File name:

Вооstаррег 8.0.3-х64.rar

Full analysis: https://app.any.run/tasks/35c240ff-de1b-489b-8a86-e25d603403f7
Verdict: Malicious activity
Analysis date: October 07, 2025, 19:30:19
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

6602FB15F00C35143069CEB901BA2E62

SHA1:

AF2351A9957B1F59456659E3B16DFC4D115A9E41

SHA256:

577DD0804D923125C7CD510F76ADC253C2C6DC86E4F0C0D22E98E463C82B1AF8

SSDEEP:

98304:Fe/EDrGReKRQwxCUIpxoZGLUGdGwbRFZ/Jjax6XJQpcXYOFUP8IRC+S5tU9CKNOD:lfOJsCo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2364)
    • Starts a Microsoft application from unusual location

      • Bootstrapper.exe (PID: 1408)
      • Bootstrapper.exe (PID: 7608)
      • Bootstrapper.exe (PID: 2896)
      • Bootstrapper.exe (PID: 1836)
      • Bootstrapper.exe (PID: 7036)
      • Bootstrapper.exe (PID: 7952)
      • Bootstrapper.exe (PID: 4256)
      • Bootstrapper.exe (PID: 2332)
      • Bootstrapper.exe (PID: 6940)
      • Bootstrapper.exe (PID: 2224)
      • Bootstrapper.exe (PID: 4800)
      • Bootstrapper.exe (PID: 7776)
      • Bootstrapper.exe (PID: 5548)
      • Bootstrapper.exe (PID: 4744)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 2364)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2364)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 2944)
      • BackgroundTransferHost.exe (PID: 3404)
      • BackgroundTransferHost.exe (PID: 6916)
      • BackgroundTransferHost.exe (PID: 3572)
      • BackgroundTransferHost.exe (PID: 4176)
      • notepad.exe (PID: 6124)
      • notepad.exe (PID: 4416)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 3404)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 3404)
      • slui.exe (PID: 7064)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 3404)
      • slui.exe (PID: 7064)
    • Checks supported languages

      • Bootstrapper.exe (PID: 1408)
      • Bootstrapper.exe (PID: 2896)
      • Bootstrapper.exe (PID: 7608)
      • Bootstrapper.exe (PID: 1836)
      • Bootstrapper.exe (PID: 7036)
      • Bootstrapper.exe (PID: 7952)
      • Bootstrapper.exe (PID: 4256)
      • Bootstrapper.exe (PID: 2332)
      • Bootstrapper.exe (PID: 6940)
      • Bootstrapper.exe (PID: 7776)
      • Bootstrapper.exe (PID: 2224)
      • Bootstrapper.exe (PID: 4800)
      • Bootstrapper.exe (PID: 4744)
      • Bootstrapper.exe (PID: 5548)
    • Manual execution by a user

      • Bootstrapper.exe (PID: 1408)
      • Bootstrapper.exe (PID: 7608)
      • Bootstrapper.exe (PID: 2896)
      • Bootstrapper.exe (PID: 1836)
      • Bootstrapper.exe (PID: 7036)
      • notepad.exe (PID: 4416)
      • notepad.exe (PID: 6124)
      • Bootstrapper.exe (PID: 7952)
      • Bootstrapper.exe (PID: 2332)
      • Bootstrapper.exe (PID: 4256)
      • Bootstrapper.exe (PID: 6940)
      • Bootstrapper.exe (PID: 7776)
      • Bootstrapper.exe (PID: 2224)
      • Bootstrapper.exe (PID: 4800)
      • Bootstrapper.exe (PID: 4744)
      • Bootstrapper.exe (PID: 5548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 570489
UncompressedSize: 1466432
OperatingSystem: Win32
ArchivedFileName: Вооstаррег 8.0.3-х64/netх64/Bootstrapper.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
195
Monitored processes
23
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs bootstrapper.exe no specs bootstrapper.exe no specs bootstrapper.exe no specs bootstrapper.exe no specs bootstrapper.exe slui.exe notepad.exe no specs notepad.exe no specs bootstrapper.exe no specs bootstrapper.exe no specs bootstrapper.exe no specs bootstrapper.exe no specs bootstrapper.exe bootstrapper.exe no specs bootstrapper.exe no specs bootstrapper.exe no specs bootstrapper.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1408"C:\Users\admin\Desktop\Вооstаррег 8.0.3-х64\netх64\Bootstrapper.exe" C:\Users\admin\Desktop\Вооstаррег 8.0.3-х64\netх64\Bootstrapper.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221225477
Version:
138.0.3351.121
Modules
Images
c:\users\admin\desktop\вооstаррег 8.0.3-х64\netх64\bootstrapper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1836"C:\Users\admin\Desktop\Вооstаррег 8.0.3-х64\netх64\Bootstrapper.exe" C:\Users\admin\Desktop\Вооstаррег 8.0.3-х64\netх64\Bootstrapper.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221225477
Version:
138.0.3351.121
Modules
Images
c:\users\admin\desktop\вооstаррег 8.0.3-х64\netх64\bootstrapper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\users\admin\desktop\вооstаррег 8.0.3-х64\netх64\msedge_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2224"C:\Users\admin\Desktop\Вооstаррег 8.0.3-х64\netх64\Bootstrapper.exe" C:\Users\admin\Desktop\Вооstаррег 8.0.3-х64\netх64\Bootstrapper.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221225477
Version:
138.0.3351.121
Modules
Images
c:\users\admin\desktop\вооstаррег 8.0.3-х64\netх64\bootstrapper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\users\admin\desktop\вооstаррег 8.0.3-х64\netх64\msedge_elf.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2332"C:\Users\admin\Desktop\Вооstаррег 8.0.3-х64\netх64\Bootstrapper.exe" C:\Users\admin\Desktop\Вооstаррег 8.0.3-х64\netх64\Bootstrapper.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221225477
Version:
138.0.3351.121
Modules
Images
c:\users\admin\desktop\вооstаррег 8.0.3-х64\netх64\bootstrapper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\вооstаррег 8.0.3-х64\netх64\msedge_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2364"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Вооstаррег 8.0.3-х64.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2896"C:\Users\admin\Desktop\Вооstаррег 8.0.3-х64\netх64\Bootstrapper.exe" C:\Users\admin\Desktop\Вооstаррег 8.0.3-х64\netх64\Bootstrapper.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221225477
Version:
138.0.3351.121
Modules
Images
c:\users\admin\desktop\вооstаррег 8.0.3-х64\netх64\bootstrapper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\users\admin\desktop\вооstаррег 8.0.3-х64\netх64\msedge_elf.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2944"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
3404"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
3572"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
4176"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
Total events
10 818
Read events
10 793
Write events
25
Delete events
0

