File name:

MicroSIP-3.21.6.exe

Full analysis: https://app.any.run/tasks/f93e9b2c-67c2-4fe6-97fd-e8331a81cc2c
Verdict: Malicious activity
Analysis date: July 07, 2025, 18:39:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

E1C727E7A7693D8896396051745D2D19

SHA1:

E19111B0398BC0BD88AB39DD8E80DAD8B9CA83CF

SHA256:

58855E1C758FFD9C0B36B40C355A3B59F11E902C489C56D337CF931E236947B8

SSDEEP:

98304:5C1PcgJYPw0gVGvssiSMWGuhrFtpjZqCE3XIA7hZZlMV7wHX69qWDB7EW2bxoRq9:h/tPB098m/2oukgGr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • MicroSIP-3.21.6.exe (PID: 7104)
      • microsip.exe (PID: 4312)
    • Changes the autorun value in the registry

      • MicroSIP-3.21.6.exe (PID: 7104)
      • microsip.exe (PID: 4312)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • MicroSIP-3.21.6.exe (PID: 7104)
    • There is functionality for taking screenshot (YARA)

      • MicroSIP-3.21.6.exe (PID: 7104)
      • microsip.exe (PID: 4312)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • MicroSIP-3.21.6.exe (PID: 7104)
    • Executable content was dropped or overwritten

      • MicroSIP-3.21.6.exe (PID: 7104)
    • Creates a software uninstall entry

      • MicroSIP-3.21.6.exe (PID: 7104)
    • Reads security settings of Internet Explorer

      • MicroSIP-3.21.6.exe (PID: 7104)
      • microsip.exe (PID: 4312)
  • INFO

    • Checks supported languages

      • MicroSIP-3.21.6.exe (PID: 7104)
      • identity_helper.exe (PID: 6296)
      • microsip.exe (PID: 4312)
    • Reads the computer name

      • MicroSIP-3.21.6.exe (PID: 7104)
      • microsip.exe (PID: 4312)
      • identity_helper.exe (PID: 6296)
    • Create files in a temporary directory

      • MicroSIP-3.21.6.exe (PID: 7104)
    • Creates files or folders in the user directory

      • MicroSIP-3.21.6.exe (PID: 7104)
      • microsip.exe (PID: 4312)
    • The sample compiled with english language support

      • MicroSIP-3.21.6.exe (PID: 7104)
    • Launching a file from a Registry key

      • MicroSIP-3.21.6.exe (PID: 7104)
      • microsip.exe (PID: 4312)
    • Application launched itself

      • msedge.exe (PID: 2356)
      • msedge.exe (PID: 7072)
      • msedge.exe (PID: 7124)
    • Checks proxy server information

      • microsip.exe (PID: 4312)
    • Reads Environment values

      • identity_helper.exe (PID: 6296)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:55:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 184832
UninitializedDataSize: 2048
EntryPoint: 0x3552
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.21.6.5
ProductVersionNumber: 3.21.6.5
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (0452)
CharacterSet: Windows, Latin1
CompanyName: www.microsip.org
FileDescription: MicroSIP Installer
FileVersion: 3.21.6
InternalName: MicroSIP-3.21.6
LegalCopyright: Copyright © 2011-2025, MicroSIP (www.microsip.org). All rights reserved.
OriginalFileName: MicroSIP-3.21.6.exe
ProductName: MicroSIP
ProductVersion: 3.21.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
28
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start microsip-3.21.6.exe msedge.exe no specs microsip.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
72"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2752,i,8782355278944041339,10082040377915636350,262144 --variations-seed-version --mojo-platform-channel-handle=2812 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1636"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5080,i,8782355278944041339,10082040377915636350,262144 --variations-seed-version --mojo-platform-channel-handle=5092 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1728"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5212,i,16780811131903697821,76236826891220331,262144 --variations-seed-version --mojo-platform-channel-handle=5216 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2276"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3636,i,16780811131903697821,76236826891220331,262144 --variations-seed-version --mojo-platform-channel-handle=3700 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2288"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4032,i,8782355278944041339,10082040377915636350,262144 --variations-seed-version --mojo-platform-channel-handle=4828 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
2356"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.microsip.org/check-version?ver=3.21.6C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMicroSIP-3.21.6.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2716"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3944,i,8782355278944041339,10082040377915636350,262144 --variations-seed-version --mojo-platform-channel-handle=2588 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2732"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4908,i,8782355278944041339,10082040377915636350,262144 --variations-seed-version --mojo-platform-channel-handle=4944 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2780C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2996"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=4876,i,8782355278944041339,10082040377915636350,262144 --variations-seed-version --mojo-platform-channel-handle=5016 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
6 777
Read events
6 720
Write events
54
Delete events
3

Modification events

(PID) Process:(7104) MicroSIP-3.21.6.exeKey:HKEY_CLASSES_ROOT\tel
Operation:writeName:URL Protocol
Value:
(PID) Process:(7104) MicroSIP-3.21.6.exeKey:HKEY_CLASSES_ROOT\callto
Operation:writeName:URL Protocol
Value:
(PID) Process:(7104) MicroSIP-3.21.6.exeKey:HKEY_CLASSES_ROOT\sip
Operation:writeName:URL Protocol
Value:
(PID) Process:(7104) MicroSIP-3.21.6.exeKey:HKEY_CLASSES_ROOT\dialpad
Operation:writeName:URL Protocol
Value:
(PID) Process:(7104) MicroSIP-3.21.6.exeKey:HKEY_CLASSES_ROOT\dial
Operation:writeName:URL Protocol
Value:
(PID) Process:(7104) MicroSIP-3.21.6.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities
Operation:writeName:ApplicationDescription
Value:
Softphone
(PID) Process:(7104) MicroSIP-3.21.6.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities
Operation:writeName:ApplicationName
Value:
MicroSIP
(PID) Process:(7104) MicroSIP-3.21.6.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:tel
Value:
MicroSIP.dial
(PID) Process:(7104) MicroSIP-3.21.6.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:callto
Value:
MicroSIP.dial
(PID) Process:(7104) MicroSIP-3.21.6.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:sip
Value:
MicroSIP.dial
Executable files
12
Suspicious files
216
Text files
75
Unknown types
25

Dropped files

PID
Process
Filename
Type
7104MicroSIP-3.21.6.exeC:\Users\admin\AppData\Local\Temp\nsu4EFB.tmp\nsDialogs.dllexecutable
MD5:B7D61F3F56ABF7B7FF0D4E7DA3AD783D
SHA256:89A82C4849C21DFE765052681E1FAD02D2D7B13C8B5075880C52423DCA72A912
7104MicroSIP-3.21.6.exeC:\Users\admin\AppData\Local\MicroSIP\SDL2.dllexecutable
MD5:70353A2E0375015D2A15E7AB5C7ADCE7
SHA256:AFEDDF0FFDC0DBA31883EFA7D41727E0D1042A02471AAD241CF415E903169FE7
7104MicroSIP-3.21.6.exeC:\Users\admin\AppData\Local\Temp\nsu4EFB.tmp\LangDLL.dllexecutable
MD5:549EE11198143574F4D9953198A09FE8
SHA256:131AA0DF90C08DCE2EECEE46CCE8759E9AFFF04BF15B7B0002C2A53AE5E92C36
7104MicroSIP-3.21.6.exeC:\Users\admin\AppData\Local\Temp\nsu4EFB.tmp\modern-wizard.bmpimage
MD5:32D872B48C1106D505F5C727D1F5A4A3
SHA256:5C5E3E1BADA532E95AEA8846336B0F5F17CC9C49BCD020064CD3EBE4A5D86922
7104MicroSIP-3.21.6.exeC:\Users\admin\AppData\Local\Temp\nsu4EFB.tmp\modern-header.bmpimage
MD5:7F2CF7FC6EE45076F9A871CF553DEF53
SHA256:33FD79634BC585E46E8CCD8BC7242CDD2133376A6DC1196C5C9D752E8ADEABCE
7104MicroSIP-3.21.6.exeC:\Users\admin\AppData\Local\Temp\nsu4EFB.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
7104MicroSIP-3.21.6.exeC:\Users\admin\AppData\Local\Temp\nsu4EFB.tmp\StartMenu.dllexecutable
MD5:DC91F181F9CB870FFF0C58BC0EA63EDA
SHA256:E74F442771F034A24B77D3A849B343551BDEF69EF151C622CB9FD5F34DCCDA81
7104MicroSIP-3.21.6.exeC:\Users\admin\AppData\Local\MicroSIP\avcodec-57.dllexecutable
MD5:D04D538A6D8A1403C4D8BB1E787C0D57
SHA256:5348A7C4D0EFEE615EF8869B04B19FB5ECB9E46C4A797FBB83B29225672763A7
7104MicroSIP-3.21.6.exeC:\Users\admin\AppData\Local\MicroSIP\microsip.exeexecutable
MD5:7AD0DE4A76BCA66310621227B1E29FE5
SHA256:33D34EEC550516935BDE7259C30B3DC3E5718004BF6C8A21E26BD88BC53204F6
7104MicroSIP-3.21.6.exeC:\Users\admin\AppData\Local\MicroSIP\avformat-57.dllexecutable
MD5:11DF4D971CFC63A4FAC48E1A0478FC99
SHA256:DF599C6944C31FD3EA212A1B080DD851D823886BBBC59A9814A910C793426E65
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
60
DNS requests
71
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1688
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
5744
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
420 b
whitelisted
1268
svchost.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
5744
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
408 b
whitelisted
4312
microsip.exe
GET
200
104.21.3.209:80
http://update.microsip.org/softphone-update.txt?version=3.21.6&client=MicroSIP
unknown
whitelisted
7136
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:xGqgf_CjY-dCttgXxIs9wz5myPP_Ec5flz5fdNfOItI&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
101 b
whitelisted
1268
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
892
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
69.192.161.161:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1688
svchost.exe
20.190.160.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1688
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5744
SIHClient.exe
20.12.23.50:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 69.192.161.161
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.160.4
  • 40.126.32.138
  • 20.190.160.14
  • 20.190.160.66
  • 40.126.32.140
  • 40.126.32.74
  • 20.190.160.64
  • 40.126.32.136
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.22
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Potentially Bad Traffic
ET INFO Possible Chrome Plugin install
No debug info