File name:

vs_BuildTools.exe

Full analysis: https://app.any.run/tasks/2954b0ca-de91-46fe-94cc-5215434cf5e6
Verdict: Malicious activity
Analysis date: August 09, 2024, 09:00:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
crypto-regex
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

654A933FC15545C9EF1E44ED34CD7309

SHA1:

42E202CECEDB21D83C0E1275059313445FB40601

SHA256:

7D9EC4AFC0346130BE7244673BB60AB159EB99794E1E5101D4DC973047C5EEEE

SSDEEP:

98304:bgxo3Ddg0SK0CTmeXAtp5QP98FnusjQWh32tKne2leMzla+fSEhl7OmOSnOfSZVR:vXeHVekD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • setup.exe (PID: 7012)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • vs_BuildTools.exe (PID: 6828)
      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7012)
      • msiexec.exe (PID: 7220)
    • Process drops legitimate windows executable

      • vs_BuildTools.exe (PID: 6828)
      • vs_setup_bootstrapper.exe (PID: 7044)
      • msiexec.exe (PID: 7220)
      • setup.exe (PID: 7012)
    • Starts a Microsoft application from unusual location

      • vs_BuildTools.exe (PID: 6828)
    • Reads security settings of Internet Explorer

      • vs_BuildTools.exe (PID: 6828)
      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
      • setup.exe (PID: 7012)
    • Reads the date of Windows installation

      • vs_BuildTools.exe (PID: 6828)
      • setup.exe (PID: 7740)
    • Executable content was dropped or overwritten

      • vs_BuildTools.exe (PID: 6828)
      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7012)
    • Found regular expressions for crypto-addresses (YARA)

      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
      • setup.exe (PID: 7012)
    • The process drops C-runtime libraries

      • vs_setup_bootstrapper.exe (PID: 7044)
    • The process creates files with name similar to system file names

      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7012)
    • Searches for installed software

      • vs_installer.windows.exe (PID: 8080)
      • setup.exe (PID: 7012)
    • Creates a software uninstall entry

      • vs_installer.windows.exe (PID: 8080)
      • setup.exe (PID: 7012)
    • Application launched itself

      • setup.exe (PID: 7740)
    • Checks Windows Trust Settings

      • setup.exe (PID: 7012)
      • msiexec.exe (PID: 7220)
      • setup.exe (PID: 7740)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7220)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 7220)
  • INFO

    • Checks supported languages

      • vs_BuildTools.exe (PID: 6828)
      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
      • vs_installer.windows.exe (PID: 8080)
      • setup.exe (PID: 7012)
      • msiexec.exe (PID: 7220)
      • ngen.exe (PID: 7136)
      • Microsoft.Build.UnGAC.exe (PID: 840)
      • msiexec.exe (PID: 6812)
      • MofCompiler.exe (PID: 6484)
      • ngen.exe (PID: 4088)
      • ngen.exe (PID: 8052)
      • ngen.exe (PID: 7344)
      • ngen.exe (PID: 8116)
      • ngen.exe (PID: 6452)
      • ngen.exe (PID: 2248)
      • ngen.exe (PID: 4788)
    • Reads the machine GUID from the registry

      • vs_BuildTools.exe (PID: 6828)
      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
      • setup.exe (PID: 7012)
      • msiexec.exe (PID: 7220)
    • Create files in a temporary directory

      • vs_BuildTools.exe (PID: 6828)
      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
      • setup.exe (PID: 7012)
      • MofCompiler.exe (PID: 6484)
      • mofcomp.exe (PID: 8036)
    • Reads the computer name

      • vs_BuildTools.exe (PID: 6828)
      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
      • vs_installer.windows.exe (PID: 8080)
      • setup.exe (PID: 7012)
      • msiexec.exe (PID: 7220)
      • ngen.exe (PID: 7136)
      • ngen.exe (PID: 4088)
      • Microsoft.Build.UnGAC.exe (PID: 840)
      • msiexec.exe (PID: 6812)
      • MofCompiler.exe (PID: 6484)
      • ngen.exe (PID: 8052)
      • ngen.exe (PID: 8116)
      • ngen.exe (PID: 7344)
      • ngen.exe (PID: 6452)
      • ngen.exe (PID: 2248)
      • ngen.exe (PID: 4788)
    • Process checks computer location settings

      • vs_BuildTools.exe (PID: 6828)
      • setup.exe (PID: 7740)
    • Reads Environment values

      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
      • setup.exe (PID: 7012)
    • Creates files in the program directory

