File name:

SHAMA-Installer-3.0.5.exe

Full analysis: https://app.any.run/tasks/a931b171-b2b8-493e-8e6c-6dbc2bf7d8c5
Verdict: Malicious activity
Analysis date: April 14, 2026, 22:17:55
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
golang
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

918A2C241BB9D2B0964FC407E0B339C6

SHA1:

FA0A228A96E6791D979955B6F1A86853D44A6DC4

SHA256:

76699DCB18ED7A50BC1B2F8E75EDE7FC2021445C1F9E0872084C203A032BC176

SSDEEP:

98304:kFuZCYJwvCePyUt3oKdo26gJAvN+Y4b+Jd/LaU69ZpChXp2ukrBzZV1q0bkq7lPI:m7JkkucQ1oSSRP9Ki88C/D2Ub6S5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SHAMA-Installer-3.0.5.exe (PID: 6576)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • SHAMA-Installer-3.0.5.exe (PID: 6576)
    • The process creates files with name similar to system file names

      • SHAMA-Installer-3.0.5.exe (PID: 6576)
    • Reads the date of Windows installation

      • PORTAL WG.exe (PID: 6472)
    • Application launched itself

      • PORTAL WG.exe (PID: 6472)
      • PORTAL WG.exe (PID: 6208)
    • Executes as Windows Service

      • PORTAL WG.exe (PID: 6208)
  • INFO

    • Checks supported languages

      • SHAMA-Installer-3.0.5.exe (PID: 6576)
      • PORTAL WG.exe (PID: 6472)
      • PORTAL WG.exe (PID: 6832)
      • PORTAL WG.exe (PID: 6892)
      • PORTAL WG.exe (PID: 6208)
    • The sample compiled with english language support

      • SHAMA-Installer-3.0.5.exe (PID: 6576)
    • Reads the computer name

      • SHAMA-Installer-3.0.5.exe (PID: 6576)
      • PORTAL WG.exe (PID: 6472)
      • PORTAL WG.exe (PID: 6832)
      • PORTAL WG.exe (PID: 6892)
      • PORTAL WG.exe (PID: 6208)
    • Create files in a temporary directory

      • SHAMA-Installer-3.0.5.exe (PID: 6576)
    • The sample compiled with chinese language support

      • SHAMA-Installer-3.0.5.exe (PID: 6576)
    • Reads security settings of Internet Explorer

      • SHAMA-Installer-3.0.5.exe (PID: 6576)
      • PORTAL WG.exe (PID: 6472)
    • Creates a software uninstall entry

      • SHAMA-Installer-3.0.5.exe (PID: 6576)
    • Creates files or folders in the user directory

      • SHAMA-Installer-3.0.5.exe (PID: 6576)
    • Manual execution by a user

      • PORTAL WG.exe (PID: 6472)
      • firefox.exe (PID: 5240)
    • Process checks computer location settings

      • PORTAL WG.exe (PID: 6472)
    • Reads the machine GUID from the registry

      • PORTAL WG.exe (PID: 6892)
    • Application based on Golang

      • PORTAL WG.exe (PID: 6208)
      • PORTAL WG.exe (PID: 6892)
    • Detects GO elliptic curve encryption (YARA)

      • PORTAL WG.exe (PID: 6208)
      • PORTAL WG.exe (PID: 6892)
    • There is functionality for taking screenshot (YARA)

      • PORTAL WG.exe (PID: 6208)
      • PORTAL WG.exe (PID: 6892)
    • Application launched itself

