File name:

MicroSIP-3.21.5.exe

Full analysis: https://app.any.run/tasks/fec20731-70b0-4b8d-8bff-6c09d309b798
Verdict: Malicious activity
Analysis date: January 08, 2025, 12:15:54
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

17B09E0E5BC4350224B92ACD2BF6C7E0

SHA1:

8753419B20C8A569B26C901EFFDFB7D37507625F

SHA256:

5E038B374E0E13332697AC2073BC89F8CC9346A7834E9F12D8946DBB85851499

SSDEEP:

98304:PC1PcgJHoJJVynK5PkzieY63QisukdrxnabUYvCeg36iTuy8W8NFW7WEN5j9d15L:XJMjFU1KAOy/2oukgCR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • microsip.exe (PID: 7040)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • MicroSIP-3.21.5.exe (PID: 6476)
    • Executable content was dropped or overwritten

      • MicroSIP-3.21.5.exe (PID: 6476)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • MicroSIP-3.21.5.exe (PID: 6476)
    • Creates a software uninstall entry

      • MicroSIP-3.21.5.exe (PID: 6476)
    • Reads security settings of Internet Explorer

      • MicroSIP-3.21.5.exe (PID: 6476)
  • INFO

    • Checks supported languages

      • MicroSIP-3.21.5.exe (PID: 6476)
      • microsip.exe (PID: 7040)
      • identity_helper.exe (PID: 6708)
    • Reads the computer name

      • MicroSIP-3.21.5.exe (PID: 6476)
      • microsip.exe (PID: 7040)
      • identity_helper.exe (PID: 6708)
    • Create files in a temporary directory

      • MicroSIP-3.21.5.exe (PID: 6476)
    • The sample compiled with english language support

      • MicroSIP-3.21.5.exe (PID: 6476)
    • Reads Environment values

      • identity_helper.exe (PID: 6708)
    • Checks proxy server information

      • microsip.exe (PID: 7040)
    • Application launched itself

      • msedge.exe (PID: 7032)
    • Creates files or folders in the user directory

      • MicroSIP-3.21.5.exe (PID: 6476)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:55:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 184832
UninitializedDataSize: 2048
EntryPoint: 0x3552
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.21.5.6
ProductVersionNumber: 3.21.5.6
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (0452)
CharacterSet: Windows, Latin1
CompanyName: www.microsip.org
FileDescription: MicroSIP Installer
FileVersion: 3.21.5
InternalName: MicroSIP-3.21.5
LegalCopyright: Copyright © 2011-2024, MicroSIP (www.microsip.org). All rights reserved.
OriginalFileName: MicroSIP-3.21.5.exe
ProductName: MicroSIP
ProductVersion: 3.21.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
164
Monitored processes
34
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start microsip-3.21.5.exe msedge.exe microsip.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5988 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
836"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6416 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2212"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4132 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2744"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3556 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3420"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4360 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3612"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2580 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3620"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=5980 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3640"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6268 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3744"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2412 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4500"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3732 --field-trial-handle=2312,i,14913781570254830839,5830359286406392701,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
5 352
Read events
5 300
Write events
49
Delete events
3

Modification events

(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:MicroSIP
Value:
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:delete valueName:\MicroSIP.exe.FriendlyAppName
Value:
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:delete valueName:\MicroSIP.exe.ApplicationCompany
Value:
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities
Operation:writeName:ApplicationName
Value:
MicroSIP
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:tel
Value:
MicroSIP.dial
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:callto
Value:
MicroSIP.dial
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:sip
Value:
MicroSIP.dial
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:dialpad
Value:
MicroSIP.dial
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP\Capabilities\UrlAssociations
Operation:writeName:dial
Value:
MicroSIP.dial
(PID) Process:(6476) MicroSIP-3.21.5.exeKey:HKEY_CURRENT_USER\SOFTWARE\MicroSIP
Operation:writeName:DesktopShortcut
Value:
0
Executable files
15
Suspicious files
212
Text files
44
Unknown types
1

Dropped files

PID
Process
Filename
Type
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\microsip.exeexecutable
MD5:FC01E7E2029BFBF3C27ADBAAE231FD81
SHA256:376AC95899EC26747F07DBA04EF65A3F541EDA8F4977C1A975E6A230BD3A32B5
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\Temp\nsz5690.tmp\StartMenu.dllexecutable
MD5:DC91F181F9CB870FFF0C58BC0EA63EDA
SHA256:E74F442771F034A24B77D3A849B343551BDEF69EF151C622CB9FD5F34DCCDA81
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\SDL2.dllexecutable
MD5:70353A2E0375015D2A15E7AB5C7ADCE7
SHA256:AFEDDF0FFDC0DBA31883EFA7D41727E0D1042A02471AAD241CF415E903169FE7
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\swscale-4.dllexecutable
MD5:62C0267FE5C7133EB74FD52324A3B7F6
SHA256:4992639DF7187DFF687AE00403D587B3ADC721F8C23CA395E71EC6628E38E743
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\lame_enc.dllexecutable
MD5:AB70669CA143E7CC72C94B07C5335D24
SHA256:609CDA424326077BB2DD931308C7D8890B4CE3310FEF0EB3B2638BBEF4F3B4CD
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\ringing2.wavwav
MD5:D29AF2743FADA13F0CA6F54DD72EC4A3
SHA256:A9E558A53EE0AE5FA8858FBA23F0DEE59D86CF0DE3EC908DC80B978857AC9D99
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\avformat-57.dllexecutable
MD5:11DF4D971CFC63A4FAC48E1A0478FC99
SHA256:DF599C6944C31FD3EA212A1B080DD851D823886BBBC59A9814A910C793426E65
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\ringtone.wavwav
MD5:F6C7C5E7AC3A119B1EE99F35A34B00BF
SHA256:A2EFA78855ED15DD4E882E4ADDE00764D3EC59936ECAD9FB953F0963A83AB740
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\avutil-55.dllexecutable
MD5:FEB0EDB1AE28F50CF919FDF86FE90B48
SHA256:BFDEC4FA40CE1164B3BFFA2116A3151548F03004257241A07A77572152064191
6476MicroSIP-3.21.5.exeC:\Users\admin\AppData\Local\MicroSIP\msgout.wavbinary
MD5:8D2BAAF9506E8EC8FA1D7D64395BDEDC
SHA256:E97045E08AF35848F0AA8D9C0AE164BE44D7D266FE38CE8B708FAAC1FFD8468E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
80
DNS requests
72
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.24:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6432
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7532
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7532
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7040
microsip.exe
GET
200
104.21.3.209:80
http://update.microsip.org/softphone-update.txt?version=3.21.5&client=MicroSIP
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.24:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.24
  • 2.16.164.34
  • 2.16.164.82
  • 2.16.164.40
  • 2.16.164.73
  • 2.16.164.129
  • 2.16.164.99
  • 2.16.164.113
  • 2.16.164.112
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 142.250.184.238
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.221
  • 2.23.227.198
  • 2.23.227.208
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.71
  • 20.190.159.4
  • 20.190.159.0
  • 40.126.31.71
  • 40.126.31.73
  • 40.126.31.69
  • 20.190.159.64
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted

Threats

No threats detected
No debug info