File name:

cadesplugin.exe

Full analysis: https://app.any.run/tasks/3b9147b0-d819-4e5d-a16f-428de3921694
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: August 01, 2024, 09:20:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A5D4F14BC494B9AEA885AD661EEE319E

SHA1:

693711ADB90E6C5BFB2616A37A08C1DED7422E92

SHA256:

7C43D41482684FF3D98FE45C741C6A14B63055C88721F0207AB2B605DBC28CB2

SSDEEP:

98304:+xL9PX7OoFSVe/ccoePZYgrNXa8ZeoVrcnvRKY01gUuBuLV2E8RKFPdBrkF4B7ZR:4WoW0bDr5MpycQHVjuCwn8kaDX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • cadesplugin.exe (PID: 6676)
      • msiexec.exe (PID: 6828)
    • Actions looks like stealing of personal data

      • msiexec.exe (PID: 4192)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • cadesplugin.exe (PID: 6676)
      • msiexec.exe (PID: 6828)
    • Executable content was dropped or overwritten

      • cadesplugin.exe (PID: 6676)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6992)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 6828)
      • Setup.exe (PID: 6796)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6828)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6828)
      • Setup.exe (PID: 6796)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 4192)
      • msiexec.exe (PID: 6828)
    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 6796)
  • INFO

    • Checks supported languages

      • cadesplugin.exe (PID: 6676)
      • Setup.exe (PID: 6796)
      • msiexec.exe (PID: 6828)
      • msiexec.exe (PID: 4088)
      • msiexec.exe (PID: 4192)
      • msiexec.exe (PID: 6424)
    • Creates files in the program directory

      • cadesplugin.exe (PID: 6676)
    • Create files in a temporary directory

      • msiexec.exe (PID: 6908)
    • Reads the computer name

      • msiexec.exe (PID: 6828)
      • cadesplugin.exe (PID: 6676)
      • Setup.exe (PID: 6796)
      • msiexec.exe (PID: 4088)
      • msiexec.exe (PID: 4192)
      • msiexec.exe (PID: 6424)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 6828)
      • msiexec.exe (PID: 4088)
      • msiexec.exe (PID: 4192)
      • Setup.exe (PID: 6796)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6828)
    • Reads the software policy settings

      • msiexec.exe (PID: 6828)
    • Reads Microsoft Office registry keys

      • msiexec.exe (PID: 6828)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 4192)
      • msiexec.exe (PID: 6828)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6828)
    • Checks proxy server information

      • Setup.exe (PID: 6796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:12:16 08:16:07+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 126464
InitializedDataSize: 44544
UninitializedDataSize: -
EntryPoint: 0x195b
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.0.15002.0
ProductVersionNumber: 2.0.15002.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Russian
CharacterSet: Unicode
CompanyName: Компания КРИПТО-ПРО
FileDescription: Установщик КриптоПро ЭЦП Browser plug-in
FileVersion: 2.0.15002.0
InternalName: cadespluginsetup
LegalCopyright: © Компания КРИПТО-ПРО. Все права защищены.
OriginalFileName: cadespluginsetup.exe
ProductName: Подсистема усовершенствованной ЭЦП
ProductVersion: 2.0.15002.0
Tag040904B0: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
11
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start cadesplugin.exe setup.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe no specs cadesplugin.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3160\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4088C:\Windows\syswow64\MsiExec.exe -Embedding 9589FB3E18E2FE994D4488A8BB9FDBB7C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4192C:\Windows\syswow64\MsiExec.exe -Embedding 406D8876182777190167864CE1CA29C5 E Global\MSI0000C:\Windows\SysWOW64\msiexec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6424C:\Windows\syswow64\MsiExec.exe -Embedding 939F2753D34FC0FD95A6FCCAA2787B5F M Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6628"C:\Users\admin\AppData\Local\Temp\cadesplugin.exe" C:\Users\admin\AppData\Local\Temp\cadesplugin.exeexplorer.exe
User:
admin
Company:
Crypto-Pro LLC
Integrity Level:
MEDIUM
Description:
CryptoPro CAdES Browser plug-in Setup Bootstrapper
Exit code:
3221226540
Version:
2.0.15002.0
Modules
Images
c:\users\admin\appdata\local\temp\cadesplugin.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6676"C:\Users\admin\AppData\Local\Temp\cadesplugin.exe" C:\Users\admin\AppData\Local\Temp\cadesplugin.exe
explorer.exe
User:
admin
Company:
Crypto-Pro LLC
Integrity Level:
HIGH
Description:
CryptoPro CAdES Browser plug-in Setup Bootstrapper
Version:
2.0.15002.0
Modules
Images
c:\users\admin\appdata\local\temp\cadesplugin.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6796"C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\Setup.exe" -root -disablerm -skipinstallvalidate C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\Setup.exe
cadesplugin.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\programdata\crypto pro\installer cache\cadescom_2.0.15002\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6828C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6908"C:\WINDOWS\system32\msiexec.exe" /i "C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\cadescom\cadescom-x64.msi" /Lv "C:\Users\admin\AppData\Local\Temp\cadescom-x64.msi_2024-08-01-09-20-41.log" REBOOT=R /qb ADDNPCADES=1 MSIRESTARTMANAGERCONTROL=Disable SKIPINSTALLVALIDATE=1C:\Windows\SysWOW64\msiexec.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6992C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
39 315
Read events
38 163
Write events
1 105
Delete events
47