      • firefox.exe (PID: 5240)
      • firefox.exe (PID: 2576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:03:08 23:05:20+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 184832
UninitializedDataSize: 2048
EntryPoint: 0x358d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.0.5.0
ProductVersionNumber: 3.0.5.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: SHAMA
FileDescription: SHAMA Installer
FileVersion: 3.0.5
LegalCopyright: Copyright (C) SHAMA
OriginalFileName: SHAMA-Installer-3.0.5.exe
ProductName: SHAMA
ProductVersion: 3.0.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
163
Monitored processes
25
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start shama-installer-3.0.5.exe portal wg.exe no specs portal wg.exe portal wg.exe no specs portal wg.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs shama-installer-3.0.5.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
420"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 2028 -prefsLen 36580 -prefMapHandle 2032 -prefMapSize 273045 -ipcHandle 2096 -initialChannelId {59897ffd-8972-4e6b-bb0c-1c90480e9966} -parentPid 2576 -crashReporter "\\.\pipe\gecko-crash-server-pipe.2576" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
572"C:\Users\admin\AppData\Local\Temp\SHAMA-Installer-3.0.5.exe" C:\Users\admin\AppData\Local\Temp\SHAMA-Installer-3.0.5.exeexplorer.exe
User:
admin
Company:
SHAMA
Integrity Level:
MEDIUM
Description:
SHAMA Installer
Exit code:
3221226540
Version:
3.0.5
Modules
Images
c:\users\admin\appdata\local\temp\shama-installer-3.0.5.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1904"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 2264 -prefsLen 36580 -prefMapHandle 2268 -prefMapSize 273045 -ipcHandle 2208 -initialChannelId {bf565d1d-545d-4b53-9f2a-f7c07638a1c5} -parentPid 2576 -crashReporter "\\.\pipe\gecko-crash-server-pipe.2576" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\msvcp140.dll
2576"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2588"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3160 -prefsLen 37299 -prefMapHandle 3164 -prefMapSize 273045 -jsInitHandle 3168 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3176 -initialChannelId {85e94d31-9b7c-4286-9906-db810e0e4c78} -parentPid 2576 -crashReporter "\\.\pipe\gecko-crash-server-pipe.2576" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
4956"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 0 -prefsHandle 4892 -prefsLen 45425 -prefMapHandle 4896 -prefMapSize 273045 -ipcHandle 4864 -initialChannelId {5d0b51f4-03ad-4465-8b7f-6b48a5498a6e} -parentPid 2576 -crashReporter "\\.\pipe\gecko-crash-server-pipe.2576" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 6 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
5240"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\bcrypt.dll
5888"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4832 -prefsLen 39377 -prefMapHandle 4848 -prefMapSize 273045 -jsInitHandle 4904 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4896 -initialChannelId {19faec09-47d3-4a03-a45d-38aaa1edb4e9} -parentPid 2576 -crashReporter "\\.\pipe\gecko-crash-server-pipe.2576" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
6076"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3760 -prefsLen 37375 -prefMapHandle 3764 -prefMapSize 273045 -jsInitHandle 3768 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3448 -initialChannelId {f303a616-7a26-41fd-a297-ce3d37012694} -parentPid 2576 -crashReporter "\\.\pipe\gecko-crash-server-pipe.2576" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
6208"C:\Program Files (x86)\PORTAL WG\PORTAL WG.exe" /managerserviceC:\Program Files (x86)\PORTAL WG\PORTAL WG.exeservices.exe
User:
SYSTEM
Company:
SHAMA
Integrity Level:
SYSTEM
Description:
PORTAL WG
Version:
3.0.5
Modules
Images
c:\program files (x86)\portal wg\portal wg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\umpdc.dll
c:\windows\system32\ws2_32.dll
Total events
4 375
Read events
4 365
Write events
10
Delete events
0

Modification events

(PID) Process:(6576) SHAMA-Installer-3.0.5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\SHAMA
Operation:writeName:Install_Dir
Value:
C:\Program Files (x86)\PORTAL WG
(PID) Process:(6576) SHAMA-Installer-3.0.5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SHAMA
Operation:writeName:DisplayName
Value:
SHAMA
(PID) Process:(6576) SHAMA-Installer-3.0.5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SHAMA
Operation:writeName:Publisher
Value:
SHAMA
(PID) Process:(6576) SHAMA-Installer-3.0.5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SHAMA
Operation:writeName:DisplayVersion
Value:
3.0.5
(PID) Process:(6576) SHAMA-Installer-3.0.5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SHAMA
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\PORTAL WG
(PID) Process:(6576) SHAMA-Installer-3.0.5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SHAMA
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\PORTAL WG\Uninstall.exe"
(PID) Process:(6576) SHAMA-Installer-3.0.5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SHAMA
Operation:writeName:NoModify
Value:
1
(PID) Process:(6576) SHAMA-Installer-3.0.5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SHAMA
Operation:writeName:NoRepair
Value:
1
(PID) Process:(6892) PORTAL WG.exeKey:HKEY_CURRENT_USER\SOFTWARE\AmneziaWG
Operation:writeName:LastWarpGenTime
Value:
2026-04-14T18:18:17-04:00
(PID) Process:(6892) PORTAL WG.exeKey:HKEY_CURRENT_USER\SOFTWARE\AmneziaWG
Operation:writeName:LastWarpGenSuccess
Value:
1
Executable files
7
Suspicious files
484
Text files
36
Unknown types
2

