File name:

SkypeMeetingsApp.msi

Full analysis: https://app.any.run/tasks/f9b6d6b5-a857-49c3-a144-eb49705d7168
Verdict: Malicious activity
Analysis date: May 15, 2025, 06:24:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Skype Meetings App, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Skype Meetings App., Template: Intel;0, Revision Number: {C6C0F413-901C-42A8-A7F1-D03BD40F9B12}, Create Time/Date: Sat Aug 3 05:00:26 2019, Last Saved Time/Date: Sat Aug 3 05:00:26 2019, Number of Pages: 300, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.11.1.2318), Security: 2
MD5:

2401C281F6798633B66B2A4A14937354

SHA1:

632C80EA6699C5A6A4D6247182DAA92A3BF60913

SHA256:

73FDFB85B80B81C87E78580DC5B46A73C73F7907F8E6CFF0886DCB6493365255

SSDEEP:

98304:MpJSNn/rIB9Kr4BQhhTXvKEXV7RXIgk0vL6mKT9nX3DA4nFkgxJotrWP8yX8AshY:LozTkVfJFyXUgT/DmhGRRvP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • msiexec.exe (PID: 7232)
      • msiexec.exe (PID: 7412)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7412)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 7412)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 7412)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 7544)
      • Skype Meetings App.exe (PID: 1272)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 7412)
  • INFO

    • The sample compiled with english language support

      • msiexec.exe (PID: 7232)
      • msiexec.exe (PID: 7412)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 7232)
    • Reads the software policy settings

      • msiexec.exe (PID: 7232)
      • msiexec.exe (PID: 7412)
      • Skype Meetings App.exe (PID: 1272)
      • slui.exe (PID: 6656)
    • Checks proxy server information

      • msiexec.exe (PID: 7232)
      • Skype Meetings App.exe (PID: 1272)
      • slui.exe (PID: 6656)
    • Reads the computer name

      • msiexec.exe (PID: 7412)
      • msiexec.exe (PID: 7544)
      • Skype Meetings App.exe (PID: 1272)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 7232)
      • msiexec.exe (PID: 7412)
      • Skype Meetings App.exe (PID: 1272)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 7412)
      • Skype Meetings App.exe (PID: 1272)
    • Checks supported languages

      • msiexec.exe (PID: 7544)
      • msiexec.exe (PID: 7412)
      • Skype Meetings App.exe (PID: 1272)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7412)
    • Manual execution by a user

      • firefox.exe (PID: 7652)
    • Application launched itself

      • firefox.exe (PID: 7652)
      • firefox.exe (PID: 7672)
    • Create files in a temporary directory

      • Skype Meetings App.exe (PID: 1272)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 7412)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Skype Meetings App
Author: Microsoft Corporation
Keywords: Installer
Comments: This installer database contains the logic and data required to install Skype Meetings App.
Template: Intel;0
RevisionNumber: {C6C0F413-901C-42A8-A7F1-D03BD40F9B12}
CreateDate: 2019:08:03 05:00:26
ModifyDate: 2019:08:03 05:00:26
Pages: 300
Words: 10
Software: Windows Installer XML Toolset (3.11.1.2318)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
16
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs skype meetings app.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
1072"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2728 -childID 1 -isForBrowser -prefsHandle 2780 -prefMapHandle 2976 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1536 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4269e55c-d6fb-442f-bc26-64ceaf6b7994} 7672 "\\.\pipe\gecko-crash-server-pipe.7672" 1616e1f4f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
1272"C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\Skype Meetings App.exe" -autostartC:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\Skype Meetings App.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Skype Meetings App
Exit code:
0
Version:
16.2.0.511
Modules
Images
c:\users\admin\appdata\local\microsoft\skypeforbusinessplugin\16.2.0.511\skype meetings app.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ws2_32.dll
c:\windows\syswow64\rpcrt4.dll
5376"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4388 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 4820 -prefMapHandle 4816 -prefsLen 36588 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d278c8f1-0511-4586-ba09-b9f3fc9fbe75} 7672 "\\.\pipe\gecko-crash-server-pipe.7672" 1617174a910 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
5960"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2084 -childID 3 -isForBrowser -prefsHandle 4836 -prefMapHandle 4824 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1536 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {bc995979-6d1f-41dd-9ec7-3846dedd6e05} 7672 "\\.\pipe\gecko-crash-server-pipe.7672" 16171463f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
6068"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4340 -childID 2 -isForBrowser -prefsHandle 4332 -prefMapHandle 4328 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1536 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ee0b01ac-474b-4110-95e8-1359b9c5621e} 7672 "\\.\pipe\gecko-crash-server-pipe.7672" 1616fb7ad90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
6656C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7232"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\Desktop\SkypeMeetingsApp.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7380"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4736 -childID 4 -isForBrowser -prefsHandle 4804 -prefMapHandle 4800 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1536 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {289dab9c-452b-425e-90d4-34390c352138} 7672 "\\.\pipe\gecko-crash-server-pipe.7672" 16171463850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
7412C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7444"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5104 -childID 5 -isForBrowser -prefsHandle 4908 -prefMapHandle 5016 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1536 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {da68a42e-8510-402b-86a4-3ed7ea5f3dd6} 7672 "\\.\pipe\gecko-crash-server-pipe.7672" 16172779f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
22 348
Read events
22 077
Write events
266
Delete events
5

