URL:

https://www.prolific.com.tw/US/ShowProduct.aspx?p_id=225&pcid=41

Full analysis: https://app.any.run/tasks/a3ad0c64-5897-4c3c-a073-bf013f12dc80
Verdict: Malicious activity
Analysis date: December 23, 2024, 09:21:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MD5:

1B1FDFB03A2EF66A5C6696E0A49FE85A

SHA1:

A17D1EF29CE3715C0AAF0E0ECFAC7F1A1D920A28

SHA256:

50ABD88D4A53EF5D4512AFE66001B182830F80A98A23343AF5C2BD6A8E82A4D2

SSDEEP:

3:N8DSLoJMQcG8k7aBJ/1MuXl9y:2OLVQcG8ksGuq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6796)
    • Executable content was dropped or overwritten

      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7028)
      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
      • dpinst64.exe (PID: 3736)
      • drvinst.exe (PID: 4764)
      • drvinst.exe (PID: 2940)
    • Searches for installed software

      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
    • Process drops legitimate windows executable

      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
    • Drops a system driver (possible attempt to evade defenses)

      • dpinst64.exe (PID: 3736)
      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
      • drvinst.exe (PID: 2940)
      • drvinst.exe (PID: 4764)
    • Creates a software uninstall entry

      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6892)
    • Starts a Microsoft application from unusual location

      • dpinst64.exe (PID: 3736)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2940)
      • drvinst.exe (PID: 4764)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 2940)
      • drvinst.exe (PID: 4764)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 4128)
    • Checks supported languages

      • SearchApp.exe (PID: 5064)
      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7028)
      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
      • dpinst64.exe (PID: 3736)
      • ISBEW64.exe (PID: 7144)
      • ISBEW64.exe (PID: 7132)
      • ISBEW64.exe (PID: 5652)
      • ISBEW64.exe (PID: 1792)
      • ISBEW64.exe (PID: 6032)
      • drvinst.exe (PID: 2940)
      • PL2303G_HandlePortNumber.exe (PID: 5544)
      • PL23XX_checkChipVersion_v1021.exe (PID: 4872)
      • drvinst.exe (PID: 4764)
    • The process uses the downloaded file

      • chrome.exe (PID: 4128)
      • chrome.exe (PID: 6952)
      • WinRAR.exe (PID: 6796)
    • The sample compiled with english language support

      • chrome.exe (PID: 4128)
      • WinRAR.exe (PID: 6796)
      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7028)
      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
      • drvinst.exe (PID: 2940)
      • dpinst64.exe (PID: 3736)
      • drvinst.exe (PID: 4764)
    • Reads Microsoft Office registry keys

      • chrome.exe (PID: 4128)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6796)
    • Create files in a temporary directory

      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7028)
      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
      • dpinst64.exe (PID: 3736)
    • Reads the computer name

      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
      • dpinst64.exe (PID: 3736)
      • ISBEW64.exe (PID: 7132)
      • ISBEW64.exe (PID: 1792)
      • PL2303G_HandlePortNumber.exe (PID: 5544)
    • The sample compiled with arabic language support

      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
    • The sample compiled with chinese language support

      • dpinst64.exe (PID: 3736)
      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
      • drvinst.exe (PID: 2940)
      • drvinst.exe (PID: 4764)
    • Manages system restore points

      • SrTasks.exe (PID: 1868)
    • Creates files in the program directory

      • PL23XX-M_LogoDriver_Setup_4300_20240704.exe (PID: 7112)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 2940)
      • drvinst.exe (PID: 4764)
      • SearchApp.exe (PID: 5064)
    • Reads the software policy settings

      • SearchApp.exe (PID: 5064)
    • Manual execution by a user

      • PL2303G_HandlePortNumber.exe (PID: 5544)
      • PL23XX_checkChipVersion_v1021.exe (PID: 4872)
      • PL2303G_HandlePortNumber.exe (PID: 4512)
    • Process checks computer location settings

      • SearchApp.exe (PID: 5064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
177
Monitored processes
40
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs winrar.exe pl23xx-m_logodriver_setup_4300_20240704.exe no specs pl23xx-m_logodriver_setup_4300_20240704.exe pl23xx-m_logodriver_setup_4300_20240704.exe isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs isbew64.exe no specs SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs isbew64.exe no specs dpinst64.exe drvinst.exe drvinst.exe chrome.exe no specs SPPSurrogate no specs pl2303g_handleportnumber.exe no specs pl2303g_handleportnumber.exe chrome.exe no specs pl23xx_checkchipversion_v1021.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs searchapp.exe