Modification events

(PID) Process:(6828) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
48000000000000001CC3B914F4E3DA01AC1A0000401B0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6828) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000001CC3B914F4E3DA01AC1A0000401B0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6828) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
48000000000000000A74FC14F4E3DA01AC1A0000401B0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6828) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000000A74FC14F4E3DA01AC1A0000401B0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6828) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000043B0115F4E3DA01AC1A0000401B0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6828) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000AC9E0315F4E3DA01AC1A0000401B0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6828) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6828) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4800000000000000325F6515F4E3DA01AC1A0000401B0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6828) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000006AC26715F4E3DA01AC1A0000B41B0000E8030000010000000000000000000000516558B161F4D4479D2E3EEFE637FA8E00000000000000000000000000000000
(PID) Process:(6992) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000002DEF6E15F4E3DA01501B0000D41B0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
129
Suspicious files
17
Text files
58
Unknown types
56

Dropped files

PID
Process
Filename
Type
6676cadesplugin.exeC:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\0B48B8D07D142A5B45E9B0E8C52186687D75E58E.cerder
MD5:5A7E8A4257A19F414353C1ACA5AE96ED
SHA256:EC99B134785192138819E11792E7C3041BDAD78172D53E932F411A9DCCEA37B4
6676cadesplugin.exeC:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\4E09E2EB25570944FC104322B5CD1643597B88F6.cerder
MD5:D8C29562FD1290878D3040623F2ECB25
SHA256:60899402D8168C4DA5DDA5F0D82CDDAC3E635025726EF37E06740441A3AF02F8
6676cadesplugin.exeC:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\13877A8BD34589567F9B9AFF6498026C0C29C617.cerder
MD5:25F843018DEEBE233154F7D3587B8A9C
SHA256:9006C4610F13BA6E0792C4BBDC27262D7C7DB88E0587855DA03911922F4DCB7B
6676cadesplugin.exeC:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\24A2CD23CC4E75EC695031B18054F7683FDF1E86.cerder
MD5:3B38C5F7FDAA1A222710FB13022D9398
SHA256:7EB425BC4E72A23A082C1767B55A9B978A0BFB5F8EC472C308631B07B400831C
6676cadesplugin.exeC:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\0408435EB90E5C8796A160E69E4BFAC453435D1D.cerder
MD5:56B3DD20751FD8D37F154313EA33408C
SHA256:C51BCD9ACEF0C7EA60F7538EE802AE15B93720D88A403258639F61874E84BAEB
6676cadesplugin.exeC:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\0932E483C4420E668F64D360006D0BEB0BFACCA7.cerder
MD5:57B8122B3F3DBB9AF72032749FD3FD7C
SHA256:F3F53906A1DB009003BFA9E307B8B428B266ABDDDBA5BDB296561C185F5D178C
6676cadesplugin.exeC:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\0884889D00F1FF2C773BC5DFB42F41DDDDEED492.cerder
MD5:2326745C970209A2570B433A8018E5FB
SHA256:8A2399725FD62A7F7640140D6FFEC95BCA007AB5443C469D81A0CD05F6FB518F
6676cadesplugin.exeC:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\2F0CB09BE3550EF17EC4F29C90ABD18BFCAAD63A.cerder
MD5:12CFA78F515907965E546048727E3BD6
SHA256:4BB37CC7C0FF4BF2AA893E95076EBB3565C69237EE1B61635BEEE4C1966495C7
6676cadesplugin.exeC:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\1B4158B9A7399FD8B90AE8A06FC676FB0624F97E.cerder
MD5:68A01739C1477C34520CD99C930A6D44
SHA256:5F08C210D77CDA988F4E6A173FED5BB1494FA94916FAB68F03E0F8702C88118C
6676cadesplugin.exeC:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.15002\34E21FC04D3576B0ADA81FD081955E2778291CC5.cerder
MD5:1D93C83C1F31552B60A345D33F78A071
SHA256:0D2AF8A0B445E63CBD7D1AB63AF8DC44AB4D69E1B8A2200373EBFF57FAB68350
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
49
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5976
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6828
msiexec.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D
unknown
whitelisted
6828
msiexec.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDFXm8Gmk5GaLiYLS3Q%3D%3D
unknown
whitelisted
3136
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6388
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5244
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2872
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
5244
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
104.126.37.178:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5976
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.78
whitelisted
www.bing.com
  • 104.126.37.178
  • 104.126.37.168
  • 104.126.37.179
  • 104.126.37.162
  • 104.126.37.185
  • 104.126.37.171
  • 104.126.37.161
  • 104.126.37.177
  • 104.126.37.163
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.31.71
  • 20.190.159.71
  • 20.190.159.4
  • 40.126.31.69
  • 20.190.159.2
  • 40.126.31.73
  • 20.190.159.64
  • 20.190.159.23
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
th.bing.com
  • 104.126.37.178
  • 104.126.37.177
  • 104.126.37.168
  • 104.126.37.162
  • 104.126.37.171
  • 104.126.37.185
  • 104.126.37.179
  • 104.126.37.186
  • 104.126.37.163
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted

Threats

No threats detected
No debug info