File name:

MicroSIP-3.21.5.exe

Full analysis: https://app.any.run/tasks/fec20731-70b0-4b8d-8bff-6c09d309b798
Verdict: Malicious activity
Analysis date: January 08, 2025, 12:15:54
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

17B09E0E5BC4350224B92ACD2BF6C7E0

SHA1:

8753419B20C8A569B26C901EFFDFB7D37507625F

SHA256:

5E038B374E0E13332697AC2073BC89F8CC9346A7834E9F12D8946DBB85851499

SSDEEP:

98304:PC1PcgJHoJJVynK5PkzieY63QisukdrxnabUYvCeg36iTuy8W8NFW7WEN5j9d15L:XJMjFU1KAOy/2oukgCR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • microsip.exe (PID: 7040)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • MicroSIP-3.21.5.exe (PID: 6476)
    • Executable content was dropped or overwritten

      • MicroSIP-3.21.5.exe (PID: 6476)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • MicroSIP-3.21.5.exe (PID: 6476)
    • Creates a software uninstall entry

      • MicroSIP-3.21.5.exe (PID: 6476)
    • Reads security settings of Internet Explorer

      • MicroSIP-3.21.5.exe (PID: 6476)
  • INFO

    • Reads the computer name

      • MicroSIP-3.21.5.exe (PID: 6476)
      • microsip.exe (PID: 7040)
      • identity_helper.exe (PID: 6708)
    • Checks supported languages

      • MicroSIP-3.21.5.exe (PID: 6476)
      • microsip.exe (PID: 7040)
      • identity_helper.exe (PID: 6708)
    • Creates files or folders in the user directory

      • MicroSIP-3.21.5.exe (PID: 6476)
    • The sample compiled with english language support

      • MicroSIP-3.21.5.exe (PID: 6476)
    • Create files in a temporary directory

      • MicroSIP-3.21.5.exe (PID: 6476)
    • Application launched itself

      • msedge.exe (PID: 7032)
    • Checks proxy server information

      • microsip.exe (PID: 7040)
    • Reads Environment values

      • identity_helper.exe (PID: 6708)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:55:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 184832
UninitializedDataSize: 2048
EntryPoint: 0x3552
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.21.5.6
ProductVersionNumber: 3.21.5.6
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (0452)
CharacterSet: Windows, Latin1
CompanyName: www.microsip.org
FileDescription: MicroSIP Installer
FileVersion: 3.21.5
InternalName: MicroSIP-3.21.5
LegalCopyright: Copyright © 2011-2024, MicroSIP (www.microsip.org). All rights reserved.
OriginalFileName: MicroSIP-3.21.5.exe
ProductName: MicroSIP
ProductVersion: 3.21.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
164
Monitored processes
34
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start microsip-3.21.5.exe msedge.exe microsip.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5988 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
836"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6416 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2212"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4132 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2744"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3556 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3420"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4360 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3612"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2580 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3620"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=5980 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3640"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6268 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3744"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2412 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4500"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3732 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
5 352
Read events
5 300
Write events
49
Delete events
3

Modification events

(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:MicroSIP
Value:
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:delete valueName:\MicroSIP.exe.FriendlyAppName
Value:
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:delete valueName:\MicroSIP.exe.ApplicationCompany
Value:
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities
Operation:writeName:ApplicationName
Value:
MicroSIP
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:tel
Value:
MicroSIP.dial
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:callto
Value:
MicroSIP.dial
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:sip
Value:
MicroSIP.dial
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:dialpad
Value:
MicroSIP.dial
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:dial
Value:
MicroSIP.dial
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP
Operation:writeName:DesktopShortcut
Value:
0
Executable files
15
Suspicious files
212
Text files
44
Unknown types
1

Dropped files

PID
Process
Filename
Type
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\avformat-57.dllexecutable
MD5:11DF4D971CFC63A4FAC48E1A0478FC99
SHA256:DF599C6944C31FD3EA212A1B080DD851D823886BBBC59A9814A910C793426E65
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\Temp\nsz5690.tmp\StartMenu.dllexecutable
MD5:DC91F181F9CB870FFF0C58BC0EA63EDA
SHA256:E74F442771F034A24B77D3A849B343551BDEF69EF151C622CB9FD5F34DCCDA81
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\Temp\nsz5690.tmp\modern-header.bmpimage
MD5:7F2CF7FC6EE45076F9A871CF553DEF53
SHA256:33FD79634BC585E46E8CCD8BC7242CDD2133376A6DC1196C5C9D752E8ADEABCE
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\Temp\nsz5690.tmp\modern-wizard.bmpimage
MD5:32D872B48C1106D505F5C727D1F5A4A3
SHA256:5C5E3E1BADA532E95AEA8846336B0F5F17CC9C49BCD020064CD3EBE4A5D86922
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\Temp\nsz5690.tmp\nsDialogs.dllexecutable
MD5:B7D61F3F56ABF7B7FF0D4E7DA3AD783D
SHA256:89A82C4849C21DFE765052681E1FAD02D2D7B13C8B5075880C52423DCA72A912
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\Temp\nsz5690.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\Temp\nsz5690.tmp\LangDLL.dllexecutable
MD5:549EE11198143574F4D9953198A09FE8
SHA256:131AA0DF90C08DCE2EECEE46CCE8759E9AFFF04BF15B7B0002C2A53AE5E92C36
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\hangup.wavbinary
MD5:C6708641DDD85A39361A4050135E795E
SHA256:C1955FD3925952FD63C47F111B3F5CCEFFF2B0E4D8E83F30EB367A4DA32A7ADA
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\ringing2.wavwav
MD5:D29AF2743FADA13F0CA6F54DD72EC4A3
SHA256:A9E558A53EE0AE5FA8858FBA23F0DEE59D86CF0DE3EC908DC80B978857AC9D99
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\msgout.wavbinary
MD5:8D2BAAF9506E8EC8FA1D7D64395BDEDC
SHA256:E97045E08AF35848F0AA8D9C0AE164BE44D7D266FE38CE8B708FAAC1FFD8468E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
80
DNS requests
72
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.16.164.24:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7040
microsip.exe
GET
200
104.21.3.209:80
http://update.microsip.org/softphone-update.txt?version=3.21.5&client=MicroSIP
unknown
whitelisted
6432
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7532
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7532
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.24:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.24
  • 2.16.164.34
  • 2.16.164.82
  • 2.16.164.40
  • 2.16.164.73
  • 2.16.164.129
  • 2.16.164.99
  • 2.16.164.113
  • 2.16.164.112
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 142.250.184.238
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.221
  • 2.23.227.198
  • 2.23.227.208
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.71
  • 20.190.159.4
  • 20.190.159.0
  • 40.126.31.71
  • 40.126.31.73
  • 40.126.31.69
  • 20.190.159.64
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted

Threats

No threats detected
No debug info