File name:

Windscribe_2.15.8_amd64.exe

Full analysis: https://app.any.run/tasks/0933ffeb-c171-4f42-9663-7bf8ad79a574
Verdict: Malicious activity
Analysis date: June 18, 2025, 17:16:11
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

9959B706658CCE08FFEE69F1E1C7BE4C

SHA1:

46357859E814AD90E45B6C6D5AEA7D7ADC1FA1E0

SHA256:

7A92BE65624E341A86602FC5A59644CA01E8C8AF29BA8B39D7381AFDBD5DB387

SSDEEP:

196608:UTfUcl+KfYJrvjfbyTRaPsX+uVtVlId21fPNFS7rOcKVg1X262+xjTr/7WjoQ9eA:EsYIuT0EX+IflIdqdFOFKW1XMIn6EQ/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Windscribe_2.15.8_amd64.exe (PID: 6224)
      • Windscribe_2.15.8_amd64.exe (PID: 5184)
      • 7zr.exe (PID: 504)
      • Windscribe_2.15.8.exe (PID: 5372)
      • 7zr.exe (PID: 1380)
      • WindscribeService.exe (PID: 472)
      • devcon.exe (PID: 5400)
      • Windscribe.exe (PID: 2216)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • Windscribe_2.15.8_amd64.exe (PID: 6224)
      • Windscribe_2.15.8_amd64.exe (PID: 5184)
    • Reads security settings of Internet Explorer

      • Windscribe_2.15.8_amd64.exe (PID: 6224)
      • Windscribe_2.15.8_amd64.exe (PID: 5184)
      • Windscribe.exe (PID: 2216)
    • Application launched itself

      • Windscribe_2.15.8_amd64.exe (PID: 6224)
    • Drops 7-zip archiver for unpacking

      • Windscribe_2.15.8_amd64.exe (PID: 5184)
    • Executable content was dropped or overwritten

      • Windscribe_2.15.8_amd64.exe (PID: 5184)
      • 7zr.exe (PID: 1380)
      • devcon.exe (PID: 5400)
      • drvinst.exe (PID: 432)
      • Windscribe_2.15.8.exe (PID: 5372)
    • Uses TASKKILL.EXE to kill process

      • Windscribe_2.15.8.exe (PID: 5372)
      • WindscribeService.exe (PID: 472)
    • Searches for installed software

      • Windscribe_2.15.8.exe (PID: 5372)
    • Process drops legitimate windows executable

      • 7zr.exe (PID: 1380)
    • Executes as Windows Service

      • WindscribeService.exe (PID: 472)
    • Drops a system driver (possible attempt to evade defenses)

      • 7zr.exe (PID: 1380)
      • devcon.exe (PID: 5400)
      • Windscribe_2.15.8.exe (PID: 5372)
      • drvinst.exe (PID: 432)
    • Creates files in the driver directory

      • drvinst.exe (PID: 432)
      • Windscribe_2.15.8.exe (PID: 5372)
    • Creates a software uninstall entry

      • Windscribe_2.15.8.exe (PID: 5372)
  • INFO

    • Reads the computer name

      • Windscribe_2.15.8_amd64.exe (PID: 6224)
      • Windscribe_2.15.8_amd64.exe (PID: 5184)
      • 7zr.exe (PID: 504)
      • Windscribe_2.15.8.exe (PID: 5372)
      • 7zr.exe (PID: 1380)
      • devcon.exe (PID: 5400)
      • WindscribeService.exe (PID: 472)
      • drvinst.exe (PID: 432)
      • Windscribe.exe (PID: 2216)
    • The sample compiled with english language support

      • Windscribe_2.15.8_amd64.exe (PID: 6224)
      • Windscribe_2.15.8_amd64.exe (PID: 5184)
      • 7zr.exe (PID: 1380)
      • devcon.exe (PID: 5400)
      • drvinst.exe (PID: 432)
    • Process checks computer location settings

