File name:

ConnectifyInstaller.exe

Full analysis: https://app.any.run/tasks/88bbc7d1-e9f4-4e78-9703-465a34310b02
Verdict: Malicious activity
Analysis date: October 03, 2025, 17:27:34
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

E67EAD35EFAD0418B476AA8A0B2BB99B

SHA1:

A532EF8ADA4DA7CE99B1EB180FE2A8E8C187020F

SHA256:

71B6E6B27F6B1742ACF06C70EBDC524F0DD6DC790898B5A6E44160BB2862065D

SSDEEP:

98304:Hbfyhtf13BeWid1GexelE1nA1PGD447BjfrSOHMCc2dak71nqFCSxvpcoSp6NNKV:dSBXswRQT4DFHu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • ConnectifyInstaller.exe (PID: 5424)
      • ConnectifyInstaller.exe (PID: 2092)
      • Analytics.exe (PID: 7556)
      • Analytics.exe (PID: 4696)
      • Analytics.exe (PID: 1836)
      • GlobalAtomTable.exe (PID: 7588)
      • ConnectifySupportCenter.exe (PID: 796)
      • Analytics.exe (PID: 8968)
      • Analytics.exe (PID: 8908)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • ConnectifyInstaller.exe (PID: 5424)
      • ConnectifyInstaller.exe (PID: 2092)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • ConnectifyInstaller.exe (PID: 5424)
      • ConnectifyInstaller.exe (PID: 2092)
    • Executable content was dropped or overwritten

      • ConnectifyInstaller.exe (PID: 5424)
      • ConnectifyInstaller.exe (PID: 2092)
    • Reads security settings of Internet Explorer

      • ConnectifyInstaller.exe (PID: 5424)
    • Reads the date of Windows installation

      • ConnectifyInstaller.exe (PID: 5424)
    • Application launched itself

      • ConnectifyInstaller.exe (PID: 5424)
      • Analytics.exe (PID: 4696)
      • Analytics.exe (PID: 8908)
    • There is functionality for taking screenshot (YARA)

      • ConnectifyInstaller.exe (PID: 5424)
      • ConnectifyInstaller.exe (PID: 2092)
      • ConnectifySupportCenter.exe (PID: 796)
  • INFO

    • Create files in a temporary directory

      • ConnectifyInstaller.exe (PID: 5424)
      • ConnectifyInstaller.exe (PID: 2092)
    • Checks supported languages

      • ConnectifyInstaller.exe (PID: 5424)
      • ConnectifyInstaller.exe (PID: 2092)
      • Analytics.exe (PID: 4696)
      • Analytics.exe (PID: 1836)
      • Analytics.exe (PID: 7556)
      • ConnectifySupportCenter.exe (PID: 796)
      • GlobalAtomTable.exe (PID: 7588)
      • Analytics.exe (PID: 8908)
      • ConnectifyShutdown.exe (PID: 9012)
      • Analytics.exe (PID: 8968)
    • Reads the computer name

      • ConnectifyInstaller.exe (PID: 5424)
      • ConnectifyInstaller.exe (PID: 2092)
      • Analytics.exe (PID: 7556)
      • Analytics.exe (PID: 4696)
      • Analytics.exe (PID: 1836)
      • ConnectifySupportCenter.exe (PID: 796)
      • Analytics.exe (PID: 8908)
      • Analytics.exe (PID: 8968)
      • ConnectifyShutdown.exe (PID: 9012)
    • Process checks whether UAC notifications are on

      • ConnectifyInstaller.exe (PID: 5424)
    • Process checks computer location settings

      • ConnectifyInstaller.exe (PID: 5424)
    • The sample compiled with english language support

      • ConnectifyInstaller.exe (PID: 2092)
    • Reads the machine GUID from the registry

      • Analytics.exe (PID: 4696)
      • Analytics.exe (PID: 7556)
      • Analytics.exe (PID: 1836)
      • ConnectifySupportCenter.exe (PID: 796)
      • Analytics.exe (PID: 8968)
      • ConnectifyShutdown.exe (PID: 9012)
      • Analytics.exe (PID: 8908)
    • Creates files in the program directory

