File name:

SpotifySetup.exe

Full analysis: https://app.any.run/tasks/975df520-39b9-4b71-bf3c-2f2de78f887f
Verdict: Malicious activity
Analysis date: February 12, 2025, 20:13:40
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-html
arch-scr
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

189E2E710A8C5E043077F8AE15E48C64

SHA1:

DD8D7E6328572B2ECD15A50999323A7B3322DF87

SHA256:

4EEC970CB03ECDCD745172F7B44FE3ED54089DEA616BA5C3687FC8D9AE0E6B0D

SSDEEP:

12288:nFcCezX4bVSYWUvS9B//ju2nmWhp5cng6lHj+eWPKZGPYFaPlO+HfMfV9qgcn4uM:nFMzOtvSb//DmWh8ngjP/fMfV9Q57

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • SpotifySetup.exe (PID: 6220)
    • Creates a software uninstall entry

      • SpWebInst0.exe (PID: 7164)
    • Executable content was dropped or overwritten

      • SpWebInst0.exe (PID: 7164)
    • Checks Windows Trust Settings

      • SpotifySetup.exe (PID: 6220)
    • Application launched itself

      • Spotify.exe (PID: 4684)
    • The process checks if it is being run in the virtual environment

      • Spotify.exe (PID: 4684)
    • Process drops legitimate windows executable

      • SpWebInst0.exe (PID: 7164)
  • INFO

    • Checks supported languages

      • SpotifySetup.exe (PID: 6220)
      • Spotify.exe (PID: 2148)
      • Spotify.exe (PID: 4684)
      • SpWebInst0.exe (PID: 7164)
    • Creates files or folders in the user directory

      • Spotify.exe (PID: 6028)
      • SpotifySetup.exe (PID: 6220)
      • Spotify.exe (PID: 4684)
      • Spotify.exe (PID: 3540)
      • SpWebInst0.exe (PID: 7164)
    • The sample compiled with english language support

      • SpWebInst0.exe (PID: 7164)
    • Reads the computer name

      • Spotify.exe (PID: 2148)
      • SpotifySetup.exe (PID: 6220)
    • Reads the software policy settings

      • SpotifySetup.exe (PID: 6220)
    • Reads the machine GUID from the registry

      • Spotify.exe (PID: 4684)
      • SpotifySetup.exe (PID: 6220)
    • Checks proxy server information

      • SpotifySetup.exe (PID: 6220)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2032:03:16 22:02:05+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 577024
InitializedDataSize: 871936
UninitializedDataSize: -
EntryPoint: 0x16d8
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.2.57.463
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Spotify Ltd
FileDescription: SpotifyInstaller
FileVersion: 0,0,0,0
InternalName: SpotifyInstaller
LegalCopyright: Copyright (c) 2025, Spotify Ltd
OriginalFileName: SpotifyInstaller.exe
ProductName: Spotify
ProductVersion: 1.2.57.463.g4f748c64
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start spotifysetup.exe spwebinst0.exe spotify.exe no specs spotify.exe no specs spotify.exe no specs spotify.exe spotify.exe no specs spotify.exe no specs spotify.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1668"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.57.463" --field-trial-handle=5376,i,13391401273803853495,5336915222243029174,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=5364 --mojo-platform-channel-handle=4408 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Exit code:
0
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2148"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=gpu-process --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.57.463" --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=2004,i,13391401273803853495,5336915222243029174,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2012 --mojo-platform-channel-handle=1992 /prefetch:2C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3540"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.57.463" --field-trial-handle=2076,i,13391401273803853495,5336915222243029174,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2292 --mojo-platform-channel-handle=2312 /prefetch:3C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
Spotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4684Spotify.exeC:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpWebInst0.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6028C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe --type=crashpad-handler /prefetch:4 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Spotify\User Data\Crashpad" --url=https://crashdump.spotify.com:443/ --annotation=platform=win64 --annotation=product=spotify --annotation=version=1.2.57.463 --initial-client-data=0x3c4,0x3c8,0x3cc,0x3c0,0x3d0,0x7ff8219c8fc8,0x7ff8219c8fd4,0x7ff8219c8fe0C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6220"C:\Users\admin\AppData\Local\Temp\SpotifySetup.exe" C:\Users\admin\AppData\Local\Temp\SpotifySetup.exe
explorer.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
SpotifyInstaller
Exit code:
0
Version:
0,0,0,0
Modules
Images
c:\users\admin\appdata\local\temp\spotifysetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6340"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=renderer --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.57.463" --autoplay-policy=no-user-gesture-required --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=4668,i,13391401273803853495,5336915222243029174,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=4684 --mojo-platform-channel-handle=4680 /prefetch:1C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
6756"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.57.463" --field-trial-handle=2504,i,13391401273803853495,5336915222243029174,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2516 --mojo-platform-channel-handle=2512 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Version:
1.2.57.463
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
7164SpWebInst0.exe /webinstallC:\Users\admin\AppData\Roaming\Spotify\SpWebInst0.exe
SpotifySetup.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
SpotifyInstaller
Exit code:
0
Version:
0,0,0,0
Modules
Images
c:\users\admin\appdata\roaming\spotify\spwebinst0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
Total events
4 297
Read events
4 239
Write events
53
Delete events
5

