File name:

spacedesk_driver_Win_10_64_v2147.msi

Full analysis: https://app.any.run/tasks/5501386e-fdd5-4cc2-baa7-7687da1a6ea4
Verdict: Malicious activity
Analysis date: May 19, 2025, 02:52:07
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: spacedesk 2.1.47 Driver Installer, Author: datronicsoft Inc., Keywords: Installer, Comments: Windows Network Display Monitor Software, Template: x64;1033, Revision Number: {DE1F57CB-6739-4B11-AF92-4BAEBFC1255E}, Create Time/Date: Thu May 15 02:29:54 2025, Last Saved Time/Date: Thu May 15 02:29:54 2025, Number of Pages: 500, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
MD5:

A4144F55C208430410CCD49DE937A68C

SHA1:

F06B1192C87C85600FB2A0B3C0B87415C8D04541

SHA256:

7E57324A72C38AE70CA9BF1EDCB8F527E3867572653A825926E9090BDF54A178

SSDEEP:

98304:TQAHlO52KtZrup9SpdcfBNNs9zHlX7ApkpRplv97YlXw9Nx/G7dn7IDCZGnVE9S6:kIXu7h4Ui/Kh9cQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 7884)
      • spacedeskService.exe (PID: 8136)
    • Executable content was dropped or overwritten

      • MSI5D15.tmp (PID: 7996)
      • drvinst.exe (PID: 8120)
      • drvinst.exe (PID: 2904)
      • drvinst.exe (PID: 1228)
      • MSI641D.tmp (PID: 5640)
      • drvinst.exe (PID: 7564)
      • drvinst.exe (PID: 7576)
      • MSI6576.tmp (PID: 8000)
      • MSI66FD.tmp (PID: 4996)
      • MSI62E3.tmp (PID: 6540)
      • MSI68D3.tmp (PID: 8108)
      • drvinst.exe (PID: 5244)
      • drvinst.exe (PID: 5868)
      • drvinst.exe (PID: 960)
      • drvinst.exe (PID: 1088)
      • MSI6A5B.tmp (PID: 5600)
    • Drops a system driver (possible attempt to evade defenses)

      • MSI5D15.tmp (PID: 7996)
      • drvinst.exe (PID: 8120)
      • msiexec.exe (PID: 7224)
      • drvinst.exe (PID: 2904)
      • drvinst.exe (PID: 1228)
      • MSI62E3.tmp (PID: 6540)
      • MSI66FD.tmp (PID: 4996)
      • drvinst.exe (PID: 1088)
      • MSI68D3.tmp (PID: 8108)
      • drvinst.exe (PID: 5244)
      • drvinst.exe (PID: 960)
      • drvinst.exe (PID: 5868)
      • MSI6A5B.tmp (PID: 5600)
    • Starts POWERSHELL.EXE for commands execution

      • spacedeskConsole.exe (PID: 6516)
    • Likely accesses (executes) a file from the Public directory

      • powershell.exe (PID: 8000)
      • powershell.exe (PID: 4740)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 7224)
      • msiexec.exe (PID: 7772)
    • Reads the software policy settings

      • msiexec.exe (PID: 2564)
    • An automatically generated document

      • msiexec.exe (PID: 2564)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 2564)
    • Checks proxy server information

      • msiexec.exe (PID: 2564)
    • Manages system restore points

      • SrTasks.exe (PID: 2240)
    • The sample compiled with english language support

      • msiexec.exe (PID: 7224)
      • MSI5D15.tmp (PID: 7996)
      • drvinst.exe (PID: 8120)
      • drvinst.exe (PID: 7564)
      • MSI6576.tmp (PID: 8000)
      • drvinst.exe (PID: 7576)
      • drvinst.exe (PID: 2904)
      • MSI641D.tmp (PID: 5640)
      • drvinst.exe (PID: 5868)
      • MSI6A5B.tmp (PID: 5600)
      • drvinst.exe (PID: 960)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 2564)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2564)
      • msiexec.exe (PID: 7224)
    • Reads the computer name