Modification events

(PID) Process:(7412) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(7412) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10b7ea.rbs
Value:
31180130
(PID) Process:(7412) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10b7ea.rbsLow
Value:
60641520
(PID) Process:(7412) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Users\admin\AppData\Roaming\Microsoft\Installer\
Value:
(PID) Process:(7412) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\09DAC598233E9F74CBBD77620BB2AE5D
Operation:writeName:74E9D1CB72981AA48A197736CB42577B
Value:
C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\
(PID) Process:(7412) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\B292FA1EE979F09449473FE50BE44675
Operation:writeName:74E9D1CB72981AA48A197736CB42577B
Value:
C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\PluginHost.exe
(PID) Process:(7412) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\B9CC14FF144022F4283B53686131CEE9
Operation:writeName:74E9D1CB72981AA48A197736CB42577B
Value:
C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\GatewayActiveX.dll
(PID) Process:(7412) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\D09D297D2C5539849AD357A3E3596DF3
Operation:writeName:74E9D1CB72981AA48A197736CB42577B
Value:
C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\GatewayActiveX-x64.dll
(PID) Process:(7412) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\F09215C668571414F95D3FBFA3F9E570
Operation:writeName:74E9D1CB72981AA48A197736CB42577B
Value:
C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\npGatewayNpapi.dll
(PID) Process:(7412) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\051DE9DE7C7E85D4FB2C88844E217E96
Operation:writeName:74E9D1CB72981AA48A197736CB42577B
Value:
C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\appshvw.dll
Executable files
51
Suspicious files
250
Text files
29
Unknown types
0

Dropped files

PID
Process
Filename
Type
7412msiexec.exeC:\Windows\Installer\10b7e8.msi
MD5:
SHA256:
7232msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C0018BB1B5834735BFA60CD063B31956binary
MD5:9B2509CFF42DFCEC25276BCC225CC4A4
SHA256:7335A1BD971D1CAF943246E1705CE2D10F83FE6A34438128D2C0CF3738FEE8AB
7232msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEbinary
MD5:0F7B8F6A846AA9CA52FA562DDDCDB5ED
SHA256:AFF90E65A81289B80D1FCC5E71B3D88E5D1AAFE22CE358EB6E28A56D1845263D
7412msiexec.exeC:\Windows\Installer\MSIBBC3.tmpexecutable
MD5:E4ADC08E8BB63B84431B1E914E05D53D
SHA256:280C1AC6326078393A389F122A5EED88C1A29E33E787A2CC0BC9BEB04F43E90F
7412msiexec.exeC:\Windows\Installer\MSIBCB0.tmpexecutable
MD5:D773D9BD091E712DF7560F576DA53DE8
SHA256:E0DB1804CF53ED4819ED70CB35C67680CE1A77573EFDED86E6DAC81010CE55E7
7412msiexec.exeC:\Windows\Installer\MSIBDCA.tmpexecutable
MD5:D773D9BD091E712DF7560F576DA53DE8
SHA256:E0DB1804CF53ED4819ED70CB35C67680CE1A77573EFDED86E6DAC81010CE55E7
7232msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:B3743601D7E7E1B365A4D877ECA181DE
SHA256:B1D66BD4CDB75B2EB9EC5CD2AFCC82840587179BF6F022B6C93F9EB90C0B1DBD
7232msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C0018BB1B5834735BFA60CD063B31956binary
MD5:126B5A0000BC7A05F38769EA41064409
SHA256:D5A3DE18695928F9BDB65F0F939BBEDDC4330112F34C65DE5C060E8F9F9FF1E7
7412msiexec.exeC:\Windows\Installer\MSIB9AD.tmpexecutable
MD5:E4ADC08E8BB63B84431B1E914E05D53D
SHA256:280C1AC6326078393A389F122A5EED88C1A29E33E787A2CC0BC9BEB04F43E90F
7412msiexec.exeC:\Windows\Installer\MSIBA3B.tmpexecutable
MD5:E4ADC08E8BB63B84431B1E914E05D53D
SHA256:280C1AC6326078393A389F122A5EED88C1A29E33E787A2CC0BC9BEB04F43E90F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
36
TCP/UDP connections
95
DNS requests
127
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7232
msiexec.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
7232
msiexec.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2104
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7672
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
7672
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
7672
firefox.exe
POST
200
184.24.77.48:80
http://r11.o.lencr.org/
unknown
whitelisted
7672
firefox.exe
POST
200
172.217.16.195:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
7672
firefox.exe
POST
200
184.24.77.48:80
http://r11.o.lencr.org/
unknown
whitelisted
7672
firefox.exe
POST
200
184.24.77.48:80
http://r11.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2104
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
7232
msiexec.exe
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
7232
msiexec.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7672
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
google.com
  • 172.217.16.206
whitelisted
meet.skype.com
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 96.7.128.186
  • 23.215.0.133
  • 23.215.0.132
  • 96.7.128.192
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted

Threats

No threats detected
No debug info