      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
      • setup.exe (PID: 7012)
    • Displays MAC addresses of computer network adapters

      • getmac.exe (PID: 2904)
    • Disables trace logs

      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7012)
      • setup.exe (PID: 7740)
    • Checks proxy server information

      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
      • setup.exe (PID: 7012)
    • Reads the software policy settings

      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
      • msiexec.exe (PID: 7220)
      • setup.exe (PID: 7012)
    • Reads CPU info

      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
    • Creates files or folders in the user directory

      • vs_setup_bootstrapper.exe (PID: 7044)
      • setup.exe (PID: 7740)
      • setup.exe (PID: 7012)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7220)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 7220)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:26 18:21:13+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 227328
InitializedDataSize: 199680
UninitializedDataSize: -
EntryPoint: 0x1dfd0
OSVersion: 5.1
ImageVersion: 10
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 17.10.35122.118
ProductVersionNumber: 17.10.35122.118
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Visual Studio Installer
FileVersion: 17.10.35122.118
InternalName: vs_buildtools.exe
OriginalFileName: vs_buildtools.exe
ProductName: Microsoft Visual Studio BuildTools
ProductVersion: Visual Studio 2022
LegalCopyright: © Microsoft Corporation. All rights reserved.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
162
Monitored processes
31
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start vs_buildtools.exe THREAT vs_setup_bootstrapper.exe getmac.exe no specs conhost.exe no specs THREAT setup.exe vs_installer.windows.exe no specs conhost.exe no specs THREAT setup.exe msiexec.exe ngen.exe no specs conhost.exe no specs ngen.exe no specs conhost.exe no specs microsoft.build.ungac.exe no specs conhost.exe no specs msiexec.exe no specs mofcompiler.exe no specs mofcomp.exe conhost.exe no specs ngen.exe no specs conhost.exe no specs ngen.exe no specs conhost.exe no specs ngen.exe no specs conhost.exe no specs ngen.exe no specs conhost.exe no specs ngen.exe no specs conhost.exe no specs ngen.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
840"C:\ProgramData\Microsoft\VisualStudio\Packages\Microsoft.Build.UnGAC,version=17.10.4.2421802,chip=neutral,language=neutral\Microsoft.Build.UnGAC.exe"C:\ProgramData\Microsoft\VisualStudio\Packages\Microsoft.Build.UnGAC,version=17.10.4.2421802,chip=neutral,language=neutral\Microsoft.Build.UnGAC.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft.Build.UnGAC.exe
Exit code:
0
Version:
17.10.4.21802
Modules
Images
c:\programdata\microsoft\visualstudio\packages\microsoft.build.ungac,version=17.10.4.2421802,chip=neutral,language=neutral\microsoft.build.ungac.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1168\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exegetmac.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1288\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2248"C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\ngen.exe" eqi 0C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
4.8.9093.0 built by: NET481REL1LAST_C
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\oleaut32.dll
c:\windows\syswow64\msvcp_win.dll
2852\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2904"getmac"C:\Windows\SysWOW64\getmac.exevs_setup_bootstrapper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Displays NIC MAC information
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\getmac.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3980\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeMicrosoft.Build.UnGAC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4088"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\ngen.exe" queue pauseC:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
4.8.9093.0 built by: NET481REL1LAST_C
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\ngen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\rpcrt4.dll
4664\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4788"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\ngen.exe" eqi 0C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
4.8.9093.0 built by: NET481REL1LAST_C
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\ngen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\vcruntime140_1_clr0400.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
50 731
Read events
48 819
Write events
1 711
Delete events
201

Modification events

(PID) Process:(6828) vs_BuildTools.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6828) vs_BuildTools.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6828) vs_BuildTools.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6828) vs_BuildTools.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(7044) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry
Operation:writeName:UseCollector
Value:
0
(PID) Process:(7044) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry\Default\v2
Operation:writeName:UseCollector
Value:
0
(PID) Process:(7044) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7044) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7044) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7044) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
1 123
Suspicious files
267
Text files
749
Unknown types
29

