File name:

SpotifySetup.exe

Full analysis: https://app.any.run/tasks/911dad05-5c11-4dab-a1d1-a448d734ab9a
Verdict: Malicious activity
Analysis date: February 15, 2025, 12:46:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

189E2E710A8C5E043077F8AE15E48C64

SHA1:

DD8D7E6328572B2ECD15A50999323A7B3322DF87

SHA256:

4EEC970CB03ECDCD745172F7B44FE3ED54089DEA616BA5C3687FC8D9AE0E6B0D

SSDEEP:

12288:nFcCezX4bVSYWUvS9B//ju2nmWhp5cng6lHj+eWPKZGPYFaPlO+HfMfV9qgcn4uM:nFMzOtvSb//DmWh8ngjP/fMfV9Q57

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Spotify.exe (PID: 6316)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • SpotifySetup.exe (PID: 4500)
    • Checks Windows Trust Settings

      • SpotifySetup.exe (PID: 4500)
    • There is functionality for taking screenshot (YARA)

      • SpotifySetup.exe (PID: 4500)
    • Process drops legitimate windows executable

      • SpWebInst0.exe (PID: 5304)
    • Executable content was dropped or overwritten

      • SpWebInst0.exe (PID: 5304)
    • Creates a software uninstall entry

      • SpWebInst0.exe (PID: 5304)
    • Application launched itself

      • Spotify.exe (PID: 6316)
    • The process checks if it is being run in the virtual environment

      • Spotify.exe (PID: 6316)
  • INFO

    • Reads the computer name

      • SpotifySetup.exe (PID: 4500)
      • SpWebInst0.exe (PID: 5304)
      • Spotify.exe (PID: 6528)
      • Spotify.exe (PID: 6316)
      • Spotify.exe (PID: 5712)
      • Spotify.exe (PID: 6516)
    • Creates files or folders in the user directory

      • SpotifySetup.exe (PID: 4500)
      • SpWebInst0.exe (PID: 5304)
      • Spotify.exe (PID: 6316)
      • Spotify.exe (PID: 6360)
      • Spotify.exe (PID: 6528)
    • Checks supported languages

      • SpotifySetup.exe (PID: 4500)
      • SpWebInst0.exe (PID: 5304)
      • Spotify.exe (PID: 6516)
      • Spotify.exe (PID: 6528)
      • Spotify.exe (PID: 6316)
      • Spotify.exe (PID: 6360)
      • Spotify.exe (PID: 5712)
      • Spotify.exe (PID: 3532)
      • Spotify.exe (PID: 6624)
      • Spotify.exe (PID: 6964)
    • Checks proxy server information

      • SpotifySetup.exe (PID: 4500)
      • Spotify.exe (PID: 6316)
    • Reads the software policy settings

      • SpotifySetup.exe (PID: 4500)
    • Reads the machine GUID from the registry

      • SpotifySetup.exe (PID: 4500)
      • Spotify.exe (PID: 6316)
    • Manual execution by a user

      • powershell.exe (PID: 5916)
    • Checks current location (POWERSHELL)

      • powershell.exe (PID: 5916)
    • The sample compiled with english language support

      • SpWebInst0.exe (PID: 5304)
    • Process checks computer location settings

      • Spotify.exe (PID: 6316)
      • Spotify.exe (PID: 6964)
    • Create files in a temporary directory

      • Spotify.exe (PID: 6316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2032:03:16 22:02:05+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 577024
InitializedDataSize: 871936
UninitializedDataSize: -
EntryPoint: 0x16d8
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.2.57.463
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Spotify Ltd
FileDescription: SpotifyInstaller
FileVersion: 0,0,0,0
InternalName: SpotifyInstaller
LegalCopyright: Copyright (c) 2025, Spotify Ltd
OriginalFileName: SpotifyInstaller.exe
ProductName: Spotify
ProductVersion: 1.2.57.463.g4f748c64
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
12
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start spotifysetup.exe powershell.exe conhost.exe no specs spwebinst0.exe spotify.exe spotify.exe no specs spotify.exe no specs spotify.exe spotify.exe no specs spotify.exe no specs spotify.exe no specs spotify.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
440\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3532"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.57.463" --field-trial-handle=6080,i,2277518450946714043,14916040925809716179,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=5932 --mojo-platform-channel-handle=6068 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Exit code:
0
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
4500"C:\Users\admin\AppData\Local\Temp\SpotifySetup.exe" C:\Users\admin\AppData\Local\Temp\SpotifySetup.exe
explorer.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
SpotifyInstaller
Exit code:
0
Version:
0,0,0,0
Modules
Images
c:\users\admin\appdata\local\temp\spotifysetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
5304SpWebInst0.exe /webinstallC:\Users\admin\AppData\Roaming\Spotify\SpWebInst0.exe
SpotifySetup.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
SpotifyInstaller
Exit code:
0
Version:
0,0,0,0
Modules
Images
c:\users\admin\appdata\roaming\spotify\spwebinst0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
5712"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.57.463" --field-trial-handle=5288,i,2277518450946714043,14916040925809716179,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=5292 --mojo-platform-channel-handle=4288 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Exit code:
0
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5916"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
6316Spotify.exeC:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
SpWebInst0.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6360C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe --type=crashpad-handler /prefetch:4 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Spotify\User Data\Crashpad" --url=https://crashdump.spotify.com:443/ --annotation=platform=win64 --annotation=product=spotify --annotation=version=1.2.57.463 --initial-client-data=0x3b0,0x3b4,0x3b8,0x3ac,0x3bc,0x7ff81d468fc8,0x7ff81d468fd4,0x7ff81d468fe0C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6516"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=gpu-process --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.57.463" --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=1988,i,2277518450946714043,14916040925809716179,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2008 --mojo-platform-channel-handle=1980 /prefetch:2C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6528"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.57.463" --field-trial-handle=1536,i,2277518450946714043,14916040925809716179,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2156 --mojo-platform-channel-handle=2080 /prefetch:3C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
Spotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
9 776
Read events
9 718
Write events
53
Delete events
5

