File name:

lghub_installer.exe

Full analysis: https://app.any.run/tasks/e4220bea-b9de-4067-8598-2c86696fb12f
Verdict: Malicious activity
Analysis date: May 24, 2025, 23:19:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 8 sections
MD5:

589D4DBD3A35EDF9FE6A99CF0A5B66E9

SHA1:

0F74E5337C2D08B7546EAC8906508B85C6DEFFB5

SHA256:

5457CD50774DDEC45DB87F6A6355DFB0CDA56EDDCED3E1D9E65CB12EE796C2DA

SSDEEP:

393216:WZE0qqFWVSqs8+GiqQ5Q46CtpJuPlP8+GiqQ5m+Sbs9ZUIJRSE89N+X0:aqbnJf468XuNUP+ys9LSkX0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • lghub_installer.exe (PID: 7772)
      • lghub_setup.exe (PID: 7888)
      • vc_redist.arm64.exe (PID: 8176)
    • Reads the date of Windows installation

      • lghub_installer.exe (PID: 7772)
      • lghub_setup.exe (PID: 7888)
    • Process drops legitimate windows executable

      • vc_redist.x64.exe (PID: 8008)
      • lghub_setup.exe (PID: 7888)
      • vc_redist.x86.exe (PID: 8080)
      • vc_redist.arm64.exe (PID: 8152)
      • vc_redist.arm64.exe (PID: 8176)
      • VC_redist.arm64.exe (PID: 7240)
    • Starts a Microsoft application from unusual location

      • vc_redist.x64.exe (PID: 8008)
      • vc_redist.x64.exe (PID: 8032)
      • vc_redist.arm64.exe (PID: 8152)
      • vc_redist.x86.exe (PID: 8080)
      • vc_redist.x86.exe (PID: 8104)
      • VC_redist.arm64.exe (PID: 7240)
      • vc_redist.arm64.exe (PID: 8176)
    • Executable content was dropped or overwritten

      • vc_redist.x64.exe (PID: 8008)
      • lghub_setup.exe (PID: 7888)
      • vc_redist.x64.exe (PID: 8032)
      • vc_redist.x86.exe (PID: 8080)
      • vc_redist.x86.exe (PID: 8104)
      • vc_redist.arm64.exe (PID: 8152)
      • vc_redist.arm64.exe (PID: 8176)
      • VC_redist.arm64.exe (PID: 7240)
    • Searches for installed software

      • vc_redist.x86.exe (PID: 8104)
      • vc_redist.x64.exe (PID: 8032)
      • vc_redist.arm64.exe (PID: 8176)
      • dllhost.exe (PID: 496)
    • Starts itself from another location

      • vc_redist.arm64.exe (PID: 8176)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7248)
  • INFO

    • Checks supported languages

      • lghub_installer.exe (PID: 7772)
      • lghub_setup.exe (PID: 7888)
      • vc_redist.x64.exe (PID: 8008)
      • vc_redist.x64.exe (PID: 8032)
      • vc_redist.x86.exe (PID: 8080)
      • vc_redist.x86.exe (PID: 8104)
      • vc_redist.arm64.exe (PID: 8152)
      • vc_redist.arm64.exe (PID: 8176)
      • VC_redist.arm64.exe (PID: 7240)
    • The sample compiled with english language support

      • lghub_installer.exe (PID: 7772)
      • vc_redist.x64.exe (PID: 8008)
      • vc_redist.x64.exe (PID: 8032)
      • lghub_setup.exe (PID: 7888)
      • vc_redist.x86.exe (PID: 8080)
      • vc_redist.x86.exe (PID: 8104)
      • vc_redist.arm64.exe (PID: 8152)
      • vc_redist.arm64.exe (PID: 8176)
      • VC_redist.arm64.exe (PID: 7240)
    • Create files in a temporary directory

      • lghub_installer.exe (PID: 7772)
      • lghub_setup.exe (PID: 7888)
      • vc_redist.x64.exe (PID: 8032)
      • vc_redist.x86.exe (PID: 8104)
      • vc_redist.arm64.exe (PID: 8176)
    • Process checks computer location settings

      • lghub_installer.exe (PID: 7772)
      • lghub_setup.exe (PID: 7888)
      • vc_redist.arm64.exe (PID: 8176)
    • Reads the computer name

