File name:

tdr_vos_slickeq_installer.zip

Full analysis: https://app.any.run/tasks/36f7de28-939e-4973-be37-48b7495642ef
Verdict: Malicious activity
Analysis date: May 15, 2025, 15:39:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
inno
installer
delphi
qrcode
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

560BF8E60C93C2B1DB788E4B93547ECD

SHA1:

CE8B66217E11AFD832341E6BD8A2A98D39364DD2

SHA256:

73713B639CA87DB4DC8584EB951D35508D470B21012A71A966680FABBC2D398A

SSDEEP:

98304:oGmnoOmXDx7hQ4kcou/UXdevvMk98MZsucCbyv5eR1xAL0MGq6sIFNO9Mz1ClQdS:44OfnCg/dbuR4in34oq0cb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7608)
      • TDR VOS SlickEQ - setup.tmp (PID: 2140)
      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
    • Start notepad (likely ransomware note)

      • WinRAR.exe (PID: 7608)
    • Executable content was dropped or overwritten

      • TDR VOS SlickEQ - setup.exe (PID: 6620)
      • TDR VOS SlickEQ - setup.exe (PID: 7504)
      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
    • Process drops legitimate windows executable

      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
    • Reads the Windows owner or organization settings

      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
  • INFO

    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 7608)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7608)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 7328)
      • notepad.exe (PID: 6044)
    • Create files in a temporary directory

      • TDR VOS SlickEQ - setup.exe (PID: 6620)
      • TDR VOS SlickEQ - setup.exe (PID: 7504)
      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
    • Manual execution by a user

      • TDR VOS SlickEQ - setup.exe (PID: 6620)
      • msedge.exe (PID: 1676)
    • Checks supported languages

      • TDR VOS SlickEQ - setup.exe (PID: 6620)
      • TDR VOS SlickEQ - setup.tmp (PID: 2140)
      • TDR VOS SlickEQ - setup.exe (PID: 7504)
      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
    • Reads the computer name

      • TDR VOS SlickEQ - setup.tmp (PID: 2140)
      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
    • Process checks computer location settings

      • TDR VOS SlickEQ - setup.tmp (PID: 2140)
    • Compiled with Borland Delphi (YARA)

      • TDR VOS SlickEQ - setup.exe (PID: 6620)
      • TDR VOS SlickEQ - setup.tmp (PID: 2140)
      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
      • TDR VOS SlickEQ - setup.exe (PID: 7504)
    • Detects InnoSetup installer (YARA)

      • TDR VOS SlickEQ - setup.exe (PID: 6620)
      • TDR VOS SlickEQ - setup.exe (PID: 7504)
      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
      • TDR VOS SlickEQ - setup.tmp (PID: 2140)
    • The sample compiled with english language support

      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
    • Reads the software policy settings

      • slui.exe (PID: 7748)
    • Creates files in the program directory

      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
    • Creates a software uninstall entry

      • TDR VOS SlickEQ - setup.tmp (PID: 5428)
    • Application launched itself

      • msedge.exe (PID: 1676)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2016:09:21 23:54:28
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: TDR VOS SlickEQ (installer)/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
194
Monitored processes
59
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe notepad.exe no specs notepad.exe no specs tdr vos slickeq - setup.exe tdr vos slickeq - setup.tmp no specs tdr vos slickeq - setup.exe tdr vos slickeq - setup.tmp slui.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7492 --field-trial-handle=2280,i,10094091021472770268,3602072454997284195,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
680"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7972 --field-trial-handle=2280,i,10094091021472770268,3602072454997284195,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
900"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=29 --mojo-platform-channel-handle=7468 --field-trial-handle=2280,i,10094091021472770268,3602072454997284195,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1052"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=6736 --field-trial-handle=2280,i,10094091021472770268,3602072454997284195,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1676"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=DefaultC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1812C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2140"C:\Users\admin\AppData\Local\Temp\is-97G6K.tmp\TDR VOS SlickEQ - setup.tmp" /SL5="$E02DE,6241002,123904,C:\Users\admin\Desktop\TDR VOS SlickEQ - setup.exe" C:\Users\admin\AppData\Local\Temp\is-97G6K.tmp\TDR VOS SlickEQ - setup.tmpTDR VOS SlickEQ - setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-97g6k.tmp\tdr vos slickeq - setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2192"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5808 --field-trial-handle=2280,i,10094091021472770268,3602072454997284195,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2192"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7812 --field-trial-handle=2280,i,10094091021472770268,3602072454997284195,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2288"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=40 --mojo-platform-channel-handle=7464 --field-trial-handle=2280,i,10094091021472770268,3602072454997284195,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
10 383
Read events
10 289
Write events
94
Delete events
0