Dropped files

PID
Process
Filename
Type
6828vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\d5e7e87311f25124f06bd23e06d7\vs_bootstrapper_d15\HelpFile\1045\help.htmlhtml
MD5:9147BC24EACE34955B865DAA39DAD8AB
SHA256:322DB9FFDB987D0C824A4DE3B8DB40722BCAF95833DCF90E7B5F250A841E592B
6828vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\d5e7e87311f25124f06bd23e06d7\vs_bootstrapper_d15\HelpFile\1049\help.htmlhtml
MD5:66D963430209555CDCB8A5C0219BC60C
SHA256:D9AB0A8DB5A8409C5849AA4E1512576225E5B320EA79B0CDC83C2B4848401611
6828vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\d5e7e87311f25124f06bd23e06d7\vs_bootstrapper_d15\HelpFile\1041\help.htmlhtml
MD5:92E54A7DB253A0A47C03B44D9651DF3C
SHA256:36C917F205A9C9D5F37788CA45ECD57D0F8EEB498F8320849BBEDF49E012E9F9
6828vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\d5e7e87311f25124f06bd23e06d7\vs_bootstrapper_d15\HelpFile\1031\help.htmlhtml
MD5:6F489A55562732D253AD828581176A9A
SHA256:9502AC0910BCEE0EB3123F7B68A605D71C8DF72FE7B33F4173AFB4A01390581A
6828vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\d5e7e87311f25124f06bd23e06d7\vs_bootstrapper_d15\vs_setup_bootstrapper.exeexecutable
MD5:C9BCDD344D7619BD194F559D33FF9DCE
SHA256:A3100E29573504E179461B12AC0B3122E12FE244D97F25EB8ED71E78179280DE
6828vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\d5e7e87311f25124f06bd23e06d7\vs_bootstrapper_d15\Microsoft.Identity.Client.Extensions.Msal.dllexecutable
MD5:352EE196CD65C98B729065AAF6F5C9E3
SHA256:6CEAA8B598E7985D5637AB1659566DFF9C1FDA37EDF0F044759B56444F739018
6828vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\d5e7e87311f25124f06bd23e06d7\vs_bootstrapper_d15\Microsoft.C2RSignatureReader.Native.dllexecutable
MD5:EA3B357B6EFF9D689243D02088A5C964
SHA256:D7EB59207A18D48F3064F2A727D252FFD201EDCDAA89EAB76EF43625783BE1C3
6828vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\d5e7e87311f25124f06bd23e06d7\vs_bootstrapper_d15\Microsoft.C2RSignatureReader.Interop.dllexecutable
MD5:C3AA65379798016352CAA4694FFF630B
SHA256:46476D4EE964F2E2B7C686774DB5BF7C24B3B0B9879E43A946F40048DE3A5758
6828vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\d5e7e87311f25124f06bd23e06d7\vs_bootstrapper_d15\Microsoft.Identity.Client.dllexecutable
MD5:B55A27FA0913854773F9C9F5A42C4456
SHA256:C7674FA4E25B030DA4AC00A3D63E1466418204E485203779D6DBAB2CC753CBFA
6828vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\d5e7e87311f25124f06bd23e06d7\vs_bootstrapper_d15\Microsoft.Identity.Client.Broker.dllexecutable
MD5:D69DDC47DDB2C4C8937E4EFCBB6E29D0
SHA256:5E93BB3957C3001DB4F0938848DEFCF247DDADB3E779F56E87F7838D62509B9C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
86
DNS requests
39
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3844
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3844
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6460
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6508
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7044
vs_setup_bootstrapper.exe
GET
200
23.36.225.233:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
7044
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
7044
vs_setup_bootstrapper.exe
GET
200
23.36.225.233:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
7044
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4788
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
92.123.104.51:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
3844
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
40.126.32.72:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.bing.com
  • 92.123.104.51
  • 92.123.104.59
  • 92.123.104.60
  • 92.123.104.52
  • 92.123.104.66
  • 92.123.104.67
  • 92.123.104.62
  • 92.123.104.63
  • 92.123.104.65
  • 92.123.104.38
  • 92.123.104.41
  • 92.123.104.33
  • 92.123.104.35
  • 92.123.104.36
  • 92.123.104.45
  • 92.123.104.37
  • 92.123.104.42
  • 92.123.104.34
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.133
  • 40.126.32.138
  • 40.126.32.68
  • 20.190.160.17
  • 40.126.32.140
  • 40.126.32.74
  • 20.190.160.14
  • 40.126.32.72
  • 40.126.32.134
  • 40.126.32.136
  • 40.126.32.76
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
az667904.vo.msecnd.net
  • 152.199.19.161
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
az700632.vo.msecnd.net
  • 152.199.19.161
whitelisted
targetednotifications-tm.trafficmanager.net
  • 20.42.128.98
  • 13.85.16.224
whitelisted

Threats

No threats detected
No debug info