Modification events

(PID) Process:(6220) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6220) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6220) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7164) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Spotify Web Helper
Value:
(PID) Process:(7164) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
(PID) Process:(7164) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayName
Value:
Spotify
(PID) Process:(7164) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" /uninstall
(PID) Process:(7164) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:URLInfoAbout
Value:
https://www.spotify.com
(PID) Process:(7164) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayVersion
Value:
1.2.57.463.g4f748c64
(PID) Process:(7164) SpWebInst0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:Version
Value:
1.2.57.463.g4f748c64
Executable files
19
Suspicious files
265
Text files
30
Unknown types
0

Dropped files

PID
Process
Filename
Type
6220SpotifySetup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\SpotifyFullSetupX64[1].exe
MD5:
SHA256:
6220SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\SpWebInst0.exe
MD5:
SHA256:
6220SpotifySetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_F0947D48684F966563488FC691A72B52der
MD5:05C8CE8A8B1A590ACF350AF667BB6006
SHA256:EF8EB383F1E57B3CA1DBC4655CE59FF6F139A962AAEB54335B0D18592EE850BF
7164SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_7164_32_~binary
MD5:A6E41222290C96728E1CAF9C4954A012
SHA256:9C9BB00BB3E21A2C7668224772465CB4333258698D3522BE9D42230131226A4D
7164SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_7164_2_~compressed
MD5:1B5DCE1D0B53C0C50F56E8D85BF44E67
SHA256:1A8E3F42E2BAAC244D56D85F3F3D8EDD59CDC3744CAF76AB8B0D69FC4BE18DC4
7164SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_7164_0_~compressed
MD5:2F9DC7434FBE56088EB69DCAB57997D3
SHA256:2810B0004E0D0039D6B260624F6B0BA2B5C0D0663A9E6667667781ADF528816E
7164SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_7164_6_~binary
MD5:F762A7806B3252CC6223F08495F36278
SHA256:5B5164566895BBDA8B85F6002F3E29604602EADC61AFBE0D2E09223BFB43B0BD
7164SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_7164_10_~binary
MD5:274C53749D7A6CC2CF1357EBE51B38B5
SHA256:E0250FFF743B9AC2DBDB3709DA425528D94A19B733ED490CD2EF596870F37928
6220SpotifySetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_F0947D48684F966563488FC691A72B52binary
MD5:E5D8277A3C7D2C9B521FBF4B258BEFFE
SHA256:6ECDE0BD70E58A92E12F5AD471F176ACFC646CFCACF9A9F78421DD77832063DB
7164SpWebInst0.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_7164_12_~binary
MD5:97B9A49F4F28B2945696CECDB7E7864B
SHA256:88737BAAB0B07594547E3BDB1C1989BCE63351A7AA131AC201C2EB0530D9C2DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
44
DNS requests
47
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
23.207.210.91:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5880
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5880
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6172
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6220
SpotifySetup.exe
GET
200
151.101.194.133:80
http://ocsp2.globalsign.com/rootr3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEQCCFEE7BXGhpoEKjlIOBXTx
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
92.123.104.54:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.207.210.91:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6220
SpotifySetup.exe
199.232.210.248:443
download.scdn.co
FASTLY
US
whitelisted
6220
SpotifySetup.exe
151.101.194.133:80
ocsp2.globalsign.com
FASTLY
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.212.142
whitelisted
www.bing.com
  • 92.123.104.54
  • 92.123.104.64
  • 92.123.104.62
  • 92.123.104.41
  • 92.123.104.63
  • 92.123.104.44
  • 92.123.104.6
  • 92.123.104.10
  • 92.123.104.65
  • 92.123.104.31
  • 92.123.104.26
  • 92.123.104.30
  • 92.123.104.28
  • 92.123.104.36
  • 92.123.104.32
  • 92.123.104.29
  • 92.123.104.27
  • 92.123.104.33
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
crl.microsoft.com
  • 23.207.210.91
  • 23.207.210.90
  • 23.207.210.82
  • 23.207.210.74
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
download.scdn.co
  • 199.232.210.248
  • 199.232.214.248
whitelisted
ocsp2.globalsign.com
  • 151.101.194.133
  • 151.101.2.133
  • 151.101.130.133
  • 151.101.66.133
whitelisted
go.microsoft.com
  • 69.192.162.125
whitelisted
login.live.com
  • 20.190.159.71
  • 40.126.31.2
  • 20.190.159.75
  • 20.190.159.128
  • 20.190.159.23
  • 20.190.159.73
  • 40.126.31.3
  • 40.126.31.131
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted

Threats

PID
Process
Class
Message
3540
Spotify.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
3540
Spotify.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
3540
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3540
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3540
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3540
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3540
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3540
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3540
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3540
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info