      • lghub_installer.exe (PID: 7772)
      • lghub_setup.exe (PID: 7888)
      • vc_redist.x86.exe (PID: 8104)
      • vc_redist.x64.exe (PID: 8032)
      • vc_redist.arm64.exe (PID: 8176)
      • VC_redist.arm64.exe (PID: 7240)
    • Creates files or folders in the user directory

      • lghub_setup.exe (PID: 7888)
    • Reads the machine GUID from the registry

      • lghub_setup.exe (PID: 7888)
    • Disables trace logs

      • lghub_setup.exe (PID: 7888)
    • Checks proxy server information

      • lghub_setup.exe (PID: 7888)
    • Reads Environment values

      • lghub_setup.exe (PID: 7888)
    • Reads the software policy settings

      • lghub_setup.exe (PID: 7888)
    • Manages system restore points

      • SrTasks.exe (PID: 7452)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7624)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:05:19 17:27:46+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.38
CodeSize: 189952
InitializedDataSize: 58685440
UninitializedDataSize: -
EntryPoint: 0x25d1c
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2025.4.9084.0
ProductVersionNumber: 2025.4.9084.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Logitech, Inc.
FileDescription: Installer
FileVersion: 2025.4.719084
InternalName: Logitech G HUB
LegalCopyright: Copyright © Logitech, Inc. 2025
ProductName: Installer
ProductVersion: 2025.4.719084
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
15
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start lghub_installer.exe no specs lghub_setup.exe vc_redist.x64.exe vc_redist.x64.exe vc_redist.x86.exe vc_redist.x86.exe vc_redist.arm64.exe vc_redist.arm64.exe vc_redist.arm64.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
496C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
6512C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7240"C:\WINDOWS\Temp\{CED8F4BD-AB0E-4519-8365-2875CDE488C0}\.be\VC_redist.arm64.exe" -q -burn.elevated BurnPipe.{304A4A9F-AB7A-470D-846C-C4C887039C5A} {2CCAE144-2D5C-41EB-A0F5-C1C31FD33D78} 8176C:\Windows\Temp\{CED8F4BD-AB0E-4519-8365-2875CDE488C0}\.be\VC_redist.arm64.exe
vc_redist.arm64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2022 Redistributable (Arm64) - 14.40.33810
Exit code:
1633
Version:
14.40.33810.0
Modules
Images
c:\windows\temp\{ced8f4bd-ab0e-4519-8365-2875cde488c0}\.be\vc_redist.arm64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7248C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7376\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7452C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exedllhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7624C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7772"C:\Users\admin\Desktop\lghub_installer.exe" C:\Users\admin\Desktop\lghub_installer.exeexplorer.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
MEDIUM
Description:
Installer
Version:
2025.4.719084
Modules
Images
c:\users\admin\desktop\lghub_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7888"C:\Users\admin\AppData\Local\Temp\ghub-b433-d035-94f2-ff31-1917\lghub_setup.exe" C:\Users\admin\AppData\Local\Temp\ghub-b433-d035-94f2-ff31-1917\lghub_setup.exe
lghub_installer.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
HIGH
Description:
Logitech G HUB
Version:
2025.4.9084
Modules
Images
c:\users\admin\appdata\local\temp\ghub-b433-d035-94f2-ff31-1917\lghub_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
8008"C:\Users\admin\AppData\Local\Temp\ghub-4zevovbf.sdh\vc_redist.x64.exe" /install /quiet /norestartC:\Users\admin\AppData\Local\Temp\ghub-4zevovbf.sdh\vc_redist.x64.exe
lghub_setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127
Exit code:
1638
Version:
14.24.28127.4
Modules
Images
c:\users\admin\appdata\local\temp\ghub-4zevovbf.sdh\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
14 566
Read events
14 332
Write events
208
Delete events
26

Modification events

(PID) Process:(7888) lghub_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\lghub_setup_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7888) lghub_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\lghub_setup_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7888) lghub_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\lghub_setup_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7888) lghub_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\lghub_setup_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7888) lghub_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\lghub_setup_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7888) lghub_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\lghub_setup_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7888) lghub_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\lghub_setup_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(7888) lghub_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\lghub_setup_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7888) lghub_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\lghub_setup_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7888) lghub_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\lghub_setup_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
18
Suspicious files
8
Text files
100
Unknown types
0