      • Windscribe_2.15.8_amd64.exe (PID: 5184)
      • Windscribe_2.15.8_amd64.exe (PID: 6224)
      • Windscribe.exe (PID: 2216)
    • Checks supported languages

      • Windscribe_2.15.8_amd64.exe (PID: 6224)
      • Windscribe_2.15.8_amd64.exe (PID: 5184)
      • 7zr.exe (PID: 504)
      • Windscribe_2.15.8.exe (PID: 5372)
      • 7zr.exe (PID: 1380)
      • devcon.exe (PID: 5400)
      • drvinst.exe (PID: 432)
      • Windscribe.exe (PID: 2216)
      • WindscribeService.exe (PID: 472)
    • Creates files in the program directory

      • Windscribe_2.15.8.exe (PID: 5372)
      • 7zr.exe (PID: 1380)
      • WindscribeService.exe (PID: 472)
    • Create files in a temporary directory

      • devcon.exe (PID: 5400)
    • Reads the software policy settings

      • drvinst.exe (PID: 432)
      • Windscribe.exe (PID: 2216)
      • WindscribeService.exe (PID: 472)
      • slui.exe (PID: 1160)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 432)
      • Windscribe.exe (PID: 2216)
      • WindscribeService.exe (PID: 472)
    • Disables trace logs

      • Windscribe.exe (PID: 2216)
    • Checks proxy server information

      • slui.exe (PID: 1160)
    • Manual execution by a user

      • Windscribe.exe (PID: 2216)
    • Creates files or folders in the user directory

      • Windscribe.exe (PID: 2216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:05:16 16:33:49+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.29
CodeSize: 388608
InitializedDataSize: 36915200
UninitializedDataSize: -
EntryPoint: 0x345e4
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.15.8.0
ProductVersionNumber: 2.15.8.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Windscribe Limited
FileDescription: Windscribe Installer
FileVersion: 2.15.8
LegalCopyright: Copyright (C) 2025 Windscribe Limited
OriginalFileName: Windscribe.exe
ProductName: Windscribe
ProductVersion: 2.15.8
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
21
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start windscribe_2.15.8_amd64.exe no specs windscribe_2.15.8_amd64.exe 7zr.exe no specs conhost.exe no specs windscribe_2.15.8.exe taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs 7zr.exe conhost.exe no specs windscribeservice.exe no specs devcon.exe conhost.exe no specs drvinst.exe windscribe.exe no specs taskkill.exe no specs conhost.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
432DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{23a95fe6-adb8-524c-86e9-b650ccb6bdc7}\ovpn-dco.inf" "9" "4da2b0e67" "00000000000001D8" "WinSta0\Default" "00000000000001E8" "208" "C:\Program Files\Windscribe\openvpndco\win10"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
472"C:\Program Files\Windscribe\WindscribeService.exe"C:\Program Files\Windscribe\WindscribeService.exeservices.exe
User:
SYSTEM
Company:
Windscribe Limited
Integrity Level:
SYSTEM
Description:
Manages the firewall and controls the VPN tunnel
Version:
2.15.8
Modules
Images
c:\program files\windscribe\windscribeservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
504"C:\WINDOWS\Temp\WindscribeInstaller11650\7zr.exe" x -y -bb3 -bd -o"C:\WINDOWS\Temp\WindscribeInstaller11650" "C:\WINDOWS\Temp\WindscribeInstaller11650\windscribeinstaller.7z"C:\Windows\Temp\WindscribeInstaller11650\7zr.exeWindscribe_2.15.8_amd64.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Reduced Standalone Console
Exit code:
0
Version:
24.08
Modules
Images
c:\windows\temp\windscribeinstaller11650\7zr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1160C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1380"C:\WINDOWS\Temp\WindscribeInstaller11650\7zr.exe" x -y -bb3 -bd -o"C:\Program Files\Windscribe" "C:\WINDOWS\Temp\WindscribeInstaller11650\windscribe.7z"C:\Windows\Temp\WindscribeInstaller11650\7zr.exe
Windscribe_2.15.8.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Reduced Standalone Console
Exit code:
0
Version:
24.08
Modules
Images
c:\windows\temp\windscribeinstaller11650\7zr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1472\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1512"C:\WINDOWS\system32\taskkill.exe" /f /t /im windscribectrld.exeC:\Windows\System32\taskkill.exeWindscribe_2.15.8.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2216"C:\Program Files\Windscribe\Windscribe.exe" C:\Program Files\Windscribe\Windscribe.exeexplorer.exe
User:
admin
Company:
Windscribe Limited
Integrity Level:
MEDIUM
Description:
Windscribe
Version:
2.15.8
Modules
Images
c:\program files\windscribe\windscribe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\user32.dll
2288\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe7zr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2792C:\WINDOWS\system32\taskkill.exe /f /t /im windscribeopenvpn.exeC:\Windows\System32\taskkill.exeWindscribeService.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
14 700
Read events
14 659
Write events
40
Delete events
1

