File name:

snipaste_snipaste-bd-gjc-1_11775912394326794383.exe

Full analysis: https://app.any.run/tasks/53469c96-2869-4946-bf96-5440fb26e117
Verdict: Malicious activity
Analysis date: March 25, 2025, 07:43:06
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

EC39BFAFAD4D23C05DF1FC8ACA56417C

SHA1:

5970532C555493A01517561EE6C56E469B3E4059

SHA256:

7B6DAA6DD6784FF43B25227EBD54309F50CC282F3746FBE4099E00C59C5AB4BA

SSDEEP:

98304:lYgV+Priwt9QoozCMuZzPYsm+9njNASgB+/8H4Q0RexxNKekjBc/ftK2rEhPDptO:IO49Zi5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • runas.exe (PID: 7148)
      • islsnipaste.exe (PID: 5436)
      • snipaste_snipaste-bd-gjc-1_11775912394326794383.exe (PID: 3884)
    • Process drops legitimate windows executable

      • snipaste_snipaste-bd-gjc-1_11775912394326794383.exe (PID: 3884)
    • Executable content was dropped or overwritten

      • snipaste_snipaste-bd-gjc-1_11775912394326794383.exe (PID: 3884)
    • The process drops C-runtime libraries

      • snipaste_snipaste-bd-gjc-1_11775912394326794383.exe (PID: 3884)
    • Starts another process probably with elevated privileges via RUNAS.EXE

      • runas.exe (PID: 7148)
  • INFO

    • The sample compiled with english language support

      • runas.exe (PID: 7148)
      • snipaste_snipaste-bd-gjc-1_11775912394326794383.exe (PID: 3884)
    • Manual execution by a user

      • snipaste_snipaste-bd-gjc-1_11775912394326794383.exe (PID: 3884)
      • islsnipaste.exe (PID: 6132)
      • WinRAR.exe (PID: 3396)
    • Reads the software policy settings

      • slui.exe (PID: 6972)
      • slui.exe (PID: 3768)
    • The sample compiled with chinese language support

      • snipaste_snipaste-bd-gjc-1_11775912394326794383.exe (PID: 3884)
    • Creates files or folders in the user directory

      • snipaste_snipaste-bd-gjc-1_11775912394326794383.exe (PID: 3884)
      • islsnipaste.exe (PID: 5436)
    • Checks supported languages

      • islsnipaste.exe (PID: 5436)
      • snipaste_snipaste-bd-gjc-1_11775912394326794383.exe (PID: 3884)
      • islsnipaste.exe (PID: 6132)
    • Create files in a temporary directory

      • islsnipaste.exe (PID: 5436)
    • Reads the computer name

      • islsnipaste.exe (PID: 5436)
      • snipaste_snipaste-bd-gjc-1_11775912394326794383.exe (PID: 3884)
    • Checks proxy server information

      • slui.exe (PID: 3768)
    • Reads the machine GUID from the registry

      • islsnipaste.exe (PID: 5436)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:25 08:25:11+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 30208
InitializedDataSize: 421888
UninitializedDataSize: 16384
EntryPoint: 0x3b96
OSVersion: 5.1
ImageVersion: 6
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2025.311.1037.47
ProductVersionNumber: 2025.311.1037.47
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: -
FileDescription: Snipaste安装小助手
FileVersion: 1.1.0.0
InternalName: setup.exe
LegalCopyright: Copyright (C)
ProductName: Snipaste安装小助手
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
11
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start runas.exe no specs conhost.exe no specs sppextcomobj.exe no specs slui.exe rundll32.exe no specs Shell Security Editor no specs slui.exe snipaste_snipaste-bd-gjc-1_11775912394326794383.exe islsnipaste.exe islsnipaste.exe no specs winrar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1056C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
2140C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
3396"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Roaming\installSnipaste\res\res.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3768C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3884"C:\Users\admin\AppData\Local\Temp\snipaste_snipaste-bd-gjc-1_11775912394326794383.exe" C:\Users\admin\AppData\Local\Temp\snipaste_snipaste-bd-gjc-1_11775912394326794383.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Snipaste安装小助手
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\snipaste_snipaste-bd-gjc-1_11775912394326794383.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5084C:\WINDOWS\system32\DllHost.exe /Processid:{4D111E08-CBF7-4F12-A926-2C7920AF52FC}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
5244\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exerunas.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5436"C:\Users\admin\AppData\Roaming\installSnipaste\islsnipaste.exe" snipaste_snipaste-bd-gjc-1_11775912394326794383.exeC:\Users\admin\AppData\Roaming\installSnipaste\islsnipaste.exe
snipaste_snipaste-bd-gjc-1_11775912394326794383.exe
User:
admin
Company:
TODO: <公司名>
Integrity Level:
MEDIUM
Description:
softdown
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\roaming\installsnipaste\islsnipaste.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6132"C:\Users\admin\AppData\Roaming\installSnipaste\islsnipaste.exe" C:\Users\admin\AppData\Roaming\installSnipaste\islsnipaste.exeexplorer.exe
User:
admin
Company:
TODO: <公司名>
Integrity Level:
MEDIUM
Description:
softdown
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\roaming\installsnipaste\islsnipaste.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6972"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 682
Read events
3 662
Write events
20
Delete events
0

