download:

/dl/VxJcH59AJu3gbZpQoSoA1Q/1743094620/4349826312261725872/USB+REDIRECTOR+1.9.7.exe

Full analysis: https://app.any.run/tasks/96924ba7-2c40-488d-a2d0-cd5b46695771
Verdict: Malicious activity
Analysis date: March 26, 2025, 16:57:19
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

A063E6E898B7FE2672660D22A4B3FD2F

SHA1:

506A2283F0854CDB7368758E8E82C6AA9025950B

SHA256:

70A57D334C6E757B89625A857FA330EC43B074B4F1B9990CC491D6E967C954DF

SSDEEP:

49152:ZmTRR0i90cyIw/wj3ka4NSV9dvLWqbURdk/qy3pvY2dPLUBIIOpyZP1Qpw:Zo0i90TIc4UJSpvLWdQZ3pvtdPw2IOp+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • USB+REDIRECTOR+1.9.7.exe (PID: 5428)
      • USB+REDIRECTOR+1.9.7.exe (PID: 4880)
      • usb-redirector-customer-module-gui.exe (PID: 5548)
      • usbredirectortechcsrv.exe (PID: 672)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • USB+REDIRECTOR+1.9.7.exe (PID: 4880)
      • usb-redirector-customer-module-gui.exe (PID: 5548)
      • drvinst.exe (PID: 4220)
    • Drops a system driver (possible attempt to evade defenses)

      • USB+REDIRECTOR+1.9.7.exe (PID: 4880)
      • usb-redirector-customer-module-gui.exe (PID: 5548)
      • drvinst.exe (PID: 4220)
    • Creates files in the driver directory

      • drvinst.exe (PID: 4220)
    • Executes as Windows Service

      • usbredirectortechcsrv.exe (PID: 672)
    • Reads security settings of Internet Explorer

      • ShellExperienceHost.exe (PID: 2384)
  • INFO

    • Checks supported languages

      • USB+REDIRECTOR+1.9.7.exe (PID: 4880)
      • usb-redirector-customer-module-gui.exe (PID: 5548)
      • drvinst.exe (PID: 4220)
      • usbredirectortechcsrv.exe (PID: 672)
      • ShellExperienceHost.exe (PID: 2384)
    • The sample compiled with english language support

      • USB+REDIRECTOR+1.9.7.exe (PID: 4880)
    • Reads the computer name

      • USB+REDIRECTOR+1.9.7.exe (PID: 4880)
      • usb-redirector-customer-module-gui.exe (PID: 5548)
      • drvinst.exe (PID: 4220)
      • usbredirectortechcsrv.exe (PID: 672)
      • ShellExperienceHost.exe (PID: 2384)
    • Create files in a temporary directory

      • USB+REDIRECTOR+1.9.7.exe (PID: 4880)
      • usb-redirector-customer-module-gui.exe (PID: 5548)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 4220)
    • Reads the software policy settings

