File name:

HxDPortableSetup.exe

Full analysis: https://app.any.run/tasks/373b7cdd-2e70-4d88-833e-41c029b7fe2a
Verdict: Malicious activity
Analysis date: May 15, 2025, 17:26:15
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
arch-exec
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

565554EA03B1EF7812E66F13262DE601

SHA1:

77558FF5D65D181B9DE3BA353538283F51DE396C

SHA256:

7EED3FBB271A7DB6D061106A0E20A5A193388F800812266CDBB7526E469820A8

SSDEEP:

98304:SYgmygQ4mUSSlmD5u6hY1T/zgzdpV9u1O:fgmw4iS+r205pVMo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • HxDPortableSetup.exe (PID: 7012)
      • HxDPortableSetup.tmp (PID: 1276)
    • Reads security settings of Internet Explorer

      • HxDPortableSetup.tmp (PID: 1276)
    • Reads the Windows owner or organization settings

      • HxDPortableSetup.tmp (PID: 1276)
    • Application launched itself

      • HxD64.exe (PID: 5936)
    • Start notepad (likely ransomware note)

      • HxDPortableSetup.tmp (PID: 1276)
  • INFO

    • Create files in a temporary directory

      • HxDPortableSetup.exe (PID: 7012)
      • HxDPortableSetup.tmp (PID: 1276)
    • Checks supported languages

      • HxDPortableSetup.exe (PID: 7012)
      • HxDPortableSetup.tmp (PID: 1276)
      • HxD64.exe (PID: 5936)
      • HxD64.exe (PID: 4180)
    • Detects InnoSetup installer (YARA)

      • HxDPortableSetup.exe (PID: 7012)
      • HxDPortableSetup.tmp (PID: 1276)
    • Reads the computer name

      • HxDPortableSetup.tmp (PID: 1276)
      • HxD64.exe (PID: 5936)
    • Compiled with Borland Delphi (YARA)

      • HxDPortableSetup.exe (PID: 7012)
      • HxDPortableSetup.tmp (PID: 1276)
    • The sample compiled with english language support

      • HxDPortableSetup.tmp (PID: 1276)
      • WinRAR.exe (PID: 7456)
    • Reads Environment values

      • HxD64.exe (PID: 5936)
    • Reads product name

      • HxD64.exe (PID: 5936)
    • Process checks computer location settings

      • HxDPortableSetup.tmp (PID: 1276)
    • Application launched itself

      • firefox.exe (PID: 2152)
      • firefox.exe (PID: 3020)
    • Reads the software policy settings

      • slui.exe (PID: 6632)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 7244)
    • Manual execution by a user

      • WinRAR.exe (PID: 7456)
      • firefox.exe (PID: 3020)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:06:14 13:27:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x1181c
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.5.0.0
ProductVersionNumber: 2.5.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Maël Hörz
FileDescription: HxD Hex Editor Portable Setup
FileVersion: 2.5
LegalCopyright: Copyright © 2002-2021 Maël Hörz
ProductName: HxD Hex Editor Portable
ProductVersion: 2.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
159
Monitored processes
28
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start hxdportablesetup.exe hxdportablesetup.tmp sppextcomobj.exe no specs slui.exe hxd64.exe no specs hxd64.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs notepad.exe no specs rundll32.exe no specs slui.exe winrar.exe no specs firefox.exe no specs firefox.exe no specs svchost.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
616"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6072 -childID 9 -isForBrowser -prefsHandle 6000 -prefMapHandle 6120 -prefsLen 31597 -prefMapSize 244583 -jsInitHandle 1516 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {5bb25174-9a8c-4f08-bd4a-fcc096b22a83} 2152 "\\.\pipe\gecko-crash-server-pipe.2152" 1956fe3dd90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
736"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2148 -parentBuildID 20240213221259 -prefsHandle 2140 -prefMapHandle 2136 -prefsLen 31031 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {27ee0860-88fc-4d1a-91df-18e15f80bf00} 2152 "\\.\pipe\gecko-crash-server-pipe.2152" 1955bd82b10 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1276"C:\Users\admin\AppData\Local\Temp\is-JUGKA.tmp\HxDPortableSetup.tmp" /SL5="$6030E,2973524,121344,C:\Users\admin\AppData\Local\Temp\HxDPortableSetup.exe" C:\Users\admin\AppData\Local\Temp\is-JUGKA.tmp\HxDPortableSetup.tmp
HxDPortableSetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-jugka.tmp\hxdportablesetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2152"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2284"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5940 -childID 10 -isForBrowser -prefsHandle 5100 -prefMapHandle 4460 -prefsLen 31597 -prefMapSize 244583 -jsInitHandle 1516 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f6c8a630-8091-4c06-9b95-93108fa0cb1a} 2152 "\\.\pipe\gecko-crash-server-pipe.2152" 195701bd850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
2644"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5416 -childID 5 -isForBrowser -prefsHandle 5408 -prefMapHandle 5404 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1516 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {65f3c156-4510-4c24-8aea-fba6922f286d} 2152 "\\.\pipe\gecko-crash-server-pipe.2152" 195717e5150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2984"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1912 -parentBuildID 20240213221259 -prefsHandle 1828 -prefMapHandle 1816 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2e5f9ed9-7957-4d6d-91db-80f102e56281} 2152 "\\.\pipe\gecko-crash-server-pipe.2152" 19568eed310 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140_1.dll
3020"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\crypt32.dll
3676C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
20 903
Read events
20 897
Write events
6
Delete events
0

