File name:

Moler Installer.exe

Full analysis: https://app.any.run/tasks/d62512b3-f99b-4d4f-a814-3c8e86de575c
Verdict: Malicious activity
Analysis date: May 13, 2025, 23:44:51
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
discord
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

7ECB5D203D087FA2A4E227D47FA0E266

SHA1:

B3277966DEFC94B0773277855281E3113309D736

SHA256:

783040E3C53576C3E9616AD4A87A6B61A6FCBAB018C1849B1D0FB0F0465B6BE0

SSDEEP:

98304:nLVIF8P3n1BLHxtD59KEKjSvksAO1iS6M5T6Wc6VlXtPKxByPBasWzanr53tQ88M:WCfdWZ9gm84IrCUdQFmPUTaf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Moler Installer.tmp (PID: 1088)
      • Moler.exe (PID: 5304)
    • Executable content was dropped or overwritten

      • Moler Installer.exe (PID: 4200)
      • Moler Installer.exe (PID: 3304)
      • Moler Installer.tmp (PID: 6184)
    • Reads the Windows owner or organization settings

      • Moler Installer.tmp (PID: 6184)
    • Process drops legitimate windows executable

      • Moler Installer.tmp (PID: 6184)
  • INFO

    • Checks supported languages

      • Moler Installer.exe (PID: 3304)
      • Moler Installer.tmp (PID: 1088)
      • Moler Installer.tmp (PID: 6184)
      • Moler Installer.exe (PID: 4200)
      • Moler.exe (PID: 5304)
    • Reads the computer name

      • Moler Installer.tmp (PID: 1088)
      • Moler.exe (PID: 5304)
      • Moler Installer.exe (PID: 4200)
      • Moler Installer.tmp (PID: 6184)
    • Create files in a temporary directory

      • Moler Installer.exe (PID: 3304)
      • Moler Installer.exe (PID: 4200)
      • Moler Installer.tmp (PID: 6184)
    • Process checks computer location settings

      • Moler Installer.tmp (PID: 1088)
    • Creates files or folders in the user directory

      • Moler Installer.tmp (PID: 6184)
    • Application launched itself

      • msedge.exe (PID: 7152)
      • msedge.exe (PID: 6576)
      • msedge.exe (PID: 7400)
    • Disables trace logs

      • Moler.exe (PID: 5304)
    • Checks proxy server information

      • Moler.exe (PID: 5304)
    • Manual execution by a user

      • msedge.exe (PID: 6576)
    • Attempting to use instant messaging service

      • msedge.exe (PID: 3008)
    • Creates files in the program directory

      • Moler.exe (PID: 5304)
    • Reads the machine GUID from the registry

      • Moler.exe (PID: 5304)
    • Reads the software policy settings

      • Moler.exe (PID: 5304)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:03:13 06:55:45+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 704512
InitializedDataSize: 221696
UninitializedDataSize: -
EntryPoint: 0xacfe0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Moler Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Moler
ProductVersion: 2.0.9.4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
179
Monitored processes
50
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start moler installer.exe moler installer.tmp no specs moler installer.exe moler installer.tmp sppextcomobj.exe no specs slui.exe no specs moler.exe svchost.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
812"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x294,0x298,0x29c,0x28c,0x1f0,0x7ffc897b5fd8,0x7ffc897b5fe4,0x7ffc897b5ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
856"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5064 --field-trial-handle=2360,i,178659745500233937,7121800797940444564,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1012"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2364 --field-trial-handle=2368,i,17604541234373967440,10327189778406766806,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1088"C:\Users\admin\AppData\Local\Temp\is-DV94N.tmp\Moler Installer.tmp" /SL5="$A0310,12593382,927232,C:\Users\admin\AppData\Local\Temp\Moler Installer.exe" C:\Users\admin\AppData\Local\Temp\is-DV94N.tmp\Moler Installer.tmpMoler Installer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-dv94n.tmp\moler installer.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
1532C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2420"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3340 --field-trial-handle=2360,i,178659745500233937,7121800797940444564,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3008"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2804 --field-trial-handle=2464,i,7156243077344734182,6339175279072302527,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3304"C:\Users\admin\AppData\Local\Temp\Moler Installer.exe" C:\Users\admin\AppData\Local\Temp\Moler Installer.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Moler Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\moler installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
Total events
9 980
Read events
9 931
Write events
49
Delete events
0

Modification events

(PID) Process:(5304) Moler.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Moler_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5304) Moler.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Moler_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5304) Moler.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Moler_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(5304) Moler.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Moler_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(5304) Moler.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Moler_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(5304) Moler.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Moler_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(5304) Moler.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Moler_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(5304) Moler.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Moler_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5304) Moler.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Moler_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5304) Moler.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Moler_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
195
Suspicious files
376
Text files
259
Unknown types
0

