E7B97D93A885D613CE9CDC6B184A3062940E4F972574D4B6F978111E8D6B
7396msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9A19ADAD9D098E039450ABBEDD5616EB_8882E6641F4980577F6015B0188D2368binary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
7396msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92Fbinary
MD5:2AB172E9398A3F429D22A89DB10F024D
SHA256:4DFCA5F2F4907EFD537D7DB7D4A8B5D57A14B551EE62A0F4F3EF6B795C438262
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
36
TCP/UDP connections
53
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7396
msiexec.exe
GET
200
2.23.79.3:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D
unknown
whitelisted
7396
msiexec.exe
GET
200
2.23.79.3:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D
unknown
whitelisted
7396
msiexec.exe
GET
200
2.23.79.3:80
http://sf.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CECsg6zOAeSqwEfZiwGT9tHM%3D
unknown
whitelisted
7396
msiexec.exe
GET
200
2.23.79.3:80
http://sf.symcb.com/sf.crl
unknown
whitelisted
7396
msiexec.exe
GET
200
2.23.79.3:80
http://sf.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CECsg6zOAeSqwEfZiwGT9tHM%3D
unknown
whitelisted
GET
304
20.109.210.53:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
7988
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
GET
200
20.109.210.53:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
7988
SIHClient.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
7988
SIHClient.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7396
msiexec.exe
2.23.79.3:80
ocsp.verisign.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7988
SIHClient.exe
20.109.210.53:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7988
SIHClient.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
7988
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
7988
SIHClient.exe
20.242.39.171:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.110
whitelisted
ocsp.verisign.com
  • 2.23.79.3
whitelisted
crl.verisign.com
  • 2.23.79.3
whitelisted
sf.symcd.com
  • 2.23.79.3
whitelisted
sf.symcb.com
  • 2.23.79.3
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

No threats detected
No debug info