      • drvinst.exe (PID: 4220)
      • BackgroundTransferHost.exe (PID: 7820)
      • slui.exe (PID: 5204)
      • slui.exe (PID: 8060)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7820)
      • BackgroundTransferHost.exe (PID: 7600)
      • BackgroundTransferHost.exe (PID: 7352)
      • BackgroundTransferHost.exe (PID: 8004)
      • BackgroundTransferHost.exe (PID: 7260)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 7820)
      • slui.exe (PID: 8060)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 7820)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:09:04 13:57:56+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 97280
InitializedDataSize: 190976
UninitializedDataSize: -
EntryPoint: 0xf2eb
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.9.7.3130
ProductVersionNumber: 1.9.7.3130
FileFlagsMask: 0x003f
FileFlags: Private build, Special build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: USB Redirector Technician Edition Customer Module Installer
CompanyName: SimplyCore LLC
FileDescription: USB Redirector Technician Edition Customer Module Installer
FileVersion: 1,9,7,3130
InternalName: usbredirector-customer-module.exe
LegalCopyright: Copyright (c) 2007 - 2019 SimplyCore LLC. All rights reserved.
LegalTrademarks: Copyright (c) 2007 - 2019 SimplyCore LLC. All rights reserved.
OriginalFileName: usbredirector-customer-module.exe
PrivateBuild: 1,9,7,3130
ProductName: USB Redirector Technician Edition Customer Module
ProductVersion: 1,9,7,3130
SpecialBuild: 1,9,7,3130
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
155
Monitored processes
14
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start usb+redirector+1.9.7.exe usb-redirector-customer-module-gui.exe drvinst.exe usbredirectortechcsrv.exe no specs sppextcomobj.exe no specs slui.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs shellexperiencehost.exe no specs slui.exe usb+redirector+1.9.7.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
672C:\Users\admin\AppData\Local\Temp\4565431a359ed81396e7b319b8786d9e\usbredirectortechcsrv.exeC:\Users\admin\AppData\Local\Temp\4565431a359ed81396e7b319b8786d9e\usbredirectortechcsrv.exeservices.exe
User:
SYSTEM
Company:
SimplyCore LLC
Integrity Level:
SYSTEM
Description:
USB Redirector Technician Edition Customer Module service
Version:
1,9,7,3130
Modules
Images
c:\users\admin\appdata\local\temp\4565431a359ed81396e7b319b8786d9e\usbredirectortechcsrv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
2384"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\wincorlib.dll
4220DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{fd65d168-c1b0-0945-877e-b039d8a7f377}\ttechusbd.inf" "9" "4b4ba34c7" "00000000000001D8" "WinSta0\Default" "00000000000001EC" "208" "C:\Users\admin\AppData\Local\Temp\4565431a359ed81396e7b319b8786d9e"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
4880"C:\Users\admin\AppData\Local\Temp\USB+REDIRECTOR+1.9.7.exe" C:\Users\admin\AppData\Local\Temp\USB+REDIRECTOR+1.9.7.exe
explorer.exe
User:
admin
Company:
SimplyCore LLC
Integrity Level:
HIGH
Description:
USB Redirector Technician Edition Customer Module Installer
Version:
1,9,7,3130
Modules
Images
c:\users\admin\appdata\local\temp\usb+redirector+1.9.7.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5156C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5204"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5428"C:\Users\admin\AppData\Local\Temp\USB+REDIRECTOR+1.9.7.exe" C:\Users\admin\AppData\Local\Temp\USB+REDIRECTOR+1.9.7.exeexplorer.exe
User:
admin
Company:
SimplyCore LLC
Integrity Level:
MEDIUM
Description:
USB Redirector Technician Edition Customer Module Installer
Exit code:
3221226540
Version:
1,9,7,3130
Modules
Images
c:\users\admin\appdata\local\temp\usb+redirector+1.9.7.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5548"C:\Users\admin\AppData\Local\Temp\4565431a359ed81396e7b319b8786d9e\usb-redirector-customer-module-gui.exe"C:\Users\admin\AppData\Local\Temp\4565431a359ed81396e7b319b8786d9e\usb-redirector-customer-module-gui.exe
USB+REDIRECTOR+1.9.7.exe
User:
admin
Company:
SimplyCore LLC
Integrity Level:
HIGH
Description:
USB Redirector Technician Edition Customer Module Setup Wizard
Version:
1,9,7,3130
Modules
Images
c:\users\admin\appdata\local\temp\4565431a359ed81396e7b319b8786d9e\usb-redirector-customer-module-gui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
7260"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7352"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
Total events
7 037
Read events
7 019
Write events
18
Delete events
0

