File name:

Setup.exe

Full analysis: https://app.any.run/tasks/7ebe9c60-a654-47bb-84e8-72d42f89f4b5
Verdict: Malicious activity
Analysis date: April 22, 2026, 16:03:41
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

3527691431512FC1E9F86FE523CA624E

SHA1:

9E042DABE32F48A01A1EAC7452F515514F1EA50E

SHA256:

56ABF6B041C19B240BB415C54F2B53CA88955BABCC3E05CC71FD5CC0953B303A

SSDEEP:

98304:o+cD4dnBozaWk5B3e4Bk5zwuqRr5dx/lDOe8HgzFdYUQiW2GaYUhP8mdYPtu+inS:JIY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • DPInst64.exe (PID: 3324)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup.exe (PID: 7260)
      • Setup.exe (PID: 2524)
      • Setup.tmp (PID: 2456)
      • DPInst64.exe (PID: 3324)
    • Reads the Windows owner or organization settings

      • Setup.tmp (PID: 2456)
    • Drops a system driver (possible attempt to evade defenses)

      • Setup.tmp (PID: 2456)
      • DPInst64.exe (PID: 3324)
      • drvinst.exe (PID: 7684)
      • drvinst.exe (PID: 1268)
    • Stops a currently running service

      • sc.exe (PID: 2676)
    • Windows service management via SC.EXE

      • sc.exe (PID: 4136)
      • sc.exe (PID: 6208)
    • Creates a new Windows service

      • sc.exe (PID: 5864)
    • Executes as Windows Service

      • AicWifiService.exe (PID: 7428)
    • Restarts service on failure

      • sc.exe (PID: 6140)
  • INFO

    • Create files in a temporary directory

      • Setup.exe (PID: 7260)
      • Setup.exe (PID: 2524)
      • Setup.tmp (PID: 2456)
      • DPInst64.exe (PID: 3324)
    • Checks supported languages

      • Setup.exe (PID: 2524)
      • Setup.exe (PID: 7260)
      • Setup.tmp (PID: 8008)
      • Setup.tmp (PID: 2456)
      • drvinst.exe (PID: 1268)
      • AicWifiService.exe (PID: 7428)
      • DPInst64.exe (PID: 3324)
      • drvinst.exe (PID: 7684)
      • devcon.exe (PID: 4480)
    • Reads the computer name

      • Setup.tmp (PID: 8008)
      • Setup.tmp (PID: 2456)
      • drvinst.exe (PID: 7684)
      • AicWifiService.exe (PID: 7428)
      • drvinst.exe (PID: 1268)
      • DPInst64.exe (PID: 3324)
    • Reads security settings of Internet Explorer