Dropped files

PID
Process
Filename
Type
2576firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
6576SHAMA-Installer-3.0.5.exeC:\Users\admin\AppData\Local\Temp\nsw125.tmp\nsDialogs.dllexecutable
MD5:8F0E7415F33843431DF308BB8E06AF81
SHA256:BB49F15FA83452370047A7801E39FC7F64E70C7545B8999BB85AA4749EAA048B
6208PORTAL WG.exeC:\Program Files (x86)\PORTAL WG\Data\Configurations\STR.WARP75679.conf.dpapibinary
MD5:AD488804AE4E8E81894AD9BCB37C4A53
SHA256:930B4588BA6252D97992CC4A7C8BB9693AA97AE13A917D717313E344D0CE9E11
2576firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:3134ED3F12E4F4F8643DB90043B0FD7B
SHA256:26E4F122034D7A03F6DA0E707799B09CBEEBDAF8D7A3133A1F7BD894AC72EEA1
2576firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.binbinary
MD5:73A2E89AF4D3D52D0167E7B3805E20E5
SHA256:AB2871B600E4E7A13DF4552B1172DA5EEA32C9BA8E3D2153F1987FE2B124CFC4
2576firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2576firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2576firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\extensions\trash\addon@example.com.xpicompressed
MD5:8D9AFAC42BC67132A3FFB3520C6B57A7
SHA256:116FDE2E4201D9545542FA9DEBC8054B12BBE874240A48BB5AE848B1BCBC2BA0
6576SHAMA-Installer-3.0.5.exeC:\Program Files (x86)\PORTAL WG\amd64_amneziawg.exeexecutable
MD5:07E4B14670C1415423D85851045ADB6D
SHA256:8F8598ABA6AAAB7EBA14E6AA5A9A3EF9B4E7658BD9C2E806168615E3BC6B107B
6576SHAMA-Installer-3.0.5.exeC:\Users\admin\AppData\Local\Temp\nsw125.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
110
TCP/UDP connections
117
DNS requests
190
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
5888
SIHClient.exe
GET
304
74.178.76.128:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
NL
binary
314 b
whitelisted
5316
svchost.exe
POST
400
20.190.159.131:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
5316
svchost.exe
POST
400
20.190.159.131:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
5888
SIHClient.exe
GET
200
74.179.77.164:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
5316
svchost.exe
POST
400
20.190.159.131:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
203 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/FlightSettings/FSService?ProcessorClockSpeed=3094&IsRetailOS=1&OEMManufacturerName=DELL&FlightingPolicyValue=3&EnablePreviewBuilds=4294967295&OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&ManagePreviewBuilds=3&BranchReadinessLevelSource=0&AttrDataVer=186&ProcessorCores=6&BranchReadinessLevelRaw=16&TotalPhysicalRAM=6144&TPMVersion=0&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&DeviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&App=FSS&AppVer=10.0&SmartActiveHoursState=1&ActiveHoursStart=20&SecureBootCapable=0&ActiveHoursEnd=13&DeviceFamily=Windows.Desktop
US
text
87.3 Kb
whitelisted
5316
svchost.exe
POST
400
20.190.159.131:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
5316
svchost.exe
POST
400
20.190.159.131:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
4212
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.204.161:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3428
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
20.190.159.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 51.104.136.2
whitelisted
www.bing.com
  • 2.16.204.161
  • 2.16.204.141
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
google.com
  • 142.251.13.139
  • 142.251.13.113
  • 142.251.13.138
  • 142.251.13.102
  • 142.251.13.100
  • 142.251.13.101
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.131
  • 20.190.159.73
  • 20.190.159.0
  • 40.126.31.67
  • 40.126.31.71
  • 20.190.159.75
  • 40.126.31.3
  • 40.126.31.1
whitelisted
crl.microsoft.com
  • 184.24.77.12
  • 184.24.77.35
whitelisted
www.microsoft.com
  • 23.59.18.102
whitelisted

Threats

PID
Process
Class
Message
4212
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2232
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloud infrastructure to build app (vercel .app)
2232
svchost.exe
Misc activity
ET TA_ABUSED_SERVICES Observed DNS Query to Actor Abused Cloud Hosting Service Domain (vercel .app)
6892
PORTAL WG.exe
Misc activity
ET TA_ABUSED_SERVICES Observed Commonly Actor Abused Cloud Hosting Service Domain (vercel .app in TLS SNI)
No debug info