File name:

Flicker Free 1.1.6 After Effects CE.exe

Full analysis: https://app.any.run/tasks/d6c0e50a-7faa-4083-aff2-15041f7814fa
Verdict: Malicious activity
Analysis date: June 26, 2025, 11:59:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
delphi
inno
installer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

BEAEEA247B3929520D92CC79A15342C8

SHA1:

90E045C937FBEFC87181BC4E90F762C5C1BF398D

SHA256:

60FC2DC6CA75012C11BB0FEB63FE673C604AF22DBCB833EB407D0DB9213D4596

SSDEEP:

98304:Ig97Ens9C+mFxu2GoOih1osxHhagXMOeMs01akPTm7eOECFhQjWw5Elh72zHdNEf:4f814Afyc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • vcredist_x64.exe (PID: 1688)
      • Setup.exe (PID: 2996)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Flicker Free 1.1.6 After Effects CE.exe (PID: 2324)
      • Flicker Free 1.1.6 After Effects CE.exe (PID: 4948)
      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 1660)
      • vcredist_x64.exe (PID: 1688)
    • Process drops legitimate windows executable

      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 1660)
      • vcredist_x64.exe (PID: 1688)
      • msiexec.exe (PID: 4112)
    • Reads the Windows owner or organization settings

      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 1660)
      • msiexec.exe (PID: 4112)
    • Starts a Microsoft application from unusual location

      • vcredist_x64.exe (PID: 1688)
    • Creates file in the systems drive root

      • vcredist_x64.exe (PID: 1688)
    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 2996)
      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 4024)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 4112)
  • INFO

    • Create files in a temporary directory

      • Flicker Free 1.1.6 After Effects CE.exe (PID: 4948)
      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 1660)
      • Setup.exe (PID: 2996)
      • Flicker Free 1.1.6 After Effects CE.exe (PID: 2324)
    • Checks supported languages

      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 1660)
      • vcredist_x64.exe (PID: 1688)
      • Setup.exe (PID: 2996)
      • msiexec.exe (PID: 4112)
      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 4024)
      • Flicker Free 1.1.6 After Effects CE.exe (PID: 2324)
      • Flicker Free 1.1.6 After Effects CE.exe (PID: 4948)
    • The sample compiled with english language support

      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 1660)
      • vcredist_x64.exe (PID: 1688)
      • msiexec.exe (PID: 4112)
    • Process checks computer location settings

      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 4024)
    • Creates files in the program directory

      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 1660)
    • Creates a software uninstall entry

      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 1660)
      • msiexec.exe (PID: 4112)
    • Reads the computer name

      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 1660)
      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 4024)
      • vcredist_x64.exe (PID: 1688)
      • Setup.exe (PID: 2996)
      • msiexec.exe (PID: 4112)
    • Reads the machine GUID from the registry

      • vcredist_x64.exe (PID: 1688)
      • Setup.exe (PID: 2996)
      • msiexec.exe (PID: 4112)
    • The sample compiled with japanese language support

      • vcredist_x64.exe (PID: 1688)
      • msiexec.exe (PID: 4112)
    • The sample compiled with korean language support

      • vcredist_x64.exe (PID: 1688)
      • msiexec.exe (PID: 4112)
    • The sample compiled with german language support

      • vcredist_x64.exe (PID: 1688)
      • msiexec.exe (PID: 4112)
    • The sample compiled with chinese language support

      • vcredist_x64.exe (PID: 1688)
      • msiexec.exe (PID: 4112)
    • The sample compiled with Italian language support

      • vcredist_x64.exe (PID: 1688)
      • msiexec.exe (PID: 4112)
    • The sample compiled with russian language support

      • vcredist_x64.exe (PID: 1688)
      • msiexec.exe (PID: 4112)
    • The sample compiled with french language support

      • vcredist_x64.exe (PID: 1688)
      • msiexec.exe (PID: 4112)
    • The sample compiled with spanish language support

      • vcredist_x64.exe (PID: 1688)
      • msiexec.exe (PID: 4112)
    • Reads CPU info

      • Setup.exe (PID: 2996)
    • Reads the software policy settings

      • msiexec.exe (PID: 4112)
      • Setup.exe (PID: 2996)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 4112)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 4112)
    • Compiled with Borland Delphi (YARA)

      • Flicker Free 1.1.6 After Effects CE.exe (PID: 2324)
      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 4024)
    • Detects InnoSetup installer (YARA)