      • Analytics.exe (PID: 1836)
      • ConnectifyInstaller.exe (PID: 2092)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 8832)
      • BackgroundTransferHost.exe (PID: 3116)
      • BackgroundTransferHost.exe (PID: 8416)
      • BackgroundTransferHost.exe (PID: 8600)
      • BackgroundTransferHost.exe (PID: 9036)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 8416)
      • slui.exe (PID: 8320)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 8416)
      • slui.exe (PID: 8320)
      • Analytics.exe (PID: 1836)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 8416)
    • Disables trace logs

      • Analytics.exe (PID: 1836)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 22:53:18+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25088
InitializedDataSize: 124928
UninitializedDataSize: 1024
EntryPoint: 0x36a0
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
193
Monitored processes
22
Malicious processes
4
Suspicious processes
5

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
708\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAnalytics.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
796"C:\Users\admin\AppData\Local\Temp\Connectify\3\ConnectifySupportCenter.exe" connectifysupport://swcheck ConnectifyC:\Users\admin\AppData\Local\Temp\Connectify\3\ConnectifySupportCenter.exeConnectifyInstaller.exe
User:
admin
Company:
Connectify
Integrity Level:
HIGH
Description:
Connectify Hotspot Support Center
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\connectify\3\connectifysupportcenter.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1836"C:\Users\admin\AppData\Local\Temp\Connectify\3\Analytics.exe" navigation Installer Init 7.1.0.29279 NoneC:\Users\admin\AppData\Local\Temp\Connectify\3\Analytics.exe
Analytics.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Analytics
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\connectify\3\analytics.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2092"C:\Users\admin\AppData\Local\Temp\ConnectifyInstaller.exe" /UAC:50310 /NCRC C:\Users\admin\AppData\Local\Temp\ConnectifyInstaller.exe
ConnectifyInstaller.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\connectifyinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2368\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeGlobalAtomTable.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3116"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
4696"C:\Users\admin\AppData\Local\Temp\Connectify\3\Analytics.exe" daemon navigation Installer Init 7.1.0.29279 NoneC:\Users\admin\AppData\Local\Temp\Connectify\3\Analytics.exeConnectifyInstaller.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Analytics
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\connectify\3\analytics.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5424"C:\Users\admin\AppData\Local\Temp\ConnectifyInstaller.exe" C:\Users\admin\AppData\Local\Temp\ConnectifyInstaller.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\connectifyinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5792\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAnalytics.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6292\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAnalytics.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
14 145
Read events
14 112
Write events
33
Delete events
0

Modification events

(PID) Process:(7556) Analytics.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Connectify
Operation:writeName:InstallDate
Value:
10/3/2025
(PID) Process:(7556) Analytics.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Connectify
Operation:writeName:Source
Value:
dispatch_
(PID) Process:(1836) Analytics.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Analytics_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1836) Analytics.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Analytics_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(1836) Analytics.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Analytics_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1836) Analytics.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Analytics_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1836) Analytics.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Analytics_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(1836) Analytics.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Analytics_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(1836) Analytics.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Analytics_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(1836) Analytics.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Analytics_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
Executable files
32
Suspicious files
33
Text files
120
Unknown types
0