Modification events

(PID) Process:(5436) islsnipaste.exeKey:HKEY_CURRENT_USER\SOFTWARE\FYGame\soft-snipaste
Operation:writeName:mn
Value:
ef5f508b6c8417984f6ecd9fe455162e
(PID) Process:(5436) islsnipaste.exeKey:HKEY_CURRENT_USER\SOFTWARE\FYGame\soft-snipaste
Operation:writeName:jwt
Value:
eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpYXQiOjE3NDI4ODg2ODEsImV4cCI6MTc3NDQyNDY4MSwiYXVkIjo3Mzk5MTAyMCwic3ViIjoiZWY1ZjUwOGI2Yzg0MTc5ODRmNmVjZDlmZTQ1NTE2MmUifQ.b23ThxApo6zAdiHX08vKq1IW94liM8Fx4qcQ4mS9Eas
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Roaming\installSnipaste\res\res.zip
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
48
Suspicious files
3
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3884snipaste_snipaste-bd-gjc-1_11775912394326794383.exeC:\Users\admin\AppData\Roaming\installSnipaste\islsnipaste.exeexecutable
MD5:EEC1C89FCCA35C651D90A388CEFA2D04
SHA256:7D8CF4A30ECB22E088E6F5F8E6E6D28755A9F5CAB326CC049796FB6A9E90B180
3884snipaste_snipaste-bd-gjc-1_11775912394326794383.exeC:\Users\admin\AppData\Roaming\installSnipaste\GamePayment.dllexecutable
MD5:36F825F65C9F29B49F987F38A2870A13
SHA256:C5F65CD173BE3E2B58A03553A91BA00B1103581684CFAE2EEBD62971950B962D
3884snipaste_snipaste-bd-gjc-1_11775912394326794383.exeC:\Users\admin\AppData\Roaming\installSnipaste\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:3F34D9F9C738F108B85D56D8FAE20526
SHA256:99328B08DBC8A7FCACE311879C61F8E24557D722096EFC84E589437B54629AB7
3884snipaste_snipaste-bd-gjc-1_11775912394326794383.exeC:\Users\admin\AppData\Roaming\installSnipaste\api-ms-win-core-localization-l2-1-0.dllexecutable
MD5:35BC6AE0A77D373A4B5FA44EA331D01D
SHA256:4F63EB0A02EF11C0EBC306199DCDE459FAA98FB0864B3202949FA4E5F3E10AC3
3884snipaste_snipaste-bd-gjc-1_11775912394326794383.exeC:\Users\admin\AppData\Roaming\installSnipaste\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:75BFB396036384B53731C1FE05808E61
SHA256:C96C6EC91A21C963015150551B36673E9BB90D54C456BA42FE4A8755613EFD51
3884snipaste_snipaste-bd-gjc-1_11775912394326794383.exeC:\Users\admin\AppData\Roaming\installSnipaste\api-ms-win-core-handle-l1-1-0.dllexecutable
MD5:C55E37CE57BF8553835D964D1B8B72E4
SHA256:37552CAEF47EB879180879B853D363D519E55B9AA14253EC173D748C7CFF567B
3884snipaste_snipaste-bd-gjc-1_11775912394326794383.exeC:\Users\admin\AppData\Roaming\installSnipaste\api-ms-win-core-heap-l1-1-0.dllexecutable
MD5:EDFE2C4BC743789F06A1AA34C910317D
SHA256:243DBCE8A451D8ED18E477FE28C953A7CB959A9D435CC89064C73D6C557FD77A
3884snipaste_snipaste-bd-gjc-1_11775912394326794383.exeC:\Users\admin\AppData\Roaming\installSnipaste\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:7855024069361E4351BF21CE27118973
SHA256:D669FF83DBB63D8C156ADC078C1C883DEC90DDF5E4A86436C8A91339CDA6CDD9
3884snipaste_snipaste-bd-gjc-1_11775912394326794383.exeC:\Users\admin\AppData\Roaming\installSnipaste\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:743AD05AEA1713FB2956D08D67471FFA
SHA256:E44BF6CC56364B15C2D4491F09A7A70ABD6988F403E8F0443354DAA06FB4E3B9
3884snipaste_snipaste-bd-gjc-1_11775912394326794383.exeC:\Users\admin\AppData\Roaming\installSnipaste\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:F5B8F97B5C946BEAF2194EACA76DD6DA
SHA256:2C1478C5D8484A2842DF9F723F1ED0130ED5B6CA61C51D48F884CAB965D30F18
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
28
DNS requests
18
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5436
islsnipaste.exe
GET
200
62.234.146.167:80
http://soft.shanghaiouye.com/api/data/soft/softs?soft_key=snipaste
unknown
unknown
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6576
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6576
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4880
backgroundTaskHost.exe
20.223.36.55:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4880
backgroundTaskHost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.131
  • 40.126.31.131
  • 40.126.31.73
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.129
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

PID
Process
Class
Message
5436
islsnipaste.exe
Misc activity
ET INFO Observed ZeroSSL SSL/TLS Certificate
No debug info