      • Flicker Free 1.1.6 After Effects CE.exe (PID: 2324)
      • Flicker Free 1.1.6 After Effects CE.tmp (PID: 4024)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:06 14:39:04+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 49664
UninitializedDataSize: -
EntryPoint: 0x117dc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.1.6.0
ProductVersionNumber: 1.1.6.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Digital Anarchy
FileDescription: Digital Anarchy Flicker Free AE v1.1.6
FileVersion: 1.1.6.0
LegalCopyright: Team V.R private CE build
ProductName: Digital Anarchy Flicker Free AE v1.1.6
ProductVersion: 1.1.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
8
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start flicker free 1.1.6 after effects ce.exe flicker free 1.1.6 after effects ce.tmp no specs flicker free 1.1.6 after effects ce.exe flicker free 1.1.6 after effects ce.tmp vcredist_x64.exe setup.exe msiexec.exe rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1660"C:\Users\admin\AppData\Local\Temp\is-EF3BU.tmp\Flicker Free 1.1.6 After Effects CE.tmp" /SL5="$1202BA,6401037,117248,C:\Users\admin\AppData\Local\Temp\Flicker Free 1.1.6 After Effects CE.exe" /SPAWNWND=$40354 /NOTIFYWND=$90230 C:\Users\admin\AppData\Local\Temp\is-EF3BU.tmp\Flicker Free 1.1.6 After Effects CE.tmp
Flicker Free 1.1.6 After Effects CE.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ef3bu.tmp\flicker free 1.1.6 after effects ce.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1688"C:\Users\admin\AppData\Local\Temp\is-1FV17.tmp\vcredist_x64.exe" /q /norestartC:\Users\admin\AppData\Local\Temp\is-1FV17.tmp\vcredist_x64.exe
Flicker Free 1.1.6 After Effects CE.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2010 x64 Redistributable Setup
Exit code:
0
Version:
10.0.40219.01
Modules
Images
c:\users\admin\appdata\local\temp\is-1fv17.tmp\vcredist_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2324"C:\Users\admin\AppData\Local\Temp\Flicker Free 1.1.6 After Effects CE.exe" C:\Users\admin\AppData\Local\Temp\Flicker Free 1.1.6 After Effects CE.exe
explorer.exe
User:
admin
Company:
Digital Anarchy
Integrity Level:
MEDIUM
Description:
Digital Anarchy Flicker Free AE v1.1.6
Exit code:
0
Version:
1.1.6.0
Modules
Images
c:\users\admin\appdata\local\temp\flicker free 1.1.6 after effects ce.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2996c:\b328f5d3cbe65e7ab728899c\Setup.exe /q /norestartC:\b328f5d3cbe65e7ab728899c\Setup.exe
vcredist_x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Setup Installer
Exit code:
0
Version:
10.0.40219.1 built by: SP1Rel
Modules
Images
c:\b328f5d3cbe65e7ab728899c\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
4024"C:\Users\admin\AppData\Local\Temp\is-JGB8U.tmp\Flicker Free 1.1.6 After Effects CE.tmp" /SL5="$90230,6401037,117248,C:\Users\admin\AppData\Local\Temp\Flicker Free 1.1.6 After Effects CE.exe" C:\Users\admin\AppData\Local\Temp\is-JGB8U.tmp\Flicker Free 1.1.6 After Effects CE.tmpFlicker Free 1.1.6 After Effects CE.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-jgb8u.tmp\flicker free 1.1.6 after effects ce.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
4112C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4948"C:\Users\admin\AppData\Local\Temp\Flicker Free 1.1.6 After Effects CE.exe" /SPAWNWND=$40354 /NOTIFYWND=$90230 C:\Users\admin\AppData\Local\Temp\Flicker Free 1.1.6 After Effects CE.exe
Flicker Free 1.1.6 After Effects CE.tmp
User:
admin
Company:
Digital Anarchy
Integrity Level:
HIGH
Description:
Digital Anarchy Flicker Free AE v1.1.6
Exit code:
0
Version:
1.1.6.0
Modules
Images
c:\users\admin\appdata\local\temp\flicker free 1.1.6 after effects ce.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
5060C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
Total events
8 609
Read events
8 331
Write events
270
Delete events
8

Modification events

(PID) Process:(1660) Flicker Free 1.1.6 After Effects CE.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Digital Anarchy\Flicker Free AE
Operation:writeName:Start Menu Folder
Value:
Flicker Free AE 1.1.6
(PID) Process:(1660) Flicker Free 1.1.6 After Effects CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Digital Anarchy\Flicker Free AE
Operation:writeName:InstallLocation64
Value:
C:\Program Files\Adobe\Common\Plug-ins\7.0\MediaCore
(PID) Process:(1660) Flicker Free 1.1.6 After Effects CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flicker Free AE_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.9 (u)
(PID) Process:(1660) Flicker Free 1.1.6 After Effects CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flicker Free AE_is1
Operation:writeName:Inno Setup: App Path
Value:
(PID) Process:(1660) Flicker Free 1.1.6 After Effects CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flicker Free AE_is1
Operation:writeName:Inno Setup: Icon Group
Value:
Digital Anarchy
(PID) Process:(1660) Flicker Free 1.1.6 After Effects CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flicker Free AE_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(1660) Flicker Free 1.1.6 After Effects CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flicker Free AE_is1
Operation:writeName:Inno Setup: Language
Value:
default
(PID) Process:(1660) Flicker Free 1.1.6 After Effects CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flicker Free AE_is1
Operation:writeName:DisplayName
Value:
Digital Anarchy Flicker Free AE v1.1.6
(PID) Process:(1660) Flicker Free 1.1.6 After Effects CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flicker Free AE_is1
Operation:writeName:UninstallString
Value:
"C:\ProgramData\Digital Anarchy\Flicker Free AE\unins000.exe"
(PID) Process:(1660) Flicker Free 1.1.6 After Effects CE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flicker Free AE_is1
Operation:writeName:QuietUninstallString
Value:
"C:\ProgramData\Digital Anarchy\Flicker Free AE\unins000.exe" /SILENT
Executable files
50
Suspicious files
10
Text files
53
Unknown types
11

