File name:

New Agreement Document 2025.com

Full analysis: https://app.any.run/tasks/cd24b685-269b-4fd3-a720-e419a22e0c3e
Verdict: Malicious activity
Analysis date: February 12, 2025, 15:53:49
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

569CD75E5907FD52FCAB645BCA570946

SHA1:

CBA256EA7B1FE276E73EC45C120A5326FAE4659E

SHA256:

5692D52FB5161FAF27BF7375F72A4AF274571EA4F86E542B5A094EBA5A8529E1

SSDEEP:

98304:pB0tvnOUylgPVQcegXB42OriAV9B3gIgQBWyOeWw+5hInLsiHF4Lqi4/XbTa4ES/:Uel/t3F

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • New Agreement Document 2025.com.exe (PID: 6236)
      • Lightshot.exe (PID: 6344)
    • Process drops legitimate windows executable

      • New Agreement Document 2025.com.exe (PID: 6236)
    • Creates a software uninstall entry

      • New Agreement Document 2025.com.exe (PID: 6236)
    • The process executes via Task Scheduler

      • control.exe (PID: 4504)
      • control.exe (PID: 904)
      • control.exe (PID: 6864)
    • Uses RUNDLL32.EXE to load library

      • control.exe (PID: 4504)
      • control.exe (PID: 6864)
      • control.exe (PID: 904)
    • Connects to unusual port

      • rundll32.exe (PID: 6012)
    • There is functionality for taking screenshot (YARA)

      • rundll32.exe (PID: 6012)
  • INFO

    • Reads the computer name

      • New Agreement Document 2025.com.exe (PID: 6236)
      • Lightshot.exe (PID: 6344)
      • identity_helper.exe (PID: 6076)
      • identity_helper.exe (PID: 7840)
    • Checks supported languages

      • New Agreement Document 2025.com.exe (PID: 6236)
      • _tinreg32.exe (PID: 6312)
      • Lightshot.exe (PID: 6344)
      • identity_helper.exe (PID: 6076)
      • identity_helper.exe (PID: 7840)
    • Creates files or folders in the user directory

      • New Agreement Document 2025.com.exe (PID: 6236)
      • Lightshot.exe (PID: 6344)
    • Reads Microsoft Office registry keys

      • New Agreement Document 2025.com.exe (PID: 6236)
    • Reads Environment values

      • New Agreement Document 2025.com.exe (PID: 6236)
      • identity_helper.exe (PID: 7840)
      • identity_helper.exe (PID: 6076)
    • Create files in a temporary directory

      • New Agreement Document 2025.com.exe (PID: 6236)
    • Manual execution by a user

      • Lightshot.exe (PID: 6344)
      • msedge.exe (PID: 6412)
      • firefox.exe (PID: 1192)
    • Reads the machine GUID from the registry

      • Lightshot.exe (PID: 6344)
    • Reads security settings of Internet Explorer

      • control.exe (PID: 4504)
      • control.exe (PID: 904)
      • control.exe (PID: 6864)
    • Application launched itself

      • firefox.exe (PID: 1192)
      • firefox.exe (PID: 1216)
      • msedge.exe (PID: 8080)
      • msedge.exe (PID: 6412)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 1216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:29 14:51:45+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 8192
InitializedDataSize: 2030592
UninitializedDataSize: -
EntryPoint: 0x15ad
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2025.2.10.958
ProductVersionNumber: 5.5.0.4
FileFlagsMask: 0x003f
FileFlags: Special build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
ProductName: LigthShoot
ProductVersion: 5.5.0.4
CompanyName: Skillbrains
LegalCopyright: Copyright (c) 2025 Skillbrains
Email: -
WebSite: -
FileDescription: Installer for LigthShoot
FileVersion: 2025.2.10.958
OriginalFileName: LigthShoot-Setup.exe
InternalName: TSULoader
Comments: WinNT (x86) Unicode Lib Rel
ProductCode: {C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}
PackageCode: {A3F73EF0-AB26-44E7-74F8-0505ED09F546}
Arguments: -
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
211
Monitored processes
75
Malicious processes
0
Suspicious processes
4

Behavior graph

Click at the process to see the details
start new agreement document 2025.com.exe _tinreg32.exe no specs lightshot.exe control.exe no specs rundll32.exe no specs rundll32.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs control.exe no specs rundll32.exe no specs rundll32.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs control.exe no specs rundll32.exe no specs rundll32.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
440"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2144 -parentBuildID 20240213221259 -prefsHandle 2136 -prefMapHandle 2132 -prefsLen 31031 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {0c89def9-4d66-49c4-bed6-8285b0426401} 1216 "\\.\pipe\gecko-crash-server-pipe.1216" 2be29081d10 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
904"C:\WINDOWS\system32\control.EXE" C:\Users\admin\AppData\Roaming\SkyVault\Skymage.dllC:\Windows\System32\control.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Control Panel
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\control.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1192"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
1216"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1220"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6692 --field-trial-handle=2360,i,5510696813202285904,18288910317468634611,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1580"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=5204 --field-trial-handle=2328,i,3626153319472206535,2489346361595411402,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1752"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=1308 --field-trial-handle=2360,i,5510696813202285904,18288910317468634611,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2072"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5312 --field-trial-handle=2328,i,3626153319472206535,2489346361595411402,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2076"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3444 --field-trial-handle=2328,i,3626153319472206535,2489346361595411402,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2120"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5048 -childID 5 -isForBrowser -prefsHandle 5052 -prefMapHandle 5056 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {5b16e131-9714-40c7-a0ee-d48767a0e379} 1216 "\\.\pipe\gecko-crash-server-pipe.1216" 2be3f640150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
21 133
Read events
21 099
Write events
33
Delete events
1

