File name:

22774963304.zip

Full analysis: https://app.any.run/tasks/7d1a8f86-2b6f-46ca-afa2-f5239c2bb81e
Verdict: Malicious activity
Analysis date: June 19, 2025, 19:32:06
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
delphi
inno
installer
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

7A0F23A09A079BF5391EAF786E2F8947

SHA1:

C27EC3380837037ECC2F28CF3844663C6CDA7EF5

SHA256:

87C41CECA2F4DCD4C90CEBBA9FA354C3B8700A2A5E3830E3A4387852467538B5

SSDEEP:

98304:VRjGT+UrcgZW4eYlPjoWcORDgcxqltn7gtfgsbuk3yn6XRqgLgv4b9njOt30xm5H:VlGwJqX23/fYjEHSUJe9/rMRKK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 5348)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 4760)
      • netscan.exe (PID: 7164)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 3740)
      • netscan.exe (PID: 7164)
    • Executable content was dropped or overwritten

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 4760)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 1760)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 5348)
    • Reads the Windows owner or organization settings

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 1760)
  • INFO

    • Manual execution by a user

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 5348)
    • Checks supported languages

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 5348)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 1760)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 4760)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 3740)
      • netscan.exe (PID: 7164)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1984)
    • Reads the computer name

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 3740)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 4760)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 1760)
      • netscan.exe (PID: 7164)
    • Create files in a temporary directory

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 4760)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 1760)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 5348)
    • Process checks computer location settings

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 3740)
    • Detects InnoSetup installer (YARA)

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 5348)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 3740)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 4760)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 1760)
    • Creates files or folders in the user directory

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 1760)
      • netscan.exe (PID: 7164)
    • The sample compiled with english language support

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 1760)
    • Compiled with Borland Delphi (YARA)

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 5348)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 3740)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 1760)
      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe (PID: 4760)
    • Creates a software uninstall entry

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 1760)
    • Creates files in the program directory

      • 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp (PID: 1760)
      • netscan.exe (PID: 7164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x5181c889
ZipCompressedSize: 12856802
ZipUncompressedSize: 13389632
ZipFileName: 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
7
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp no specs 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe 0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp slui.exe no specs netscan.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1760"C:\Users\admin\AppData\Local\Temp\is-88OC8.tmp\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp" /SL5="$7031E,12329888,867840,C:\Users\admin\Desktop\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe" /SPAWNWND=$702E0 /NOTIFYWND=$8037A C:\Users\admin\AppData\Local\Temp\is-88OC8.tmp\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp
0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe
User:
admin
Company:
SoftPerfect Pty Ltd
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-88oc8.tmp\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
1984"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\22774963304.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3740"C:\Users\admin\AppData\Local\Temp\is-9304H.tmp\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp" /SL5="$8037A,12329888,867840,C:\Users\admin\Desktop\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe" C:\Users\admin\AppData\Local\Temp\is-9304H.tmp\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe
User:
admin
Company:
SoftPerfect Pty Ltd
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-9304h.tmp\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4760"C:\Users\admin\Desktop\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe" /SPAWNWND=$702E0 /NOTIFYWND=$8037A C:\Users\admin\Desktop\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe
0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp
User:
admin
Company:
SoftPerfect Pty Ltd
Integrity Level:
HIGH
Description:
SoftPerfect Network Scanner
Exit code:
0
Version:
25.6
Modules
Images
c:\users\admin\desktop\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
5348"C:\Users\admin\Desktop\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe" C:\Users\admin\Desktop\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe
explorer.exe
User:
admin
Company:
SoftPerfect Pty Ltd
Integrity Level:
MEDIUM
Description:
SoftPerfect Network Scanner
Exit code:
0
Version:
25.6
Modules
Images
c:\users\admin\desktop\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
7092C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7164"C:\Program Files\SoftPerfect Network Scanner\netscan.exe"C:\Program Files\SoftPerfect Network Scanner\netscan.exe0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmp
User:
admin
Company:
SoftPerfect Pty Ltd
Integrity Level:
MEDIUM
Description:
Application for scanning networks
Version:
25.6.0.0
Modules
Images
c:\program files\softperfect network scanner\netscan.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
6 194
Read events
6 109
Write events
71
Delete events
14