Modification events

(PID) Process:(5400) devcon.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(5372) Windscribe_2.15.8.exeKey:HKEY_CURRENT_USER\SOFTWARE\Windscribe\Installer
Operation:writeName:ovpnDCODriverOEMIdentifier
Value:
oem1.inf
(PID) Process:(5372) Windscribe_2.15.8.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Windscribe\
(PID) Process:(5372) Windscribe_2.15.8.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1
Operation:writeName:DisplayName
Value:
Windscribe
(PID) Process:(5372) Windscribe_2.15.8.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Windscribe\Windscribe.exe
(PID) Process:(5372) Windscribe_2.15.8.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1
Operation:writeName:UninstallString
Value:
"C:\Program Files\Windscribe\uninstall.exe"
(PID) Process:(5372) Windscribe_2.15.8.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files\Windscribe\uninstall.exe" /SILENT
(PID) Process:(5372) Windscribe_2.15.8.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1
Operation:writeName:DisplayVersion
Value:
2.15.8
(PID) Process:(5372) Windscribe_2.15.8.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1
Operation:writeName:Publisher
Value:
Windscribe Limited
(PID) Process:(5372) Windscribe_2.15.8.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1
Operation:writeName:URLInfoAbout
Value:
http://www.windscribe.com/
Executable files
22
Suspicious files
1
Text files
12
Unknown types
10