Modification events

(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Вооstаррег 8.0.3-х64.rar
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
5
Suspicious files
27
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2364.7535\Вооstаррег 8.0.3-х64\netх64\locales\locales\af.pakbinary
MD5:C9312FF081E600E5FB4483B46DDD7C23
SHA256:B1987CDCBB8D76598422AA1739A246ED6690DC1B211F950FCBF2F040491ED7A8
2364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2364.7535\Вооstаррег 8.0.3-х64\netх64\locales\locales\sl.pakbinary
MD5:234E628A62F822BD7B3546B91E79CAB2
SHA256:D0415BFA061B36A6EB93FA2C78563448DA8B63C91E0523086C7EB2714933AB99
2364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2364.7535\Вооstаррег 8.0.3-х64\netх64\locales\locales\sv.pakbinary
MD5:C5437BB175FED93E85C5E7CAF76FF352
SHA256:3F0ACF6F6319636C3E72CDC392B7B80AB0CFD8AE1A5A8E319624E4B46BCD3C42
2364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2364.7535\Вооstаррег 8.0.3-х64\netх64\Bootstrapper.exeexecutable
MD5:A1AEEBF67BE219F2DBF9E586AC6F63D4
SHA256:B4D8D2FA3C9ABD1D40D80519CB058E1BB5FC2FC30448D47395DD9DE1CE479A08
2364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2364.7535\Вооstаррег 8.0.3-х64\netх64\locales\hi.pakbinary
MD5:1185163466551AACAE45329C93E92A91
SHA256:EDA355E3785313E3D982C1D3652266DCE1B6E08832056FE58854B825E0712CA5
2364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2364.7535\Вооstаррег 8.0.3-х64\netх64\locales\locales\sr.pakbinary
MD5:AA4E2E54B648F66794F485318651B730
SHA256:D459C1A781DDC344DE76558211983DD07D47E3CA6CACFFB518043BD78DC48FBE
2364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2364.7535\Вооstаррег 8.0.3-х64\netх64\locales\locales\te.pakbinary
MD5:B1A4D471FD8AF54DFB8FF252246BFDE1
SHA256:F53E06181C9FA0F6028906A7388FD4E8F000FFB7277330634462433D34572395
2364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2364.7535\Вооstаррег 8.0.3-х64\netх64\locales\locales\vi.pakbinary
MD5:1B1B14F542BB4A9F014D1801FB2E4007
SHA256:F1602637E7F3E0A908D7A9A3F630B8DD38BFD26704CC64EF432D2C88A1EE7017
2364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2364.7535\Вооstаррег 8.0.3-х64\netх64\locales\resources\app.asar.unpacked\node_modules\get-fonts\binding.nodeexecutable
MD5:EEB1D1EA9FC3F870F292161CFA79850D
SHA256:149BC3824ECBF68F7A892A311E77548EA156963B88DB0590063B50725C9D883C
2364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2364.7535\Вооstаррег 8.0.3-х64\netх64\locales\locales\zh-TW.pakbinary
MD5:14F3F547A54713F91251B38459A096B5
SHA256:280BA35171DFB6A54EFB13FC4DDEDC13A0283A9A6EEBFF4C15275767BEB4BA77
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
37
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4440
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
2600
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
313 b
whitelisted
2120
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
DE
binary
471 b
whitelisted
2184
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
DE
binary
471 b
whitelisted
3404
BackgroundTransferHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
4440
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1260
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6016
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5224
SearchApp.exe
2.16.241.205:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4440
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5224
SearchApp.exe
2.16.241.218:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4440
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2600
backgroundTaskHost.exe
2.16.241.218:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2600
backgroundTaskHost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
www.bing.com
  • 2.16.241.205
  • 2.16.241.218
  • 2.16.241.207
whitelisted
google.com
  • 142.250.185.206
whitelisted
login.live.com
  • 20.190.160.22
  • 20.190.160.67
  • 20.190.160.2
  • 40.126.32.134
  • 20.190.160.132
  • 20.190.160.17
  • 40.126.32.72
  • 20.190.160.64
whitelisted
th.bing.com
  • 2.16.241.218
  • 2.16.241.207
  • 2.16.241.205
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 172.66.2.5
  • 162.159.142.9
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
arc.msn.com
  • 20.31.169.57
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted
slscr.update.microsoft.com
  • 135.233.95.144
whitelisted

Threats

No threats detected
No debug info