Modification events

(PID) Process:(4500) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4500) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4500) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5304) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Spotify Web Helper
Value:
(PID) Process:(5304) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
(PID) Process:(5304) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayName
Value:
Spotify
(PID) Process:(5304) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayVersion
Value:
1.2.57.463.g4f748c64
(PID) Process:(5304) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:Version
Value:
1.2.57.463.g4f748c64
(PID) Process:(5304) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallDate
Value:
20250215
(PID) Process:(5304) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\Spotify
Executable files
20
Suspicious files
270
Text files
33
Unknown types
4

Dropped files

PID
Process
Filename
Type
4500SpotifySetup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\SpotifyFullSetupX64[1].exe
MD5:
SHA256:
4500SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\SpWebInst0.exe
MD5:
SHA256:
5916powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:659DA184C8710CDBEF5172AA27EB1796
SHA256:4DDC0682F6B46E0CCCA349629F3DCCCD2F635B88B5D2441B6329A1FC4B8A20FF
5916powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF136af2.TMPbinary
MD5:D040F64E9E7A2BB91ABCA5613424598E
SHA256:D04E0A6940609BD6F3B561B0F6027F5CA4E8C5CF0FB0D0874B380A0374A8D670
5304SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_5304_6_~binary
MD5:F762A7806B3252CC6223F08495F36278
SHA256:5B5164566895BBDA8B85F6002F3E29604602EADC61AFBE0D2E09223BFB43B0BD
5916powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_pquwsq2d.n4y.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
5304SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_5304_2_~compressed
MD5:1B5DCE1D0B53C0C50F56E8D85BF44E67
SHA256:1A8E3F42E2BAAC244D56D85F3F3D8EDD59CDC3744CAF76AB8B0D69FC4BE18DC4
5916powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ehrl32ms.yap.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
5304SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_5304_4_~binary
MD5:C5A319C0CB320DCCAB68C63D63583394
SHA256:58C59298067ED5542F6E282A9E7BD71C48A007D0ECFE80B63BA1C57F42D1450E
5304SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_5304_0_~compressed
MD5:2F9DC7434FBE56088EB69DCAB57997D3
SHA256:2810B0004E0D0039D6B260624F6B0BA2B5C0D0663A9E6667667781ADF528816E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
45
DNS requests
48
Threats
15

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.141:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4500
SpotifySetup.exe
GET
200
151.101.66.133:80
http://ocsp2.globalsign.com/rootr3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEQCCFEE7BXGhpoEKjlIOBXTx
unknown
whitelisted
5064
SearchApp.exe
GET
200
23.67.160.244:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
23.67.160.244:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3544
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acqx6rfuv4ccvh2th25qcyoyhk3a_2025.2.14.0/niikhdgajlphfehepabhhblakbdgeefj_2025.02.14.00_all_ld3jwojee6clp5ni6dpz32zstq.crx3
unknown
whitelisted
3544
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acqx6rfuv4ccvh2th25qcyoyhk3a_2025.2.14.0/niikhdgajlphfehepabhhblakbdgeefj_2025.02.14.00_all_ld3jwojee6clp5ni6dpz32zstq.crx3
unknown
whitelisted
3544
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acqx6rfuv4ccvh2th25qcyoyhk3a_2025.2.14.0/niikhdgajlphfehepabhhblakbdgeefj_2025.02.14.00_all_ld3jwojee6clp5ni6dpz32zstq.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.141:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.19.217.218:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4500
SpotifySetup.exe
199.232.214.248:443
download.scdn.co
FASTLY
US
whitelisted
4500
SpotifySetup.exe
151.101.66.133:80
ocsp2.globalsign.com
FASTLY
US
whitelisted
1684
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
23.212.110.169:443
www.bing.com
Akamai International B.V.
CZ
whitelisted
1176
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.141
  • 23.48.23.147
  • 23.48.23.145
  • 23.48.23.140
  • 23.48.23.137
  • 23.48.23.143
  • 23.48.23.142
  • 23.48.23.144
  • 23.48.23.146
whitelisted
www.microsoft.com
  • 2.19.217.218
whitelisted
google.com
  • 142.250.185.78
whitelisted
download.scdn.co
  • 199.232.214.248
  • 199.232.210.248
whitelisted
ocsp2.globalsign.com
  • 151.101.66.133
  • 151.101.194.133
  • 151.101.130.133
  • 151.101.2.133
whitelisted
www.bing.com
  • 23.212.110.169
  • 23.212.110.138
  • 23.212.110.161
  • 23.212.110.144
  • 23.212.110.209
  • 23.212.110.137
  • 23.212.110.217
  • 23.212.110.146
  • 23.212.110.155
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.132
  • 40.126.32.74
  • 20.190.160.66
  • 20.190.160.5
  • 20.190.160.14
  • 40.126.32.76
  • 20.190.160.64
whitelisted
ocsp.digicert.com
  • 23.67.160.244
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted

Threats

PID
Process
Class
Message
6528
Spotify.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
6528
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6528
Spotify.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
6528
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6528
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6528
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6528
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6528
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6528
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6528
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info