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\Users\admin\AppData\Local\Temp\Rar$EXa6796.2755\PL23XX_Prolific_DriverInstaller_v4300\PL23XX-M_LogoDriver_Setup_4300_20240704.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6796.2755\PL23XX_Prolific_DriverInstaller_v4300\PL23XX-M_LogoDriver_Setup_4300_20240704.exeWinRAR.exe
User:
admin
Company:
Prolific
Integrity Level:
MEDIUM
Description:
InstallScript Setup Launcher Unicode
Exit code:
3221226540
Version:
4.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6796.2755\pl23xx_prolific_driverinstaller_v4300\pl23xx-m_logodriver_setup_4300_20240704.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
848"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=3272 --field-trial-handle=1856,i,14681318912232876168,11902918255588179206,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1792C:\Users\admin\AppData\Local\Temp\{89450A8D-88A7-4738-910C-7479BC020CAF}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{71C0A99C-C5B8-41C9-9C2F-EA676972DA02}C:\Users\admin\AppData\Local\Temp\{89450A8D-88A7-4738-910C-7479BC020CAF}\ISBEW64.exePL23XX-M_LogoDriver_Setup_4300_20240704.exe
User:
admin
Company:
Flexera
Integrity Level:
HIGH
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
28.0.759
Modules
Images
c:\users\admin\appdata\local\temp\{89450a8d-88a7-4738-910c-7479bc020caf}\isbew64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
1868C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exedllhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2040"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=3524 --field-trial-handle=1856,i,14681318912232876168,11902918255588179206,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2940DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{7b01a2bf-e966-e44f-9f63-280e514b42f5}\plser.inf" "9" "45138533b" "0000000000000174" "WinSta0\Default" "00000000000001D4" "208" "c:\users\admin\appdata\local\temp\{89450a8d-88a7-4738-910c-7479bc020caf}\{618d450a-b26a-4cb2-abca-f59c209b312e}\wa"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
3568C:\Users\admin\AppData\Local\Temp\{89450A8D-88A7-4738-910C-7479BC020CAF}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{81314394-B2C0-4DAD-B69E-F055D1B8DF35}C:\Users\admin\AppData\Local\Temp\{89450A8D-88A7-4738-910C-7479BC020CAF}\ISBEW64.exePL23XX-M_LogoDriver_Setup_4300_20240704.exe
User:
admin
Company:
Flexera
Integrity Level:
HIGH
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
28.0.759
Modules
Images
c:\users\admin\appdata\local\temp\{89450a8d-88a7-4738-910c-7479bc020caf}\isbew64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
3736C:\Users\admin\AppData\Local\Temp\{89450A8D-88A7-4738-910C-7479BC020CAF}\{618D450A-B26A-4CB2-ABCA-F59C209B312E}\dpinst64.exe /PATH C:\Users\admin\AppData\Local\Temp\{89450A8D-88A7-4738-910C-7479BC020CAF}\{618D450A-B26A-4CB2-ABCA-F59C209B312E}\WA\ /SW /LM /SAC:\Users\admin\AppData\Local\Temp\{89450A8D-88A7-4738-910C-7479BC020CAF}\{618D450A-B26A-4CB2-ABCA-F59C209B312E}\dpinst64.exe
PL23XX-M_LogoDriver_Setup_4300_20240704.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
512
Version:
2.1
Modules
Images
c:\users\admin\appdata\local\temp\{89450a8d-88a7-4738-910c-7479bc020caf}\{618d450a-b26a-4cb2-abca-f59c209b312e}\dpinst64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4128"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "https://www.prolific.com.tw/US/ShowProduct.aspx?p_id=225&pcid=41"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4420C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
Total events
20 995
Read events
20 663
Write events
295
Delete events
37

Modification events

(PID) Process:(4128) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(4128) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(4128) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(4128) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(4128) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(5064) SearchApp.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.search_cw5n1h2txyewy\Internet Explorer\DOMStorage\bing.com
Operation:writeName:Total
Value:
929
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\ConstraintIndex
Operation:writeName:CurrentConstraintIndexCabPath
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0049006E007000750074005F007B00380033003200620036003800640032002D0037006600650032002D0034006500370031002D0061003300610064002D003200360031003600360062003600350036006500630036007D0000002E28680A1C55DB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex
Operation:writeName:LatestConstraintIndexFolder
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0041007000700073005F007B00620065006500610036003500340064002D0066003200620037002D0034006200380064002D0061003100640035002D006200620037003200370061006400610034003800370063007D0000002E28680A1C55DB01
(PID) Process:(5064) SearchApp.exeKey:\REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex
Operation:writeName:LastConstraintIndexBuildCompleted
Value:
3538680A1C55DB012E28680A1C55DB01
(PID) Process:(5064) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex
Operation:writeName:CurrentConstraintIndexCabPath
Value:
C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{832b68d2-7fe2-4e71-a3ad-26166b656ec6}
Executable files
112
Suspicious files
208
Text files
93
Unknown types
6

Dropped files

PID
Process
Filename
Type
4128chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF136d34.TMP
MD5:
SHA256:
4128chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF136d53.TMP
MD5:
SHA256:
4128chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
4128chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF136d63.TMP
MD5:
SHA256:
4128chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
4128chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF136d73.TMP
MD5:
SHA256:
4128chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF136d73.TMP
MD5:
SHA256:
4128chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
4128chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
4128chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
79
DNS requests
59
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
314 b
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
6952
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
US
binary
1.09 Kb
whitelisted
5712
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
6952
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
US
whitelisted
5728
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
US
binary
471 b
whitelisted
6952
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
US
binary
205 b
whitelisted
6952
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
US
binary
3.88 Kb
whitelisted
6952
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
US
binary
8.79 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5064
SearchApp.exe
104.126.37.137:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
640
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4128
chrome.exe
239.255.255.250:1900
whitelisted
6352
chrome.exe
173.194.69.84:443
accounts.google.com
GOOGLE
US
whitelisted
6352
chrome.exe
210.61.208.203:443
www.prolific.com.tw
Data Communication Business Group
TW
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 104.126.37.137
  • 104.126.37.147
  • 104.126.37.155
  • 104.126.37.154
  • 104.126.37.153
  • 104.126.37.146
  • 104.126.37.145
  • 104.126.37.129
  • 104.126.37.130
  • 2.23.209.181
  • 2.23.209.183
  • 2.23.209.176
  • 2.23.209.161
  • 2.23.209.179
  • 2.23.209.182
  • 2.23.209.177
  • 2.23.209.175
  • 2.23.209.160
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.206
whitelisted
www.prolific.com.tw
  • 210.61.208.203
whitelisted
accounts.google.com
  • 173.194.69.84
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
www.googletagmanager.com
  • 216.58.206.72
whitelisted
www.google.com
  • 216.58.206.36
  • 172.217.16.196
whitelisted

Threats

No threats detected
No debug info