      • Setup.tmp (PID: 8008)
    • Process checks computer location settings

      • Setup.tmp (PID: 8008)
    • The sample compiled with russian language support

      • Setup.tmp (PID: 2456)
    • The sample compiled with english language support

      • Setup.tmp (PID: 2456)
    • Reads product name

      • Setup.tmp (PID: 2456)
    • Creates a software uninstall entry

      • Setup.tmp (PID: 2456)
    • Reads Environment values

      • Setup.tmp (PID: 2456)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 7684)
      • drvinst.exe (PID: 1268)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 43008
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.10
ProductVersionNumber: 1.0.0.10
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Ugreen
FileDescription: AicDriver Setup
FileVersion: 1.0.0.10
LegalCopyright: Ugreen
OriginalFileName:
ProductName: Setup
ProductVersion: 1.0.0.10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
160
Monitored processes
20
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start setup.exe setup.tmp no specs setup.exe setup.tmp sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs dpinst64.exe drvinst.exe no specs drvinst.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs aicwifiservice.exe no specs sc.exe no specs conhost.exe no specs devcon.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
488\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exedevcon.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1268DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{78cda025-77f9-ea40-93ee-e48da1d02bf8}\aicusbwifi.inf" "9" "48110a273" "0000000000000200" "WinSta0\Default" "0000000000000204" "208" "c:\program files\ugreen\win10_x64"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2456"C:\Users\admin\AppData\Local\Temp\is-67LS1.tmp\Setup.tmp" /SL5="$17028C,2373743,785920,C:\Users\admin\AppData\Local\Temp\Setup.exe" /SPAWNWND=$7025E /NOTIFYWND=$90302 C:\Users\admin\AppData\Local\Temp\is-67LS1.tmp\Setup.tmp
Setup.exe
User:
admin
Company:
Ugreen
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-67ls1.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
2524"C:\Users\admin\AppData\Local\Temp\Setup.exe" /SPAWNWND=$7025E /NOTIFYWND=$90302 C:\Users\admin\AppData\Local\Temp\Setup.exe
Setup.tmp
User:
admin
Company:
Ugreen
Integrity Level:
HIGH
Description:
AicDriver Setup
Exit code:
0
Version:
1.0.0.10
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2676"C:\WINDOWS\system32\sc.exe" stop AicWifiServiceC:\Windows\System32\sc.exeSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
1060
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
2812\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3324"C:\Program Files\Ugreen\win10_x64\DPInst64.exe" /A /SW /SAC:\Program Files\Ugreen\win10_x64\DPInst64.exe
Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
512
Version:
2.1
Modules
Images
c:\program files\ugreen\win10_x64\dpinst64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3416\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4136"C:\WINDOWS\system32\sc.exe" config AicWifiService start= demandC:\Windows\System32\sc.exeSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
1060
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
4480"C:\Program Files\Ugreen\tool\devcon.exe" /rescanC:\Program Files\Ugreen\tool\devcon.exeSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Device Console
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\program files\ugreen\tool\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
7 068
Read events
7 040
Write events
28
Delete events
0