Dropped files

PID
Process
Filename
Type
6184Moler Installer.tmpC:\Users\admin\AppData\Local\Temp\is-004K9.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
4200Moler Installer.exeC:\Users\admin\AppData\Local\Temp\is-GTQNT.tmp\Moler Installer.tmpexecutable
MD5:0B310AA9465F3FDECC6E87D554ACD0CD
SHA256:8360410BD6CFBA04E615E8B95AE4C5028C9C77C547D27E161B24FFA23D94D4DC
6184Moler Installer.tmpC:\Users\admin\AppData\Local\Moler V1\BouncyCastle.Cryptography.xmlxml
MD5:A9F54F76DCD1DA2BD1C38FB379114592
SHA256:7A479B659A32EB9E063892417AA698B14954F7251FF3F899630B2792263D92FA
6184Moler Installer.tmpC:\Users\admin\AppData\Local\Moler V1\is-8KESF.tmpxml
MD5:EA9510F5FDF45000EEC680BEE3488872
SHA256:B93E9BEAABB7DD6B5F7C2F332F56AD5842E69FEC8AF71751DF02C7B6D27611B2
6184Moler Installer.tmpC:\Users\admin\AppData\Local\Moler V1\is-FTOQD.tmpexecutable
MD5:90166668F9B02B0CF519A21325078B98
SHA256:1CAC6EA064ADBA2E67D43A6D91A5B8B4B6968568076DC8ADB832553C90F0DE76
6184Moler Installer.tmpC:\Users\admin\AppData\Local\Moler V1\DarkNet.dllexecutable
MD5:90166668F9B02B0CF519A21325078B98
SHA256:1CAC6EA064ADBA2E67D43A6D91A5B8B4B6968568076DC8ADB832553C90F0DE76
6184Moler Installer.tmpC:\Users\admin\AppData\Local\Moler V1\is-E8M58.tmpxml
MD5:200AF43938B545467D33B0430E3F2BBA
SHA256:F026177D9E5BCC33B8967D5621B5BC5A86AA5B780018E2EF6BE5247701C628DD
6184Moler Installer.tmpC:\Users\admin\AppData\Local\Moler V1\is-O07TT.tmpxml
MD5:A9F54F76DCD1DA2BD1C38FB379114592
SHA256:7A479B659A32EB9E063892417AA698B14954F7251FF3F899630B2792263D92FA
6184Moler Installer.tmpC:\Users\admin\AppData\Local\Moler V1\Discord.Net.Core.dllexecutable
MD5:EAD8D9836C182FA4EC015A9E8BA94CC8
SHA256:2530B1C2B00A8536F9B482F876432FA76E9900424FFCD81C7228400B8AD315F6
6184Moler Installer.tmpC:\Users\admin\AppData\Local\Moler V1\is-GNT8O.tmpexecutable
MD5:C0E52EA008419D93C45D0D6597B7CC2F
SHA256:CA01E4CD463C9B0418ECAE20606F46C8BE1F9DEB5968A55450C2662FDF3A527D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
79
DNS requests
68
Threats
23

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.20.245.137:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.20.245.137:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6972
SIHClient.exe
GET
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6972
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2.20.245.137:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5304
Moler.exe
147.93.63.98:443
molerapi.moler.cloud
BE
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.20.245.137
  • 2.20.245.139
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.159.130
  • 40.126.31.3
  • 20.190.159.128
  • 40.126.31.73
  • 20.190.159.64
  • 20.190.159.73
  • 20.190.159.2
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
molerapi.moler.cloud
  • 147.93.63.98
unknown
i.postimg.cc
  • 46.105.222.161
  • 46.105.222.162
  • 46.105.222.81
  • 46.105.222.82
whitelisted
public-files.gumroad.com
  • 104.17.176.98
  • 104.18.243.99
unknown

Threats

PID
Process
Class
Message
2196
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
3008
msedge.exe
Misc activity
ET INFO Observed Discord Domain in DNS Lookup (discord .com)
3008
msedge.exe
Misc activity
ET INFO Observed Discord Domain in DNS Lookup (discord .com)
3008
msedge.exe
Misc activity
ET INFO Discord Chat Service Domain in DNS Lookup (discord .com)
3008
msedge.exe
Misc activity
ET INFO Discord Chat Service Domain in DNS Lookup (discord .com)
3008
msedge.exe
Misc activity
ET INFO Observed Discord Domain (discord .com in TLS SNI)
3008
msedge.exe
Misc activity
ET INFO Observed Discord Service Domain (discord .com) in TLS SNI
3008
msedge.exe
Misc activity
ET INFO Observed Discord Domain in DNS Lookup (discord .com)
3008
msedge.exe
Misc activity
ET INFO Observed Discord Domain in DNS Lookup (discord .com)
3008
msedge.exe
Misc activity
ET INFO Discord Chat Service Domain in DNS Lookup (discord .com)
No debug info