Modification events

(PID) Process:(7608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\tdr_vos_slickeq_installer.zip
(PID) Process:(7608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithProgids
Operation:writeName:txtfile
Value:
(PID) Process:(5428) TDR VOS SlickEQ - setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TDR VOS SlickEQ_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.4 (u)
Executable files
46
Suspicious files
647
Text files
85
Unknown types
4

Dropped files

PID
Process
Filename
Type
5428TDR VOS SlickEQ - setup.tmpC:\Users\admin\Desktop\TDR VOS SlickEQ (x64).dllbinary
MD5:F73D5D48B993D16AB316EB2B23903676
SHA256:42E1F3896FB53A63594941E0EC647B7A4A242705D95477C7CB56BD6264FA2812
7504TDR VOS SlickEQ - setup.exeC:\Users\admin\AppData\Local\Temp\is-1F9BU.tmp\TDR VOS SlickEQ - setup.tmpexecutable
MD5:1E7B43852A0C836B8C6220E87E7E1A24
SHA256:0DE0938B2C352254165176EC6A87E62139FCF501ECEA336B2308893D839F62B4
7608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa7608.41189\ReadMe.txttext
MD5:C63B1DA69CAA85D52B7CC6C19E6077E8
SHA256:7A8ACC7A69EE44FB6F3F8FB94509E4EBE6AAB941A1006854BB48422782007636
7608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7608.41003\TDR VOS SlickEQ (installer)\TDR VOS SlickEQ - setup.exeexecutable
MD5:9E45FA4B94B185452CA297A625EB2ABB
SHA256:D58B075D1B76C1DA4AC09E9EF536E47F78606115A40960D3350385671B06FF24
5428TDR VOS SlickEQ - setup.tmpC:\Program Files\Tokyo Dawn Labs\TDR VOS SlickEQ\unins000.exeexecutable
MD5:1E7B43852A0C836B8C6220E87E7E1A24
SHA256:0DE0938B2C352254165176EC6A87E62139FCF501ECEA336B2308893D839F62B4
5428TDR VOS SlickEQ - setup.tmpC:\Users\admin\AppData\Local\Temp\is-AJ72P.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
5428TDR VOS SlickEQ - setup.tmpC:\Users\admin\AppData\Local\Temp\is-AJ72P.tmp\_isetup\_setup64.tmpexecutable
MD5:526426126AE5D326D0A24706C77D8C5C
SHA256:B20A8D88C550981137ED831F2015F5F11517AEB649C29642D9D61DEA5EBC37D1
7608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa7608.41283\ReadMe.txttext
MD5:C63B1DA69CAA85D52B7CC6C19E6077E8
SHA256:7A8ACC7A69EE44FB6F3F8FB94509E4EBE6AAB941A1006854BB48422782007636
6620TDR VOS SlickEQ - setup.exeC:\Users\admin\AppData\Local\Temp\is-97G6K.tmp\TDR VOS SlickEQ - setup.tmpexecutable
MD5:1E7B43852A0C836B8C6220E87E7E1A24
SHA256:0DE0938B2C352254165176EC6A87E62139FCF501ECEA336B2308893D839F62B4
5428TDR VOS SlickEQ - setup.tmpC:\Program Files\Tokyo Dawn Labs\TDR VOS SlickEQ\is-BV7U2.tmpexecutable
MD5:1E7B43852A0C836B8C6220E87E7E1A24
SHA256:0DE0938B2C352254165176EC6A87E62139FCF501ECEA336B2308893D839F62B4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
281
DNS requests
293
Threats
70