Modification events

(PID) Process:(2152) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(1276) HxDPortableSetup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithProgids
Operation:writeName:txtfile
Value:
(PID) Process:(7456) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7456) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7456) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7456) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
6
Suspicious files
228
Text files
33
Unknown types
0

Dropped files

PID
Process
Filename
Type
2152firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
1276HxDPortableSetup.tmpC:\Users\admin\Desktop\HxD\license.txttext
MD5:4E93FBC8DB2A3BF7CC8336DE7B75169F
SHA256:DD616207E21510E9F8F3F2A220DA037DC2C8BED8D90927A2C00C01A6AFF104CF
1276HxDPortableSetup.tmpC:\Users\admin\Desktop\HxD\is-5491B.tmptext
MD5:0755D4E1FDF379C36369E96F6F6D8FA8
SHA256:CA4F74DE91DB68DB75A685640957140C42D8D01659C20CF72EB771A0F7BCBA2D
1276HxDPortableSetup.tmpC:\Users\admin\Desktop\HxD\HxD64.exeexecutable
MD5:14FCA45F383B3DE689D38F45C283F71F
SHA256:9D460040A454DEEB3FE69300FE6B9017350E1EFCB1F52F7F14A4702D96CB45CA
7012HxDPortableSetup.exeC:\Users\admin\AppData\Local\Temp\is-JUGKA.tmp\HxDPortableSetup.tmpexecutable
MD5:34ACC2BDB45A9C436181426828C4CB49
SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07
1276HxDPortableSetup.tmpC:\Users\admin\Desktop\HxD\HxD32.exeexecutable
MD5:804F06B24FBA7BA4E1122FAF2B119A2B
SHA256:1FC927CB6747C105D1A66E4792F166B857A9E42BC1B58A08A6698C2D05E62087
1276HxDPortableSetup.tmpC:\Users\admin\Desktop\HxD\readme.txttext
MD5:0755D4E1FDF379C36369E96F6F6D8FA8
SHA256:CA4F74DE91DB68DB75A685640957140C42D8D01659C20CF72EB771A0F7BCBA2D
1276HxDPortableSetup.tmpC:\Users\admin\Desktop\HxD\is-QG94R.tmptext
MD5:4E93FBC8DB2A3BF7CC8336DE7B75169F
SHA256:DD616207E21510E9F8F3F2A220DA037DC2C8BED8D90927A2C00C01A6AFF104CF
1276HxDPortableSetup.tmpC:\Users\admin\Desktop\HxD\changelog.txttext
MD5:E5884E3283664012C3F2DAADE3B4FC8B
SHA256:176FE3F6276CE5E2DED4A23F63F7216114B44D9844E01F33ED1F5A862C653010
1276HxDPortableSetup.tmpC:\Users\admin\Desktop\HxD\is-46E9C.tmptext
MD5:E5884E3283664012C3F2DAADE3B4FC8B
SHA256:176FE3F6276CE5E2DED4A23F63F7216114B44D9844E01F33ED1F5A862C653010
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
59
TCP/UDP connections
218
DNS requests
223
Threats
17

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2152
firefox.exe
POST
200
184.24.77.44:80
http://r10.o.lencr.org/
unknown
whitelisted
2152
firefox.exe
POST
200
184.24.77.44:80
http://r10.o.lencr.org/
unknown
whitelisted
2152
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
2152
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/we2
unknown
whitelisted
2152
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
4208
RUXIMICS.exe
GET
200
23.48.23.150:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2104
svchost.exe
GET
200
23.48.23.150:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4208
RUXIMICS.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4208
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4208
RUXIMICS.exe
23.48.23.150:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
23.48.23.150:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4208
RUXIMICS.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.150
  • 23.48.23.146
  • 23.48.23.193
  • 23.48.23.145
  • 23.48.23.141
  • 23.48.23.148
  • 23.48.23.194
  • 23.48.23.135
  • 23.48.23.195
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.67
  • 20.190.160.14
  • 40.126.32.138
  • 20.190.160.3
  • 40.126.32.140
  • 20.190.160.5
  • 20.190.160.20
  • 20.190.160.130
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
2196
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
2196
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
No debug info