File name:

action1_agent(My_Organization).msi

Full analysis: https://app.any.run/tasks/eedb955d-6a80-498b-b198-30dca673b324
Verdict: Malicious activity
Analysis date: February 05, 2025, 19:03:55
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
generated-doc
fody
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Action1 Agent provides the ability to remotely manage computers using Action1 Platform, Author: Action1 Corporation, Keywords: Action1,Agent, Comments: Version: 5.213.614.1. Copyright (C) 2021 Action1 Corporation, Template: Intel;1033, Revision Number: {93CBCBB1-BFE5-44AF-9851-12AB61B1A154}, Create Time/Date: Mon Dec 16 17:27:58 2024, Last Saved Time/Date: Mon Dec 16 17:27:58 2024, Number of Pages: 400, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
MD5:

A76B3BAE2A2A4DA1F82040E98A4300C3

SHA1:

F2798E9D3CC1409ABD5C8FD41182B68FA97C2831

SHA256:

5B9B5E4FCCC07A2BBFB1C076786872F0B87E82ECA58038BC4724A722A0B99CFA

SSDEEP:

98304:709tWD+72IXgMzx8Th7PIrrOjoqoE3SL9sMfR7t00vaWEaGfAmf29tjCSEU9ag/X:KhIVsEDo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 6436)
    • Changes powershell execution policy (Bypass)

      • action1_agent.exe (PID: 2136)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 7104)
      • action1_agent.exe (PID: 2136)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6572)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6572)
    • Drops 7-zip archiver for unpacking

      • msiexec.exe (PID: 6572)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 6572)
    • Searches for installed software

      • action1_agent.exe (PID: 2136)
    • Connects to unusual port

      • action1_agent.exe (PID: 2136)
    • Starts POWERSHELL.EXE for commands execution

      • action1_agent.exe (PID: 2136)
    • The process executes Powershell scripts

      • action1_agent.exe (PID: 2136)
    • The process bypasses the loading of PowerShell profile settings

      • action1_agent.exe (PID: 2136)
    • The process hides Powershell's copyright startup banner

      • action1_agent.exe (PID: 2136)
    • Reads security settings of Internet Explorer

      • action1_agent.exe (PID: 2136)
    • The process hide an interactive prompt from the user

      • action1_agent.exe (PID: 2136)
    • There is functionality for taking screenshot (YARA)

      • action1_agent.exe (PID: 2136)
  • INFO

    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 6244)
      • powershell.exe (PID: 6436)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6244)
    • The sample compiled with english language support

      • msiexec.exe (PID: 6244)
      • msiexec.exe (PID: 6572)
    • Checks proxy server information

      • msiexec.exe (PID: 6244)
    • Reads the computer name

      • msiexec.exe (PID: 6572)
      • msiexec.exe (PID: 4052)
      • msiexec.exe (PID: 4144)
      • action1_agent.exe (PID: 2136)
    • Checks supported languages

      • msiexec.exe (PID: 6572)
      • msiexec.exe (PID: 4052)
      • msiexec.exe (PID: 4144)
      • action1_agent.exe (PID: 2136)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 6572)
    • Reads the software policy settings

      • msiexec.exe (PID: 6244)
      • msiexec.exe (PID: 6572)
      • powershell.exe (PID: 6436)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6572)
    • Manages system restore points

      • SrTasks.exe (PID: 3988)
    • Reads Environment values

      • action1_agent.exe (PID: 2136)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6572)
    • Process checks computer location settings

      • action1_agent.exe (PID: 2136)
    • Manual execution by a user

      • notepad.exe (PID: 768)
      • notepad++.exe (PID: 1704)
      • notepad++.exe (PID: 2624)
      • notepad++.exe (PID: 748)
    • Uses string split method (POWERSHELL)

      • powershell.exe (PID: 6436)
    • Detects Fody packer (YARA)

      • powershell.exe (PID: 6436)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Action1 Agent provides the ability to remotely manage computers using Action1 Platform
Author: Action1 Corporation
Keywords: Action1,Agent
Comments: Version: 5.213.614.1. Copyright (C) 2021 Action1 Corporation
Template: Intel;1033
RevisionNumber: {93CBCBB1-BFE5-44AF-9851-12AB61B1A154}
CreateDate: 2024:12:16 17:27:58
ModifyDate: 2024:12:16 17:27:58
Pages: 400
Words: 2
Software: Windows Installer XML Toolset (3.14.1.8722)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
15
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs action1_agent.exe powershell.exe no specs conhost.exe no specs rundll32.exe no specs notepad++.exe notepad++.exe notepad++.exe notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
748"C:\Program Files\Notepad++\notepad++.exe" "C:\Windows\Action1\scripts\DataSource_1008.ps1"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Don HO don.h@free.fr
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
768"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Windows\Action1\logs\action1_log_2025-02-05_19-04-45~2136.logC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
1704"C:\Program Files\Notepad++\notepad++.exe" "C:\Windows\Action1\datasource_data\1000.poll"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Don HO don.h@free.fr
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2136C:\WINDOWS\Action1\action1_agent.exe serviceC:\Windows\Action1\action1_agent.exe
services.exe
User:
SYSTEM
Company:
Action1 Corporation
Integrity Level:
SYSTEM
Description:
Endpoint Agent
Version:
5.213.614.1
Modules
Images
c:\windows\action1\action1_agent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\psapi.dll
c:\windows\syswow64\wintrust.dll
2624"C:\Program Files\Notepad++\notepad++.exe" "C:\Windows\Action1\scripts\DataSource_1004.ps1"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Don HO don.h@free.fr
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3820\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3988C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4052C:\Windows\syswow64\MsiExec.exe -Embedding CE2C01646C49E7C3021DDE7619C8CA4EC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4144C:\Windows\syswow64\MsiExec.exe -Embedding 1663E99450C231964C0D01A323A08005 E Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5652\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
16 989
Read events
16 644
Write events
325
Delete events
20