Dropped files

PID
Process
Filename
Type
5184Windscribe_2.15.8_amd64.exeC:\Windows\Temp\WindscribeInstaller11650\windscribeinstaller.7z
MD5:
SHA256:
5047zr.exeC:\Windows\Temp\WindscribeInstaller11650\Windscribe_2.15.8.exe
MD5:
SHA256:
5372Windscribe_2.15.8.exeC:\Windows\Temp\WindscribeInstaller11650\windscribe.7z
MD5:
SHA256:
13807zr.exeC:\Program Files\Windscribe\Windscribe.exe
MD5:
SHA256:
13807zr.exeC:\Program Files\Windscribe\openvpndco\win11\ovpn-dco.catcat
MD5:8FD89F82A273CD3ED2F76F7F09CF30AE
SHA256:8C9456AEACD5566234519B5B34CEECD0F7EBB22F6813747E595F5945517EC438
13807zr.exeC:\Program Files\Windscribe\openvpndco\win10\ovpn-dco.catcat
MD5:5551203F3F1095335FF00421B16FD7E2
SHA256:26C54CE26CB43407855BA24D10FBB30A87E5A1A0A35536025A02CB003FE474F4
5184Windscribe_2.15.8_amd64.exeC:\Windows\Temp\WindscribeInstaller11650\7zr.exeexecutable
MD5:4492280AB3AB242F13DC365EBED6FA44
SHA256:3BFBDD19311D6741254344214D7F0601E8C16F3B17402B35E94AC2E60D9A66CC
13807zr.exeC:\Program Files\Windscribe\openvpndco\win10\ovpn-dco.infini
MD5:77DA079A3665AFC84D05C3D07BCAA0D0
SHA256:1F6C35BC11D910F91C32EA54894D0FDDB0094876BDD526D04A9287D04D636242
13807zr.exeC:\Program Files\Windscribe\open_source_licenses.txttext
MD5:2C64C599B69E560193FA213D439F9CC5
SHA256:CBD5401B6FBE6EC095732F25CE09FD522DB0F45D9D91C947457BB2BD12B78084
13807zr.exeC:\Program Files\Windscribe\splittunnel\windscribesplittunnel.infini
MD5:CBBB5F17C53610C70913299CDE04D4C2
SHA256:07D52DB986C550B8EA72DC5CF1E035552C187AD9AD8ADC270AD682C05BC20D98
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
45
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
200
20.190.159.71:443
https://login.live.com/RST2.srf
unknown
xml
10.3 Kb
whitelisted
6172
RUXIMICS.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
200
20.190.159.71:443
https://login.live.com/RST2.srf
unknown
xml
11.1 Kb
whitelisted
POST
200
40.126.31.129:443
https://login.live.com/RST2.srf
unknown
xml
11.0 Kb
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6172
RUXIMICS.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
200
40.126.31.3:443
https://login.live.com/RST2.srf
unknown
xml
10.3 Kb
whitelisted
GET
200
4.175.87.197:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
compressed
23.9 Kb
whitelisted
4808
SIHClient.exe
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
6172
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
40.126.31.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
436
svchost.exe
40.126.31.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2336
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.46
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.31.2
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.129
  • 40.126.31.130
  • 20.190.159.64
  • 40.126.31.67
  • 40.126.31.129
  • 20.190.159.75
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.4
  • 20.190.159.130
  • 20.190.159.0
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 95.101.149.131
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.14
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
Process
Message
Windscribe_2.15.8_amd64.exe
Windscribe bootstrapper installing to C:\WINDOWS\Temp\WindscribeInstaller11650
Windscribe_2.15.8_amd64.exe
Extracting resource: 7zr.exe
Windscribe_2.15.8_amd64.exe
Extracting resource: windscribeinstaller.7z
Windscribe_2.15.8_amd64.exe
executeCmd: "C:\WINDOWS\Temp\WindscribeInstaller11650\7zr.exe" x -y -bb3 -bd -o"C:\WINDOWS\Temp\WindscribeInstaller11650" "C:\WINDOWS\Temp\WindscribeInstaller11650\windscribeinstaller.7z"
Windscribe_2.15.8_amd64.exe
Extracting files from windscribeinstaller.7z
Windscribe_2.15.8_amd64.exe
executeCmd output: 7-Zip (r) 24.08 (x86) : Igor Pavlov : Public domain : 2024-08-11 Scanning the drive for archives: 1 file, 35859461 bytes (35 MiB) Extracting archive: C:\WINDOWS\Temp\WindscribeInstaller11650\windscribeinstaller.7z -- Path = C:\WINDOWS\Temp\WindscribeInstaller11650\windscribeinstaller.7z Type = 7z Physical Size = 35859461 Headers Size = 162 Method = LZMA2:24 BCJ Solid = - Blocks = 1 - Windscribe_2.15.8.exe Everything is Ok Size: 49880168 Compressed: 35859461
Windscribe_2.15.8.exe
{"tm": "2025-06-18 17:16:41.013", "lvl": "info", "mod": "installer", "msg": "System language: en"}
Windscribe_2.15.8.exe
{"tm": "2025-06-18 17:16:41.013", "lvl": "info", "mod": "installer", "msg": "Using language: en"}
Windscribe_2.15.8.exe
{"tm": "2025-06-18 17:16:41.008", "lvl": "info", "mod": "installer", "msg": "Command-line args: \"Windscribe_2.15.8.exe\" "}
Windscribe_2.15.8.exe
{"tm": "2025-06-18 17:16:41.006", "lvl": "info", "mod": "installer", "msg": "Installing Windscribe version 2.15.8"}