Dropped files

PID
Process
Filename
Type
7772lghub_installer.exeC:\Users\admin\AppData\Local\Temp\ghub-b433-d035-94f2-ff31-1917\lghub_setup.exe
MD5:
SHA256:
7888lghub_setup.exeC:\Users\admin\AppData\Local\Temp\0ev14juw.lme\lghub_05_24_2025.logtext
MD5:73A1FE983C069C84B968B82335CE2184
SHA256:CBCE8B2604B0FC0B733A13B5DC293F81D72EB56EF5A4F48841646153E46341C6
7888lghub_setup.exeC:\Users\admin\AppData\Local\Temp\ghub-4zevovbf.sdh\vc_redist.x86.exeexecutable
MD5:24E8177B25C072F4FB0D37496CCDBB34
SHA256:E59AE3E886BD4571A811FE31A47959AE5C40D87C583F786816C60440252CD7EC
7888lghub_setup.exeC:\Users\admin\AppData\Local\Temp\ghub-4zevovbf.sdh\vc_redist.x64.exeexecutable
MD5:BE433764FA9BBE0F2F9C654F6512C9E0
SHA256:40EA2955391C9EAE3E35619C4C24B5AAF3D17AEAA6D09424EE9672AA9372AEED
7888lghub_setup.exeC:\Users\admin\AppData\Local\Temp\ghub-4zevovbf.sdh\vc_redist.arm64.exeexecutable
MD5:8A18E318309DF2DDE09402720131DB1A
SHA256:15B8F5B2106DC7A7BD83AB57B796770E0F4ECB891AD19BF655C9D6A9DA650AD2
8032vc_redist.x64.exeC:\Windows\Temp\{49EF3C5D-103E-4015-ADA9-B67BAB4AD3C1}\.ba\logo.pngimage
MD5:D6BD210F227442B3362493D046CEA233
SHA256:335A256D4779EC5DCF283D007FB56FD8211BBCAF47DCD70FE60DED6A112744EF
8032vc_redist.x64.exeC:\Windows\Temp\{49EF3C5D-103E-4015-ADA9-B67BAB4AD3C1}\.ba\wixstdba.dllexecutable
MD5:EAB9CAF4277829ABDF6223EC1EFA0EDD
SHA256:A4EFBDB2CE55788FFE92A244CB775EFD475526EF5B61AD78DE2BCDFADDAC7041
8008vc_redist.x64.exeC:\Windows\Temp\{6F9E39B3-FA56-46EE-9DF6-E23E342F55A7}\.cr\vc_redist.x64.exeexecutable
MD5:94970FC3A8ED7B9DE44F4117419CE829
SHA256:DE1ACBB1DF68A39A5B966303AC1B609DDE2688B28EBF3EBA8D2ADEEB3D90BF5E
8032vc_redist.x64.exeC:\Windows\Temp\{49EF3C5D-103E-4015-ADA9-B67BAB4AD3C1}\.ba\thm.xmlxml
MD5:F62729C6D2540015E072514226C121C7
SHA256:F13BAE0EC08C91B4A315BB2D86EE48FADE597E7A5440DCE6F751F98A3A4D6916
8032vc_redist.x64.exeC:\Windows\Temp\{49EF3C5D-103E-4015-ADA9-B67BAB4AD3C1}\.ba\thm.wxlxml
MD5:FBFCBC4DACC566A3C426F43CE10907B6
SHA256:70400F181D00E1769774FF36BCD8B1AB5FBC431418067D31B876D18CC04EF4CE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
39
TCP/UDP connections
68
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
403
18.245.31.6:443
https://util.logitech.io/brand
unknown
POST
200
34.120.195.249:443
https://o311478.ingest.us.sentry.io/api/4507430762512384/envelope/
unknown
binary
2 b
whitelisted
GET
304
172.202.163.200:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
GET
200
172.202.163.200:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
5164
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
5164
SIHClient.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5164
SIHClient.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
5164
SIHClient.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
unknown
whitelisted
5164
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5164
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.2.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7888
lghub_setup.exe
34.120.195.249:443
o311478.ingest.us.sentry.io
GOOGLE-CLOUD-PLATFORM
US
whitelisted
7888
lghub_setup.exe
18.245.31.110:443
util.logitech.io
US
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5164
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5164
SIHClient.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5164
SIHClient.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 172.217.23.110
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 4.207.247.138
whitelisted
o311478.ingest.us.sentry.io
  • 34.120.195.249
whitelisted
util.logitech.io
  • 18.245.31.110
  • 18.245.31.6
  • 18.245.31.9
  • 18.245.31.2
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
  • 23.216.77.42
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted

Threats

No threats detected
No debug info