Modification events

(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000D7D7F5BF0078DB01AC190000B01B0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000D7D7F5BF0078DB01AC190000B01B0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
480000000000000082BA3FC00078DB01AC190000B01B0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000531D42C00078DB01AC190000B01B0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
480000000000000060E446C00078DB01AC190000B01B0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000068144C00078DB01AC190000B01B0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
48000000000000003375FEC00078DB01AC190000B01B0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7104) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000040B205C10078DB01C01B0000D8120000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7104) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000040B205C10078DB01C01B0000E01B0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7104) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000040B205C10078DB01C01B0000900F0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
8
Suspicious files
39
Text files
14
Unknown types
1

Dropped files

PID
Process
Filename
Type
6572msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6572msiexec.exeC:\Windows\Installer\141b27.msi
MD5:
SHA256:
6244msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_93702E680A5530C052C8D2BA33A2225Fbinary
MD5:7EE332EB9D8A2AE791ECE323CEC41515
SHA256:647C9B1097383A1F97B6923513C200C5340ACD68DB2BAE373C911E2C151D5C69
6572msiexec.exeC:\Windows\Installer\MSI1F40.tmpexecutable
MD5:8EDC1557E9FC7F25F89AD384D01BCEC4
SHA256:78860E15E474CC2AF7AD6E499A8971B6B8197AFB8E49A1B9EAAA392E4378F3A5
6572msiexec.exeC:\Windows\Installer\MSI1E25.tmpexecutable
MD5:2B5FF933919383BE9F6E66AF68B9C155
SHA256:E0D30A6C4207BEA8D1B8D00EF4963B28F9423BE4F4D3B914BE5A71C458598975
6572msiexec.exeC:\Windows\Installer\MSI1F01.tmpbinary
MD5:307BD5A7B9E21F936688C9E86848CCC8
SHA256:6655A2AD78D64138B933FB5B622F568A5484852E8BF714825702ABFE4AF5BAE2
6572msiexec.exeC:\Windows\Action1\7z.dllexecutable
MD5:26ACF2E068A715BD449A1CFCB9074AE4
SHA256:F9762180D733B0AFDEBD33869DA91B96623A439A70E27573E71974AFB39B436B
6244msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\18E6B4A57A6BC7EC9B861CDF2D6D0D02_EF52C1EC85F21F31CC0157A5C8803013binary
MD5:5CBF9429CAF8AF09F6E465903424A806
SHA256:FAB5154FA79930E536CA23D7ED9645F74625F715543D7680BB37F117ED0908E7
6244msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_93702E680A5530C052C8D2BA33A2225Fbinary
MD5:74772D74DF98F8FE642E208C098BB6B1
SHA256:86392693A7FAF31D8D23CE24A7FB0A2399352709EFD8F19555E310E9C0429DBF
6244msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\18E6B4A57A6BC7EC9B861CDF2D6D0D02_EF52C1EC85F21F31CC0157A5C8803013binary
MD5:4603A1673D4290FA8F888826EC4751C9
SHA256:E02FCFB485321F35FB9AD93B7D35203ABE59C85A4EF0563F9BD32BB99236F9C1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
30
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6244
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEDPXCKiRQFMZ4qW70zm5rW4%3D
unknown
binary
765 b
whitelisted
6244
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D
unknown
binary
1.42 Kb
whitelisted
6244
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRd0JozUYXMqqW4y4zJTrLcMCRSkAQUgTKSQSsozUbIxKLGKjkS7EipPxQCEEV%2F6oPpCGe%2BJ43kKfDM9ME%3D
unknown
binary
637 b
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
6152
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
408 b
whitelisted
6152
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
104.126.37.130:443
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
104.126.37.130:443
Akamai International B.V.
DE
unknown
6244
msiexec.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
40.126.31.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6152
SIHClient.exe
20.109.210.53:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
login.live.com
  • 40.126.31.130
  • 20.190.159.128
  • 40.126.31.69
  • 40.126.31.71
  • 40.126.31.131
  • 40.126.31.67
  • 20.190.159.129
  • 20.190.159.0
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
server.eu.action1.com
  • 18.159.245.29
  • 18.195.232.183
unknown
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted

Threats

No threats detected
Process
Message
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: error while getting certificate informations
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll