File name:

SQLi Dumper v8.5.rar

Full analysis: https://app.any.run/tasks/ccedb272-8fcc-4a81-a21c-938c75b53fac
Verdict: Malicious activity
Analysis date: August 20, 2024, 18:38:17
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
pastebin
crypto-regex
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

C517622724EB4FB83309C17DEA02025C

SHA1:

A9B640B1A035CE95857065635AB401DE5CE16DA1

SHA256:

7786B8B10C80183300F4373E0DC4A530B18234858334DCD9B265E61DA91204CC

SSDEEP:

98304:9D/7npcLPh2fQrNvDzKDNVIJ8DYhwIFVLby14siyzZxPPwopotF1PGC1uevGA+jl:+eDohW/p4PT0vJJqZk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • Runtime64.exe (PID: 7020)
  • SUSPICIOUS

    • Hides command output

      • cmd.exe (PID: 7068)
    • Starts CMD.EXE for commands execution

      • SQLi Dumper v8.5.exe (PID: 6852)
      • blockDriverDll.exe (PID: 7036)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 6688)
      • SQLi Dumper v8.5.exe (PID: 6852)
      • Runtime64.exe (PID: 7020)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 6688)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 6688)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6688)
      • blockDriverDll.exe (PID: 7036)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • SQLi Dumper v8.5.exe (PID: 6852)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Reads the BIOS version

      • SQLi Dumper v8.5.exe (PID: 6852)
    • Executable content was dropped or overwritten

      • SQLi Dumper v8.5.exe (PID: 6852)
      • Runtime64.exe (PID: 7020)
    • Executing commands from a ".bat" file

      • blockDriverDll.exe (PID: 7036)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Reads the date of Windows installation

      • blockDriverDll.exe (PID: 7036)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • SQLi Dumper v8.5.exe (PID: 6852)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Probably delay the execution using 'w32tm.exe'

      • cmd.exe (PID: 6536)
      • cmd.exe (PID: 7080)
      • cmd.exe (PID: 6248)
      • cmd.exe (PID: 6492)
      • cmd.exe (PID: 3672)
      • cmd.exe (PID: 4252)
    • The executable file from the user directory is run by the CMD process

      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Found regular expressions for crypto-addresses (YARA)

      • Runtime64.exe (PID: 7020)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6688)
    • Checks supported languages

      • SQLi Dumper v8.5.exe (PID: 6852)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 7036)
      • Runtime64.exe (PID: 7020)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Reads the computer name

      • SQLi Dumper v8.5.exe (PID: 6852)
      • blockDriverDll.exe (PID: 7036)
      • Runtime64.exe (PID: 7020)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Creates files or folders in the user directory

      • Runtime64.exe (PID: 7020)
    • Reads the software policy settings

      • blockDriverDll.exe (PID: 7036)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Reads Environment values

      • blockDriverDll.exe (PID: 7036)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Disables trace logs

      • blockDriverDll.exe (PID: 7036)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Checks proxy server information

      • blockDriverDll.exe (PID: 7036)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Reads the machine GUID from the registry

      • blockDriverDll.exe (PID: 7036)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Create files in a temporary directory

      • blockDriverDll.exe (PID: 7036)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • blockDriverDll.exe (PID: 6632)
      • SQLi Dumper v8.5.exe (PID: 6852)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
    • Process checks computer location settings

      • blockDriverDll.exe (PID: 7036)
      • blockDriverDll.exe (PID: 7000)
      • blockDriverDll.exe (PID: 2456)
      • SQLi Dumper v8.5.exe (PID: 6852)
      • blockDriverDll.exe (PID: 6632)
      • blockDriverDll.exe (PID: 736)
      • blockDriverDll.exe (PID: 5624)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
158
Monitored processes
29
Malicious processes
3
Suspicious processes
6

Behavior graph

Click at the process to see the details
start winrar.exe sqli dumper v8.5.exe THREAT runtime64.exe blockdriverdll.exe cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs w32tm.exe no specs blockdriverdll.exe cmd.exe no specs conhost.exe no specs w32tm.exe no specs blockdriverdll.exe cmd.exe no specs conhost.exe no specs w32tm.exe no specs blockdriverdll.exe cmd.exe no specs conhost.exe no specs w32tm.exe no specs blockdriverdll.exe cmd.exe no specs conhost.exe no specs w32tm.exe no specs blockdriverdll.exe cmd.exe no specs conhost.exe no specs w32tm.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
736"C:\Users\admin\AppData\Local\Temp\blockDriverDll.exe" C:\Users\admin\AppData\Local\Temp\blockDriverDll.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.1.1o
Modules
Images
c:\users\admin\appdata\local\temp\blockdriverdll.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2456"C:\Users\admin\AppData\Local\Temp\blockDriverDll.exe" C:\Users\admin\AppData\Local\Temp\blockDriverDll.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.1.1o
Modules
Images
c:\users\admin\appdata\local\temp\blockdriverdll.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2524w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2 C:\Windows\System32\w32tm.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Time Service Diagnostic Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\w32tm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\advapi32.dll
3672C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\mWzz7cjAeP.bat" "C:\Windows\System32\cmd.exeblockDriverDll.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
4252C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\64IFTJQeKo.bat" "C:\Windows\System32\cmd.exeblockDriverDll.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
5104\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5144w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2 C:\Windows\System32\w32tm.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Time Service Diagnostic Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\w32tm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\advapi32.dll
5532\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5624"C:\Users\admin\AppData\Local\Temp\blockDriverDll.exe" C:\Users\admin\AppData\Local\Temp\blockDriverDll.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.1.1o
Modules
Images
c:\users\admin\appdata\local\temp\blockdriverdll.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6248C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\vF7CrwxjwX.bat" "C:\Windows\System32\cmd.exeblockDriverDll.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
Total events
38 883
Read events
38 797
Write events
86
Delete events
0

Modification events

(PID) Process:(6688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\SQLi Dumper v8.5.rar
(PID) Process:(6688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
8
Suspicious files
0
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
6688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6688.42206\dxdiagn.dllexecutable
MD5:6A9A20E2518CAE98F78618EBBB27C699
SHA256:F4A4EC04A0B0197428CAB6A4D21A8F0438F045EEF8FA35CB2B9662E1E5FC28DE
6852SQLi Dumper v8.5.exeC:\Users\admin\AppData\Local\Temp\blockDriverDll.exeexecutable
MD5:CD9B98565D9ACAD306321D8AE9015E7E
SHA256:B9E095F562426C71EBC8E5846168E048D3FF0BA58A027165130358ABE0F63D43
6688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6688.42206\SQLi Dumper v8.5.exeexecutable
MD5:C0925E3058A6F9B668ECB454B3D7D4E7
SHA256:83DB7EFDDDA530E7B4C7B10A6E762FA9B1216421AE6694AECD5FEBEA866380A5
6688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6688.42206\eapphost.dllexecutable
MD5:7F9AEC82D7480068C6D444D4FD8FB36F
SHA256:E697AA951AA9E49988DF3C984FC5426D267D7BBC9DB83670E3C1F34DA95095F9
6688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6688.42206\README.txttext
MD5:229BFB07694F123E2CB4986F47100A62
SHA256:8DF26B1F550C80646F01D25B8AAFCABB1342BBB2BE1CD335CDB8D254BE8C4090
6688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6688.42206\NlsData0026.dllexecutable
MD5:A08FF320A2BD98F9982B2B91F57D7881
SHA256:D175F3C196BAFA05D18424490BFCF2DF7A93341608DF67B808DCED5EE7CEC668
6688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6688.42206\eapp3hst.dllexecutable
MD5:12BF0E1F71E2EA1A52B5D1723F87BD16
SHA256:A668165F00276FA4FEFE3F10A04E5D42FD60683CF7664C6D741F6EDF2943BD4C
6852SQLi Dumper v8.5.exeC:\Users\admin\AppData\Local\Temp\Runtime64.exeexecutable
MD5:2149F4DB23F99EBB482F3DD0E5F13AB4
SHA256:F6684DDE58EA7FAF54AE22F54277FBD07E430E815FC142AA45572CC8470E140A
7020Runtime64.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\System32.exeexecutable
MD5:2149F4DB23F99EBB482F3DD0E5F13AB4
SHA256:F6684DDE58EA7FAF54AE22F54277FBD07E430E815FC142AA45572CC8470E140A
7036blockDriverDll.exeC:\Users\admin\AppData\Local\Temp\oYNvu0ZNBR.battext
MD5:23645E035520E8811BE30CF87AB2CD4B
SHA256:AC996E5E5C77B9B027D03C8BACD51FA53D9A5A7FEF87FC097B14A9D70B39FC80
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
35
DNS requests
16
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3992
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
6152
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
5148
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1432
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
304
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1432
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
7036
blockDriverDll.exe
104.20.3.235:443
pastebin.com
CLOUDFLARENET
unknown
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3992
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.18.14
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
pastebin.com
  • 104.20.3.235
  • 104.20.4.235
  • 172.67.19.24
shared
client.wns.windows.com
  • 40.113.103.199
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.4
  • 20.190.159.73
  • 20.190.159.23
  • 40.126.31.73
  • 40.126.31.67
  • 20.190.159.75
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

PID
Process
Class
Message
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Online Pastebin Text Storage
No debug info