File name:

Adobe AIR Installer.exe

Full analysis: https://app.any.run/tasks/3014df19-db2b-4e35-a59a-7319fa9be361
Verdict: Malicious activity
Analysis date: August 02, 2024, 10:40:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: MS-DOS executable PE32 executable (GUI) Intel 80386, for MS Windows, MZ for MS-DOS
MD5:

DE9C3DD3F3FB4503D7015489ABF90DCE

SHA1:

D38FAAA4D24AB180BE143F890BCACFC1CD6C6F16

SHA256:

5F85EAF8622ADDA6E7196E7E1662362B49C35DC4FDFE08DC42E8AADC3B9DC968

SSDEEP:

98304:XaacpLdSzu8q9Dr4JxoVXwqOgjMMLYZnD74LlGJ8fIoSREuGpcD/cpbwWePd39F/:iePGDBUGcj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Adobe AIR Installer.exe (PID: 3660)
      • msiexec.exe (PID: 3260)
      • Adobe AIR Installer.exe (PID: 3248)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Adobe AIR Installer.exe (PID: 3660)
      • Adobe AIR Installer.exe (PID: 3248)
    • Executable content was dropped or overwritten

      • Adobe AIR Installer.exe (PID: 3660)
      • Adobe AIR Installer.exe (PID: 3248)
    • Reads the Internet Settings

      • Adobe AIR Installer.exe (PID: 3660)
      • Adobe AIR Installer.exe (PID: 3248)
    • Application launched itself

      • Adobe AIR Installer.exe (PID: 3248)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 3260)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 3260)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 3260)
    • Creates file in the systems drive root

      • AcroRd32.exe (PID: 3348)
  • INFO

    • Creates files or folders in the user directory

      • Adobe AIR Installer.exe (PID: 3660)
      • Adobe AIR Installer.exe (PID: 3248)
    • Reads the computer name

      • Adobe AIR Installer.exe (PID: 3660)
      • Adobe AIR Installer.exe (PID: 3248)
      • Adobe AIR Installer.exe (PID: 3500)
      • msiexec.exe (PID: 3260)
      • wmpnscfg.exe (PID: 3196)
    • Checks supported languages

      • Adobe AIR Installer.exe (PID: 3660)
      • Adobe AIR Installer.exe (PID: 3248)
      • Adobe AIR Installer.exe (PID: 3500)
      • msiexec.exe (PID: 3260)
      • wmpnscfg.exe (PID: 3196)
    • Create files in a temporary directory

      • Adobe AIR Installer.exe (PID: 3660)
      • msiexec.exe (PID: 3260)
    • Reads the machine GUID from the registry

      • Adobe AIR Installer.exe (PID: 3660)
      • Adobe AIR Installer.exe (PID: 3248)
      • msiexec.exe (PID: 3260)
      • Adobe AIR Installer.exe (PID: 3500)
    • Reads CPU info

      • Adobe AIR Installer.exe (PID: 3248)
      • Adobe AIR Installer.exe (PID: 3500)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3260)
    • Reads the software policy settings

      • msiexec.exe (PID: 3260)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3260)
    • Creates files in the program directory

      • Adobe AIR Installer.exe (PID: 3248)
    • Manual execution by a user

      • AcroRd32.exe (PID: 3596)
      • wmpnscfg.exe (PID: 3196)
    • Application launched itself

      • RdrCEF.exe (PID: 3292)
      • AcroRd32.exe (PID: 3596)
    • Drops the executable file immediately after the start

      • RdrCEF.exe (PID: 3292)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:01:07 16:19:09+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 5.12
CodeSize: 82514
InitializedDataSize: 24584
UninitializedDataSize: -
EntryPoint: 0x4ffee
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.20
ProductVersionNumber: 2.0.0.20
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments:
FileVersion: 2.0.0.20
ProductVersion: 2.0.0.20
CompanyName:
LegalCopyright:
ProductName: NOSSO(R)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
14
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start adobe air installer.exe adobe air installer.exe adobe air installer.exe no specs msiexec.exe acrord32.exe acrord32.exe no specs wmpnscfg.exe no specs rdrcef.exe rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs adobe air installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2256"C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exe" C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
2.0.0.20
Modules
Images
c:\users\admin\appdata\local\temp\adobe air installer.exe
c:\windows\system32\ntdll.dll
2500"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --touch-events=enabled --field-trial-handle=1176,8749948323840566352,11356802718611368189,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-gpu-compositing --lang=en-US --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=17351847136355351055 --renderer-client-id=6 --mojo-platform-channel-handle=1472 --allow-no-sandbox-job /prefetch:1C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
0
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3196"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3248"C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR Installer.exe" C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR Installer.exe
Adobe AIR Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225547
Modules
Images
c:\users\admin\appdata\local\nos\adobe air installer\adobe air installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msi.dll
3260C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3292"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --backgroundcolor=16514043C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
AcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
3221225547
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3348"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=rendererC:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3476"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --touch-events=enabled --field-trial-handle=1176,8749948323840566352,11356802718611368189,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-gpu-compositing --lang=en-US --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6926605397065857594 --renderer-client-id=2 --mojo-platform-channel-handle=1184 --allow-no-sandbox-job /prefetch:1C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
0
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3500"C:\Users\admin\appdata\local\nos\adobe air installer\adobe air installer.exe" -stdio \\.\pipe\AIR_3248_0 -silentC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR Installer.exeAdobe AIR Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\nos\adobe air installer\adobe air installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msi.dll
3556"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=gpu-process --field-trial-handle=1176,8749948323840566352,11356802718611368189,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --lang=en-US --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAABAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --service-request-channel-token=11812840356119466344 --mojo-platform-channel-handle=1284 --allow-no-sandbox-job --ignored=" --type=renderer " /prefetch:2C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
1
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
26 546
Read events
26 301
Write events
211
Delete events
34