Dropped files

PID
Process
Filename
Type
2092ConnectifyInstaller.exeC:\Users\admin\AppData\Local\Temp\nst18D9.tmp\System.dllexecutable
MD5:C17103AE9072A06DA581DEC998343FC1
SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F
2092ConnectifyInstaller.exeC:\Users\admin\AppData\Local\Temp\nst18D9.tmp\modern-header.bmpimage
MD5:06D1C9640315DBE3AD514CB3A8E11A7F
SHA256:C4EC072EBA73B1D914E914CBEA632B1608689C5610C31D94DD0A391F7F1A0DBE
5424ConnectifyInstaller.exeC:\Users\admin\AppData\Local\Temp\nsb1399.tmp\System.dllexecutable
MD5:C17103AE9072A06DA581DEC998343FC1
SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F
2092ConnectifyInstaller.exeC:\Users\admin\AppData\Local\Temp\nst18D9.tmp\UAC.dllexecutable
MD5:7F56C0D6A8733DEC142814ED5A58B0EE
SHA256:86445396775370AFF5834F10BDA25E505B6F89EFC69A04FE1CE46F5D128BE73F
5424ConnectifyInstaller.exeC:\Users\admin\AppData\Local\Temp\nsb1399.tmp\modern-wizard.bmpimage
MD5:AE43624C14859150EDFB54B4024AFF46
SHA256:D5B56046F10941E6659277D46FFD4A0D327DB24BE3174D6A8E7AE0660DA874E9
2092ConnectifyInstaller.exeC:\Users\admin\AppData\Local\Temp\nst18D9.tmp\modern-wizard.bmpimage
MD5:AE43624C14859150EDFB54B4024AFF46
SHA256:D5B56046F10941E6659277D46FFD4A0D327DB24BE3174D6A8E7AE0660DA874E9
2092ConnectifyInstaller.exeC:\Users\admin\AppData\Local\Temp\Connectify\3\Analytics.exeexecutable
MD5:05712885EF39A6D6DAAD0EB884763946
SHA256:D88789C5D5C5855CEC6EEFE3BFDB948F1C6E1033C02C3F947B71DDF93FB181AC
2092ConnectifyInstaller.exeC:\Users\admin\AppData\Local\Temp\nst18D9.tmp\md5dll.dllexecutable
MD5:7059F133EA2316B9E7E39094A52A8C34
SHA256:32C3D36F38E7E8A8BAFD4A53663203EF24A10431BDA16AF9E353C7D5D108610F
2092ConnectifyInstaller.exeC:\Users\admin\AppData\Local\Temp\Connectify\3\Connectify.exeexecutable
MD5:52AF43B5AC5AED5DE13E60E72B9CBAF1
SHA256:8465840E31D9F906BFA2FBF596F8FBB9BBD7A01FCF777829FCFC8744BEACB825
2092ConnectifyInstaller.exeC:\Users\admin\AppData\Local\Temp\Connectify\3\Connectify.exe.configxml
MD5:2E8901597468F263A183DCA9C59F1330
SHA256:9A38F15BF07CD33E7FBFBF93000982575FC6A37DCBE0E98BC90EB488F49E41AD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
36
DNS requests
19
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4936
svchost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
4936
svchost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
6208
backgroundTaskHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
4176
backgroundTaskHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
8416
BackgroundTransferHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
5792
backgroundTaskHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
1836
Analytics.exe
GET
200
142.250.185.78:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=571013505&utmhn=connectify.connectify.me&utmp=Installer%2fInit%2f7.1.0.29279%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1814719801.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fInit%2f7.1.0.29279%2fNone%3B&utmul=en&utmdebug=ON
US
image
35 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7072
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5224
SearchApp.exe
95.101.142.200:443
www.bing.com
Akamai International B.V.
SE
whitelisted
4
System
192.168.100.255:138
whitelisted
1836
Analytics.exe
142.250.185.78:80
www.google-analytics.com
GOOGLE
US
whitelisted
4936
svchost.exe
20.190.160.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4936
svchost.exe
172.66.2.5:80
ocsp.digicert.com
US
whitelisted
6208
backgroundTaskHost.exe
104.84.152.9:443
www.bing.com
Akamai International B.V.
SE
whitelisted
6208
backgroundTaskHost.exe
172.66.2.5:80
ocsp.digicert.com
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
www.bing.com
  • 95.101.142.200
  • 95.101.142.187
  • 95.101.142.194
  • 95.101.142.208
  • 95.101.142.209
  • 95.101.142.186
  • 95.101.142.203
  • 95.101.142.192
  • 95.101.142.193
  • 104.84.152.9
  • 95.101.142.227
  • 104.84.152.25
  • 95.101.142.232
  • 104.84.152.24
  • 95.101.142.226
  • 104.84.152.19
  • 104.84.152.8
  • 104.84.152.18
whitelisted
google.com
  • 172.217.16.206
whitelisted
www.google-analytics.com
  • 142.250.185.78
whitelisted
login.live.com
  • 20.190.160.2
  • 40.126.32.138
  • 20.190.160.65
  • 20.190.160.3
  • 20.190.160.66
  • 20.190.160.130
  • 20.190.160.20
  • 40.126.32.76
whitelisted
ocsp.digicert.com
  • 172.66.2.5
  • 162.159.142.9
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
arc.msn.com
  • 20.31.169.57
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
slscr.update.microsoft.com
  • 74.178.76.128
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info