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.25.50.8:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
8132
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8132
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1452
svchost.exe
GET
206
208.89.74.23:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1747803129&P2=404&P3=2&P4=gMRJjuKgXr4D%2bE8SN6qlcHJUx21f6K8G1xoXSNqM6n86HzvDNFtgsljtK6USvnLFfDgW%2fIldyyDRlVkYI%2bs%2f7Q%3d%3d
unknown
whitelisted
1452
svchost.exe
HEAD
200
208.89.74.23:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1747803129&P2=404&P3=2&P4=gMRJjuKgXr4D%2bE8SN6qlcHJUx21f6K8G1xoXSNqM6n86HzvDNFtgsljtK6USvnLFfDgW%2fIldyyDRlVkYI%2bs%2f7Q%3d%3d
unknown
whitelisted
1452
svchost.exe
GET
206
208.89.74.23:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1747803129&P2=404&P3=2&P4=gMRJjuKgXr4D%2bE8SN6qlcHJUx21f6K8G1xoXSNqM6n86HzvDNFtgsljtK6USvnLFfDgW%2fIldyyDRlVkYI%2bs%2f7Q%3d%3d
unknown
whitelisted
1452
svchost.exe
GET
206
208.89.74.23:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1747803129&P2=404&P3=2&P4=gMRJjuKgXr4D%2bE8SN6qlcHJUx21f6K8G1xoXSNqM6n86HzvDNFtgsljtK6USvnLFfDgW%2fIldyyDRlVkYI%2bs%2f7Q%3d%3d
unknown
whitelisted
1452
svchost.exe
GET
206
208.89.74.23:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1747803129&P2=404&P3=2&P4=gMRJjuKgXr4D%2bE8SN6qlcHJUx21f6K8G1xoXSNqM6n86HzvDNFtgsljtK6USvnLFfDgW%2fIldyyDRlVkYI%2bs%2f7Q%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
184.25.50.8:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.1:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 184.25.50.8
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 142.250.185.110
  • 142.250.184.238
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.31.1
  • 40.126.31.71
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

PID
Process
Class
Message
7384
msedge.exe
Misc activity
ET FILE_SHARING File Sharing Service Domain in DNS Lookup (dropmefiles .com)
7384
msedge.exe
Misc activity
ET FILE_SHARING File Sharing Service Domain in DNS Lookup (dropmefiles .com)
7384
msedge.exe
Misc activity
ET FILE_SHARING File Sharing Service Domain in DNS Lookup (dropmefiles .com)
7384
msedge.exe
Misc activity
ET FILE_SHARING File Sharing Service Domain in DNS Lookup (dropmefiles .com)
7384
msedge.exe
Misc activity
ET FILE_SHARING File Sharing Service Domain in DNS Lookup (dropmefiles .com)
7384
msedge.exe
Misc activity
ET FILE_SHARING File Sharing Service Domain in DNS Lookup (dropmefiles .com)
7384
msedge.exe
Misc activity
ET FILE_SHARING File Sharing Service Domain in DNS Lookup (dropmefiles .com)
7384
msedge.exe
Misc activity
ET FILE_SHARING File Sharing Service Domain in DNS Lookup (dropmefiles .com)
7384
msedge.exe
Misc activity
ET FILE_SHARING File Sharing Service Domain in DNS Lookup (dropmefiles .com)
7384
msedge.exe
Misc activity
ET FILE_SHARING File Sharing Service Domain in DNS Lookup (dropmefiles .com)
No debug info