Modification events

(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\22774963304.zip
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
12
Suspicious files
6
Text files
680
Unknown types
0

Dropped files

PID
Process
Filename
Type
53480b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.exeC:\Users\admin\AppData\Local\Temp\is-9304H.tmp\0b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmpexecutable
MD5:78E33E5AFF4B483B95A4362D9A77F5AE
SHA256:60634DB3E1B16908D17663BBDF47EC9D82CBB2B250AFDA75E5F1B785563DF724
17600b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmpC:\Users\admin\AppData\Local\Temp\is-EJ7R1.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
17600b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmpC:\Users\admin\AppData\Roaming\SoftPerfect Network Scanner\Mibs\ACCESSBIND-PIBtext
MD5:0F5E93840F554BC192069F9D556B98B9
SHA256:D45B578B3A21E40AA165C58CDA8A86E402B1C9556FF461D4F22A185EDA74A81A
17600b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmpC:\Users\admin\AppData\Roaming\SoftPerfect Network Scanner\Mibs\ACCOUNTING-CONTROL-MIBtext
MD5:B3D5843D270546D9D304BA2F5BA03DE4
SHA256:2E476CE697C592E4F39A0E43EB51E4EBD8977C41D7FDA287C9DE7B98CFA6F1CA
17600b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmpC:\Users\admin\AppData\Roaming\SoftPerfect Network Scanner\Mibs\ACCOUNTING-FRAMEWORK-PIBtext
MD5:3BCBD550C01F34F323BED1E4EA7083BD
SHA256:84E202C003BFB45B14212F3880DD4FF6E7CF1825E8935A08086F144155EF1202
17600b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmpC:\Users\admin\AppData\Roaming\SoftPerfect Network Scanner\Mibs\is-8J812.tmptext
MD5:62317CE9EFF85065D1828F8BFD8B8165
SHA256:38227DA168C76CC0B23730A33F4C90698CCE1F3A2E2FB6C8AFACE396AC8CC564
17600b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmpC:\Users\admin\AppData\Roaming\SoftPerfect Network Scanner\Mibs\is-6IK5I.tmptext
MD5:3BCBD550C01F34F323BED1E4EA7083BD
SHA256:84E202C003BFB45B14212F3880DD4FF6E7CF1825E8935A08086F144155EF1202
17600b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmpC:\Users\admin\AppData\Roaming\SoftPerfect Network Scanner\Mibs\is-ES47O.tmptext
MD5:94895CA7AFCF9B9501E6EEFE5D684CA3
SHA256:0DE89F0BD22C373072A1525EA219C9403FF0642D31C25C27ED66C35456C8C3F1
17600b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmpC:\Users\admin\AppData\Roaming\SoftPerfect Network Scanner\Mibs\ADSL2-LINE-MIBtext
MD5:5DDDCC925D0AF9E3AC7542ACE919817C
SHA256:7ACA55BAA4470867172F702382C4E798C9F75B688B56AA8964D8B7A12BB3E20A
17600b99aad90998c532f7419426202e3ab729eb80f1eb1fed8bc9e7641991ac357a.tmpC:\Program Files\SoftPerfect Network Scanner\is-5969D.tmpexecutable
MD5:FB2CE6765C7A60824D9B70BCAA8EA7CD
SHA256:52C7541793B15510A81B743A998938BE7AE8E0D7295D9150267F76E0AD9C9C4D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
25
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.48.23.137:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2524
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5124
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5124
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2940
svchost.exe
GET
200
23.209.209.135:80
http://x1.c.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6672
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2336
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
2524
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2524
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.48.23.137:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 216.58.212.142
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.68
  • 40.126.31.2
  • 40.126.31.129
  • 40.126.31.130
  • 40.126.31.67
  • 40.126.31.3
  • 40.126.31.128
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
crl.microsoft.com
  • 23.48.23.137
  • 23.48.23.185
  • 23.48.23.181
  • 23.48.23.141
  • 23.48.23.145
  • 23.48.23.140
  • 23.48.23.191
  • 23.48.23.143
  • 23.48.23.138
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.48
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

No threats detected
No debug info