Modification events

(PID) Process:(6236) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}
Operation:writeName:TizPath
Value:
C:\Users\admin\AppData\Local\Temp\New Agreement Document 2025.com.exe
(PID) Process:(6236) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\States
Operation:delete valueName:Added_20250210095040
Value:
(PID) Process:(6236) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\States
Operation:writeName:Product
Value:
4
(PID) Process:(6236) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
105
(PID) Process:(6412) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6412) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6412) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6412) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6412) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
0E4C58408A8C2F00
(PID) Process:(6412) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
D54252408A8C2F00
Executable files
66
Suspicious files
990
Text files
175
Unknown types
1

Dropped files

PID
Process
Filename
Type
6236New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\Ligth.jpgimage
MD5:2A8AC2E8CFA995C0F572B6201B995EB4
SHA256:F7F20CECB699FD114297ADEED134FD256961FF8D6628154E4783D171C05B7672
6236New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\TsuAC5CA842.dllexecutable
MD5:DD804E04C89BB795545152159F8F5BCB
SHA256:AA7D394C0245D95B7D65B7B04CF45966F145186655A1E01BBE02B6F33B0D7E6C
6236New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\C507C861.datbinary
MD5:442494A43FDE46CF784860193FD8FBEF
SHA256:2F41B5A2B458AD788B3A16F749D848DD398C7FD9B8E9D55E51130E8AD41420F1
6236New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\Setup.exeexecutable
MD5:4128E1764395387ACFB4586913EB47FD
SHA256:81F539598A6481CDF5414A4DC26EC4B05EFBE9FFCB07A84DE02673F0C9A8AA90
6236New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\C507C861\Readme.txttext
MD5:3154E35EF76E0C11D800C1B3C8C7F20B
SHA256:F70BB349BA773E82648109CBCA5766B61FFD6ACE30F6388719F00865134F79D4
6236New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\C507C861\Setup.exeexecutable
MD5:4128E1764395387ACFB4586913EB47FD
SHA256:81F539598A6481CDF5414A4DC26EC4B05EFBE9FFCB07A84DE02673F0C9A8AA90
6236New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\net.dll._tmexecutable
MD5:E68D7EAD1C2F5970541346AC8CB6F4FB
SHA256:45B2C27A4345D789287539DD82C9F85AC9324D01825F6E2E0C2CDD4C4172C038
6236New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\C507C861\Setup.icoimage
MD5:6234FD14AA6A9D4645ADA275EEEA061C
SHA256:47E5F3DC05BBD7464B1373DE6F9B8D9129A348EB2956547F58D3B627337716AA
6236New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_tinreg64.exeexecutable
MD5:49175CE08D38ED7CCC43891A0232F9ED
SHA256:5F670EA7561637AA4885494D3A6264E549C6A62F5E6B753DC1944579123E6C57
6236New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_Setup.dllexecutable
MD5:3569FA229BD51231DB327C43EF14C6D5
SHA256:E47C195AA55701A30A8196781EA5B321C8DB3CC583B6C9EE562C9DC9477EE9A1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
48
TCP/UDP connections
152
DNS requests
210
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6316
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6316
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6828
msedge.exe
GET
304
23.54.109.203:80
http://cacerts.digicert.com/DigiCertGlobalRootG2.crt
unknown
whitelisted
3732
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1488
svchost.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1488
svchost.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1216
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
1216
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
2.19.96.40:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1488
svchost.exe
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1488
svchost.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
1076
svchost.exe
2.19.106.8:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.160.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.19.96.40
  • 2.19.96.48
  • 2.19.96.56
  • 2.19.96.27
  • 2.19.96.26
  • 2.19.96.49
  • 2.19.96.51
  • 2.19.96.43
  • 2.19.96.32
  • 104.126.37.136
  • 104.126.37.144
  • 104.126.37.131
  • 104.126.37.139
  • 104.126.37.146
  • 104.126.37.152
  • 104.126.37.128
  • 104.126.37.130
  • 104.126.37.153
  • 104.126.37.162
  • 104.126.37.160
  • 104.126.37.155
  • 104.126.37.154
  • 104.126.37.123
  • 104.126.37.178
  • 104.126.37.184
  • 104.126.37.171
whitelisted
google.com
  • 142.250.184.206
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 95.101.149.131
  • 184.30.21.171
whitelisted
go.microsoft.com
  • 2.19.106.8
whitelisted
login.live.com
  • 20.190.160.4
  • 40.126.32.140
  • 20.190.160.5
  • 20.190.160.66
  • 20.190.160.64
  • 40.126.32.74
  • 20.190.160.128
  • 20.190.160.20
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
No debug info