Modification events

(PID) Process:(3660) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3660) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3660) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3660) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3248) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3248) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3248) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3248) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3260) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3260) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:742C3192E607E424EB4549542BE1BBC53E6174E2
Value:
Executable files
21
Suspicious files
106
Text files
6
Unknown types
10

Dropped files

PID
Process
Filename
Type
3660Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\sentineltext
MD5:A5C11CA014FE30B8085EA2E95F7196C4
SHA256:096E4BFD9F7E1FAF15058C0A0FE45E6DBD00E3E1360F21F2CA92BCE16A9A919A
3660Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\template.msiexecutable
MD5:D4A1A427AE17047055186395CA873089
SHA256:A7438FBE8C8996D966CAFF507C77114A861833B4C1BC1248A71271762005A2C8
3660Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.swfbinary
MD5:8599589CB2F1CFAD899F0E95C3CF2BC9
SHA256:101140C8DF33CD81AF64000549872EF9E48AF5913A27367E0865A4F83BECC509
3660Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe Root Certificate.cerbinary
MD5:BF70913FF8D6D60A47FE825330815DB4
SHA256:944E66AA967BD390952D22426BF1DFCD379A2C87A21B942FBCA79F41F0354AAC
3660Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\setup.swfbinary
MD5:5A933EAA6F248C06A2FF42410720E243
SHA256:B1DEA74CFA75B57B37F14E678B86A7BE35F42A8A2A9C808AC4E6CE6E78B31188
3660Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Thawte Root Certificate.cerbinary
MD5:7F667A71D3EB6978209A51149D83DA20
SHA256:6B6C1E01F590F5AFC5FCF85CD0B9396884048659FC2C6D1170D68B045216C3FD
3660Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\airappinstaller.exeexecutable
MD5:9C5B124EFD76128D26D3BCF85A3F2092
SHA256:5FA546E912A3FEDEA19477BA68BB127CD2867170A2BDB831B78549C6190D55B9
3660Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\WebKit.dllexecutable
MD5:7DDE37CD1B91865A2A202DE66E2B6FDA
SHA256:6C43E63A3E93144F5D3442B62E87545E43ADE86AA0C855A4ADDA89629D0B2646
3660Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\template.exeexecutable
MD5:F3EA2F1D80738777C226C7D0C4212662
SHA256:0350407FD5C8DF439EAA1450F66428933ADA5F4AAE01743F219D43FDDC668A8B
3660Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exeexecutable
MD5:5E9D2FCCAD3B9EDBC0A8AB0FE1E5E510
SHA256:BA7CD3C2EF37746576EA934FBBFE6CE0F659977F604CB6528E642E6D82E60FF7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
21
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
23.50.131.216:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
whitelisted
1372
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1372
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1060
svchost.exe
GET
304
23.50.131.216:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5e5d86b7c9b09139
unknown
whitelisted
3596
AcroRd32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
239.255.255.250:3702
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted
1372
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1372
svchost.exe
23.50.131.216:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.181.238
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
ctldl.windowsupdate.com
  • 23.50.131.216
  • 23.50.131.200
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.173
  • 23.48.23.164
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
geo2.adobe.com
  • 23.218.208.137
whitelisted
p13n.adobe.io
  • 34.237.241.83
  • 18.213.11.84
  • 50.16.47.176
  • 54.224.241.105
whitelisted
armmf.adobe.com
  • 184.30.20.134
whitelisted
acroipm2.adobe.com
  • 23.32.238.152
  • 23.32.238.130
  • 23.32.238.144
  • 23.32.238.105
  • 23.32.238.146
  • 23.32.238.99
  • 23.32.238.106
  • 23.32.238.137
  • 23.32.238.107
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info