      • msiexec.exe (PID: 7224)
      • msiexec.exe (PID: 7772)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 7224)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: spacedesk 2.1.47 Driver Installer
Author: datronicsoft Inc.
Keywords: Installer
Comments: Windows Network Display Monitor Software
Template: x64;1033
RevisionNumber: {DE1F57CB-6739-4B11-AF92-4BAEBFC1255E}
CreateDate: 2025:05:15 02:29:54
ModifyDate: 2025:05:15 02:29:54
Pages: 500
Words: 2
Software: Windows Installer XML Toolset (3.14.1.8722)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
176
Monitored processes
40
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe sppextcomobj.exe no specs slui.exe no specs msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msi5b6c.tmp no specs msi5bcb.tmp no specs msi5cc6.tmp no specs msi5d15.tmp drvinst.exe drvinst.exe no specs msi618b.tmp no specs drvinst.exe msi62e3.tmp drvinst.exe msi641d.tmp drvinst.exe msi6576.tmp drvinst.exe msi66fd.tmp drvinst.exe msi68d3.tmp drvinst.exe msi6a5b.tmp drvinst.exe drvinst.exe msi6be2.tmp no specs spacedeskservice.exe no specs spacedeskservicetray.exe no specs msi6c51.tmp no specs msi6ccf.tmp no specs msi6daa.tmp no specs spacedeskconsole.exe powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
960DrvInst.exe "2" "1" "ROOT\SPACEDESK_VIRTUAL_BUS\0000" "C:\WINDOWS\System32\DriverStore\FileRepository\spacedeskdriverbus.inf_amd64_c3aa8673bc8e2935\spacedeskdriverbus.inf" "oem12.inf:*:*:1.0.476.48:Root\VID_DATRONICSOFT_PID_SPACEDESK_VIRTUAL_BUS_0001," "4522ade83" "0000000000000218"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1088DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{0c82eca5-cd58-d943-a9fd-d05e2eeebea8}\spacedeskDriverAudio.inf" "9" "447268673" "0000000000000214" "WinSta0\Default" "00000000000001C0" "208" "C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1228DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{7851909c-35cc-214d-bc7d-6dcd5f897ae1}\spacedeskKtmInputmouse.inf" "9" "431da1b7b" "00000000000001BC" "WinSta0\Default" "0000000000000200" "208" "C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1660"C:\WINDOWS\Installer\MSI6C51.tmp" -openFirewall,C:\Program Files\datronicsoft\spacedesk\C:\Windows\Installer\MSI6C51.tmpmsiexec.exe
User:
admin
Company:
datronicsoft
Integrity Level:
MEDIUM
Description:
spacedesk Setup Custom Action
Exit code:
0
Version:
0.2.1.47
Modules
Images
c:\windows\installer\msi6c51.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2240C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2344"C:\WINDOWS\Installer\MSI5BCB.tmp" -preInstallCheck_W10C:\Windows\Installer\MSI5BCB.tmpmsiexec.exe
User:
admin
Company:
datronicsoft
Integrity Level:
MEDIUM
Description:
spacedesk Setup Custom Action
Exit code:
0
Version:
0.2.1.47
Modules
Images
c:\windows\installer\msi5bcb.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2564"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\Downloads\spacedesk_driver_Win_10_64_v2147.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2904DrvInst.exe "4" "1" "C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles\spacedeskDriverAndroidUsb.inf" "9" "4c4c2d17b" "00000000000001C4" "WinSta0\Default" "0000000000000174" "208" "C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
3008\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4336\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
46 857
Read events
46 483
Write events
340
Delete events
34

Modification events

(PID) Process:(7224) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
48000000000000008AB2281569C8DB01381C0000BC1E0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7224) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000008AB2281569C8DB01381C0000BC1E0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7224) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
48000000000000002B42701569C8DB01381C0000BC1E0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7224) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000002B42701569C8DB01381C0000BC1E0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7224) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000AFA6721569C8DB01381C0000BC1E0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7224) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000001D6F771569C8DB01381C0000BC1E0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7224) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000000F84FA1569C8DB01381C0000441F0000E8030000010000000000000000000000DC37BE5003A4CB4495789EE834A7CC2600000000000000000000000000000000
(PID) Process:(7884) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{5b970157-8568-11eb-b45c-806e6f6e6963}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(7884) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{5b970157-8568-11eb-b45c-806e6f6e6963}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
(PID) Process:(7884) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{5b970157-8568-11eb-b45c-806e6f6e6963}\Elements\12000002
Operation:delete keyName:(default)
Value:
Executable files
66
Suspicious files
112
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
7224msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
7224msiexec.exeC:\Windows\Installer\11539b.msi
MD5:
SHA256:
7224msiexec.exeC:\Windows\Installer\MSI58CB.tmp
MD5:
SHA256:
2564msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIE030.tmpexecutable
MD5:CFBB8568BD3711A97E6124C56FCFA8D9
SHA256:7F47D98AB25CFEA9B3A2E898C3376CC9BA1CD893B4948B0C27CAA530FD0E34CC
2564msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:E1E31A2E4E237C5D96775E6F03EF3E39
SHA256:819D7B07839B7FCAA426642100EADA086E396130F068B5C3A5285F5CA41E11EF
2564msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:2E8D4B3BFB5CE6C311243DEBF6B07574
SHA256:C037CDD72A7250EB5CCA5ABCAFD2902910973250A68E890D7F848B439F6FE464
2564msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_74F67001B3C2D533D99B6A2860970A04binary
MD5:15D49E52F9E970B8EFAFA9A90DCF8EB4
SHA256:44A5A70B9B6FAC654D24B95D0A3E4D451A8AFCD4B3EBC0F82689273BD711A187
7224msiexec.exeC:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles\spacedeskdisplay.infbinary
MD5:BB684F41B7E74985B6628AD582611C00
SHA256:809313953ED87D5AC011EBB5F06BAE228A2AA03F902663024DE97A1AA20C9B75
7224msiexec.exeC:\Windows\Temp\~DF6000DF3DDF85CE5E.TMPbinary
MD5:E4C2A306549D544EC173579ABF0F9CC0
SHA256:FC58DF3754B9CC70EB99E6877C46D1C95E5184F264EF7F7C04454E639E89269D
7224msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:EE5705E22C3C3C7C642C9FEB6F31071C
SHA256:0A561078046C6A7ABE3BABC0D3B90D9A9FBD4BFBB0C2FE9B4B873854A797B5D9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
46
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2564
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA4bLnp0JeaKiM0Z462JHJc%3D
unknown
whitelisted
2564
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
2564
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8100
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2564
msiexec.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.174
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.128
  • 40.126.32.134
  • 20.190.160.131
  • 40.126.32.136
  • 20.190.160.3
  • 20.190.160.65
  • 40.126.32.76
  • 40.126.32.68
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
www.bing.com
  • 92.123.104.31
  • 92.123.104.34
  • 92.123.104.38
  • 92.123.104.63
  • 92.123.104.32
whitelisted

Threats

No threats detected
No debug info