Modification events

(PID) Process:(2456) Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A93E57B-A092-48B9-9A5A-7F7218FF8F29}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\Ugreen
(PID) Process:(2456) Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A93E57B-A092-48B9-9A5A-7F7218FF8F29}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Ugreen\
(PID) Process:(2456) Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A93E57B-A092-48B9-9A5A-7F7218FF8F29}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
Ugreen
(PID) Process:(2456) Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A93E57B-A092-48B9-9A5A-7F7218FF8F29}_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(2456) Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A93E57B-A092-48B9-9A5A-7F7218FF8F29}_is1
Operation:writeName:Inno Setup: Setup Type
Value:
custom
(PID) Process:(2456) Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A93E57B-A092-48B9-9A5A-7F7218FF8F29}_is1
Operation:writeName:Inno Setup: Selected Components
Value:
(PID) Process:(2456) Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A93E57B-A092-48B9-9A5A-7F7218FF8F29}_is1
Operation:writeName:Inno Setup: Deselected Components
Value:
(PID) Process:(2456) Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A93E57B-A092-48B9-9A5A-7F7218FF8F29}_is1
Operation:writeName:Inno Setup: Language
Value:
en
(PID) Process:(2456) Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A93E57B-A092-48B9-9A5A-7F7218FF8F29}_is1
Operation:writeName:DisplayName
Value:
Wi-Fi Adapter
(PID) Process:(2456) Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A93E57B-A092-48B9-9A5A-7F7218FF8F29}_is1
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Ugreen\logo.ico
Executable files
46
Suspicious files
52
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
2456Setup.tmpC:\Users\admin\AppData\Local\Temp\is-3CLJ4.tmp\pbfg.pngimage
MD5:0C7C99E6886255F06DAEF595061EB2BB
SHA256:C7F8E22F37156E5345EC3FBF45FF4C4DC8130DADEE30DFCD5A2454BEC7755533
7260Setup.exeC:\Users\admin\AppData\Local\Temp\is-6B8TA.tmp\Setup.tmpexecutable
MD5:7ACE882AC2E54CEFC995C1D34B10A4CF
SHA256:071AE66321133D80D5D8D3DF94C602C9FEE872D0E424B68EE79D4FEA40112F5E
2456Setup.tmpC:\Users\admin\AppData\Local\Temp\is-3CLJ4.tmp\innocallback.dllexecutable
MD5:1C55AE5EF9980E3B1028447DA6105C75
SHA256:6AFA2D104BE6EFE3D9A2AB96DBB75DB31565DAD64DD0B791E402ECC25529809F
2456Setup.tmpC:\Users\admin\AppData\Local\Temp\is-3CLJ4.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
2524Setup.exeC:\Users\admin\AppData\Local\Temp\is-67LS1.tmp\Setup.tmpexecutable
MD5:7ACE882AC2E54CEFC995C1D34B10A4CF
SHA256:071AE66321133D80D5D8D3DF94C602C9FEE872D0E424B68EE79D4FEA40112F5E
2456Setup.tmpC:\Users\admin\AppData\Local\Temp\is-3CLJ4.tmp\pbbg.pngimage
MD5:E1BDAE02B3BC2B20482566E11371E9E2
SHA256:443904C6DB5ED717ED94E5229B332AFBCA9A4AFC33A4EFAB7782E90BDBA6B1EB
2456Setup.tmpC:\Users\admin\AppData\Local\Temp\is-3CLJ4.tmp\wifi.pngimage
MD5:789F87489921DD377E3742795ACA1C75
SHA256:1859F7D5F031219EE7308EBD6123DA9E177BE1A47840D561508057A9068D345D
2456Setup.tmpC:\Program Files\Ugreen\win7_x64\is-59V0J.tmpbinary
MD5:60276C74C5C76CD9555BEC21D3178F1B
SHA256:D0326E7562C858F82C321BAC9BCDE333DA68029A3F9F970E7830879C88C4B6A2
2456Setup.tmpC:\Program Files\Ugreen\win7_x64\is-IJ5MN.tmpbinary
MD5:1071B1F00F19CDD7C2029003ED34CF95
SHA256:92A37BAA9B7CDC0A52F4D0ED8C5472CDCE201399267EC2B661E9EB13ED55A375
2456Setup.tmpC:\Program Files\Ugreen\win7_x64\aicloadfw.infbinary
MD5:1071B1F00F19CDD7C2029003ED34CF95
SHA256:92A37BAA9B7CDC0A52F4D0ED8C5472CDCE201399267EC2B661E9EB13ED55A375
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
29
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
5316
svchost.exe
POST
400
40.126.31.1:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
4784
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
4784
SIHClient.exe
GET
503
135.233.95.135:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
4784
SIHClient.exe
GET
200
20.165.94.54:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
4784
SIHClient.exe
GET
200
74.178.240.61:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
4784
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5316
svchost.exe
POST
400
40.126.31.1:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/FlightSettings/FSService?ProcessorClockSpeed=3094&IsRetailOS=1&OEMManufacturerName=DELL&FlightingPolicyValue=3&EnablePreviewBuilds=4294967295&OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&ManagePreviewBuilds=3&BranchReadinessLevelSource=0&AttrDataVer=186&ProcessorCores=6&BranchReadinessLevelRaw=16&TotalPhysicalRAM=6144&TPMVersion=0&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&DeviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&App=FSS&AppVer=10.0&SmartActiveHoursState=1&ActiveHoursStart=20&SecureBootCapable=0&ActiveHoursEnd=13&DeviceFamily=Windows.Desktop
US
text
87.3 Kb
whitelisted
5316
svchost.exe
POST
400
40.126.31.1:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5484
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
5532
SearchApp.exe
2.16.241.212:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
5484
svchost.exe
23.216.77.25:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
5532
SearchApp.exe
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
5484
svchost.exe
23.59.18.102:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
5532
SearchApp.exe
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 142.251.110.101
  • 142.251.110.100
  • 142.251.110.138
  • 142.251.110.113
  • 142.251.110.102
  • 142.251.110.139
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
www.bing.com
  • 2.16.241.212
  • 2.16.241.206
  • 2.16.241.222
  • 2.16.241.219
  • 2.16.241.205
  • 2.16.241.218
  • 2.16.241.223
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
crl.microsoft.com
  • 23.216.77.25
  • 23.216.77.18
  • 23.216.77.14
whitelisted
www.microsoft.com
  • 23.59.18.102
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.31.1
  • 20.190.159.0
  • 20.190.159.128
  • 20.190.159.68
  • 40.126.31.129
  • 20.190.159.71
  • 40.126.31.0
  • 20.190.159.75
whitelisted

Threats

No threats detected
No debug info