Modification events

(PID) Process:(5548) usb-redirector-customer-module-gui.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(7600) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7600) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7600) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7820) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7820) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7820) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(8004) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(8004) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(8004) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
9
Suspicious files
17
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
4880USB+REDIRECTOR+1.9.7.exeC:\Users\admin\AppData\Local\Temp\__try__temporary__file__1097468binary
MD5:64E628C336B67B17676FDBF2DB7771D8
SHA256:E45D97F8F17D14A73127A3D969952192040D0E7801542015D45072CA47250C11
5548usb-redirector-customer-module-gui.exeC:\Users\admin\AppData\Local\Temp\{fd65d168-c1b0-0945-877e-b039d8a7f377}\ttechusbd.catbinary
MD5:54E55F7FA5338FCEDCD4F7AD582A53B2
SHA256:564ABF35EC7872F3A2288CFB7BDF675DE805335DD73743673285B59C5A4E232A
4880USB+REDIRECTOR+1.9.7.exeC:\Users\admin\AppData\Local\Temp\4565431a359ed81396e7b319b8786d9e\usb-redirector-customer-module-gui.exeexecutable
MD5:16687B591DBD936314C1EB20D61B76C4
SHA256:130DB293D102235CE86D68C5D987BE2E4D937ED0FECDE928BF913F7FD570801D
5548usb-redirector-customer-module-gui.exeC:\Users\admin\AppData\Local\Temp\{fd65d168-c1b0-0945-877e-b039d8a7f377}\ttechusbd.infbinary
MD5:34A0FAA3DA3BF4EE2E21632098CDFADF
SHA256:793E8E83B4D363C6336F663733F80BE980C7051B7C7C18A984AFC12CE1F92903
4220drvinst.exeC:\Windows\System32\DriverStore\Temp\{eb6512c5-d2b7-f045-9838-cff105aa2f64}\amd64\ttechusbd.sysexecutable
MD5:5F0645BEC453F758D2899142A7901826
SHA256:58CE3EC88300355B0AE4EA408450456F3B8A472B17CAE1D73BDC2561E3C8D05F
7820BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\c6145786-b432-4bed-8acd-6603a53699ff.down_data
MD5:
SHA256:
4220drvinst.exeC:\Windows\System32\DriverStore\Temp\{eb6512c5-d2b7-f045-9838-cff105aa2f64}\ttechusbd.catbinary
MD5:54E55F7FA5338FCEDCD4F7AD582A53B2
SHA256:564ABF35EC7872F3A2288CFB7BDF675DE805335DD73743673285B59C5A4E232A
5548usb-redirector-customer-module-gui.exeC:\Users\admin\AppData\Local\Temp\{fd65d168-c1b0-0945-877e-b039d8a7f377}\SETCD25.tmpbinary
MD5:54E55F7FA5338FCEDCD4F7AD582A53B2
SHA256:564ABF35EC7872F3A2288CFB7BDF675DE805335DD73743673285B59C5A4E232A
5548usb-redirector-customer-module-gui.exeC:\Users\admin\AppData\Local\Temp\{fd65d168-c1b0-0945-877e-b039d8a7f377}\SETCD36.tmpbinary
MD5:34A0FAA3DA3BF4EE2E21632098CDFADF
SHA256:793E8E83B4D363C6336F663733F80BE980C7051B7C7C18A984AFC12CE1F92903
5548usb-redirector-customer-module-gui.exeC:\Users\admin\AppData\Local\Temp\{fd65d168-c1b0-0945-877e-b039d8a7f377}\amd64\SETCD47.tmpexecutable
MD5:5F0645BEC453F758D2899142A7901826
SHA256:58CE3EC88300355B0AE4EA408450456F3B8A472B17CAE1D73BDC2561E3C8D05F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
25
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7820
BackgroundTransferHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2320
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1764
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1764
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.172.255.217:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6544
svchost.exe
40.126.31.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2320
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2320
backgroundTaskHost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
7820
BackgroundTransferHost.exe
2.16.241.222:443
www.bing.com
Akamai International B.V.
DE
whitelisted
7820
BackgroundTransferHost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.18.14
whitelisted
client.wns.windows.com
  • 172.172.255.217
whitelisted
login.live.com
  • 40.126.31.131
  • 40.126.31.1
  • 20.190.159.130
  • 40.126.31.128
  • 20.190.159.75
  • 20.190.159.23
  • 20.190.159.128
  • 20.190.159.131
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
www.bing.com
  • 2.16.241.222
  • 2.16.241.204
  • 2.16.241.216
  • 2.16.241.225
  • 2.16.241.205
  • 2.16.241.207
  • 2.16.241.201
  • 2.16.241.218
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted

Threats

No threats detected
No debug info