Dropped files

PID
Process
Filename
Type
4948Flicker Free 1.1.6 After Effects CE.exeC:\Users\admin\AppData\Local\Temp\is-EF3BU.tmp\Flicker Free 1.1.6 After Effects CE.tmpexecutable
MD5:1019E9C9A41525CE57C141812DF43147
SHA256:A4484D58C6B6BF3805E04711D60416ABEC3F205567B8048BCC431F2444139DBC
1660Flicker Free 1.1.6 After Effects CE.tmpC:\Users\admin\AppData\Local\Temp\is-1FV17.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
2324Flicker Free 1.1.6 After Effects CE.exeC:\Users\admin\AppData\Local\Temp\is-JGB8U.tmp\Flicker Free 1.1.6 After Effects CE.tmpexecutable
MD5:1019E9C9A41525CE57C141812DF43147
SHA256:A4484D58C6B6BF3805E04711D60416ABEC3F205567B8048BCC431F2444139DBC
1660Flicker Free 1.1.6 After Effects CE.tmpC:\ProgramData\Digital Anarchy\Flicker Free AE\unins000.exeexecutable
MD5:C6AC3C843749443D040A4BB2E3F98CEF
SHA256:996F907BF068A9A5432879F58A998EAF74FFD28B59C38EACFB93B919842BB27E
1660Flicker Free 1.1.6 After Effects CE.tmpC:\Users\admin\AppData\Local\Temp\is-1FV17.tmp\vcredist_x64.exeexecutable
MD5:CBE0B05C11D5D523C2AF997D737C137B
SHA256:C6CD2D3F0B11DC2A604FFDC4DD97861A83B77E21709BA71B962A47759C93F4C8
1660Flicker Free 1.1.6 After Effects CE.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Digital Anarchy\Uninstall Flicker Free AE.lnklnk
MD5:90FB255BC96D36E3654EA7F08779A90A
SHA256:4E38AF1F76284FBEF1E0FD6D7B6524E1510F76331B322B22910E7474E5DE9A36
1660Flicker Free 1.1.6 After Effects CE.tmpC:\Program Files\Adobe\Common\Plug-ins\7.0\MediaCore\Digital Anarchy\Flicker Free 1.1.6\crashrpt_lang.initext
MD5:771DA39B527E886A247A0C0A33FFB715
SHA256:763F0FE5AF80055827FB2563AF696BD1452C39BE080720AB483D0CE6AC36EE92
1660Flicker Free 1.1.6 After Effects CE.tmpC:\Users\admin\AppData\Local\Temp\is-1FV17.tmp\is-PHTPK.tmpexecutable
MD5:CBE0B05C11D5D523C2AF997D737C137B
SHA256:C6CD2D3F0B11DC2A604FFDC4DD97861A83B77E21709BA71B962A47759C93F4C8
1660Flicker Free 1.1.6 After Effects CE.tmpC:\Program Files\Adobe\Common\Plug-ins\7.0\MediaCore\Digital Anarchy\Flicker Free 1.1.6\is-6MHK0.tmpexecutable
MD5:200B91B94B97F08F3EC635800A70F65D
SHA256:BB8AC78EA6CCF9280E6F8CAB70AC442008EC50913824D591E4F814554FAC7C85
1660Flicker Free 1.1.6 After Effects CE.tmpC:\Program Files\Adobe\Common\Plug-ins\7.0\MediaCore\Digital Anarchy\Flicker Free 1.1.6\is-PRMI9.tmpexecutable
MD5:FACBA7E97CA1C4D074BA567CABBFADA9
SHA256:79936C6BF54DB565864A2F89A4FA8C362F4DA00D89AF1E253D499C3C74FEF82C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
23
DNS requests
16
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4112
msiexec.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/CSPCA.crl
unknown
whitelisted
4132
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2320
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2320
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2432
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4112
msiexec.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4132
svchost.exe
40.126.31.3:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.52.120.96
  • 2.23.246.101
whitelisted
login.live.com
  • 40.126.31.3
  • 40.126.31.130
  • 20.190.159.68
  • 40.126.31.71
  • 40.126.31.131
  • 20.190.159.130
  • 20.190.159.0
  • 40.126.31.67
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.48
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Process
Message
Setup.exe
The operation completed successfully.