File name:

Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK.zip

Full analysis: https://app.any.run/tasks/90d3fbf6-14d3-4ba0-8d78-0e2bc5690c55
Verdict: Malicious activity
Analysis date: July 15, 2024, 15:01:02
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

A430CA41C1C526F83123E847390CDBC2

SHA1:

0E7D09D36A52956DC332392F958327DC72F8585B

SHA256:

8B3860209404027D766C301B1810AF8B930F86BE5D9E7A0D0739BA0766516F9A

SSDEEP:

98304:UwQOuEa3fHO6Y/Kc6nChGA7tJx6GRofH93eGUpcFRQFQ+OltHBrYu98F97wkbvlp:Zdn/uSCFXXWeJ0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2100)
      • Air.Explorer.Pro.v5.4.3.exe (PID: 3836)
      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
    • Modifies hosts file to block updates

      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Air.Explorer.Pro.v5.4.3.exe (PID: 3836)
      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
    • The process creates files with name similar to system file names

      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
      • Air.Explorer.Pro.v5.4.3.exe (PID: 3836)
    • Process drops legitimate windows executable

      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
      • Air.Explorer.Pro.v5.4.3.exe (PID: 3836)
    • Creates a software uninstall entry

      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
      • Air.Explorer.Pro.v5.4.3.exe (PID: 3836)
    • Process uses IPCONFIG to clear DNS cache

      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
      • Air.Explorer.Pro.v5.4.3.exe (PID: 3836)
    • Changes Internet Explorer settings (feature browser emulation)

      • AirExplorer.exe (PID: 1960)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2100)
    • Manual execution by a user

      • Air.Explorer.Pro.v5.4.3.exe (PID: 4536)
      • Air.Explorer.Pro.v5.4.3.exe (PID: 3836)
      • cmd.exe (PID: 640)
    • Checks supported languages

      • Air.Explorer.Pro.v5.4.3.exe (PID: 3836)
      • mode.com (PID: 1644)
      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
      • AirExplorer.exe (PID: 1960)
    • Create files in a temporary directory

      • Air.Explorer.Pro.v5.4.3.exe (PID: 3836)
      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
    • Reads the computer name

      • Air.Explorer.Pro.v5.4.3.exe (PID: 3836)
      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
      • AirExplorer.exe (PID: 1960)
    • Creates files in the program directory

      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
    • Disables trace logs

      • AirExplorer.exe (PID: 1960)
    • Creates files or folders in the user directory

      • Air.Explorer.Pro.v5.4.3.exe (PID: 1580)
    • Checks proxy server information

      • AirExplorer.exe (PID: 1960)
    • Reads the machine GUID from the registry

      • AirExplorer.exe (PID: 1960)
    • Reads Environment values

      • AirExplorer.exe (PID: 1960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: 0x0800
ZipCompression: None
ZipModifyDate: 2024:07:15 14:47:22
ZipCRC: 0x782bf04e
ZipCompressedSize: 4529510
ZipUncompressedSize: 4529510
ZipFileName: Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK/Air.Explorer.Pro.v5.4.3.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
15
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs air.explorer.pro.v5.4.3.exe no specs air.explorer.pro.v5.4.3.exe cmd.exe no specs conhost.exe no specs mode.com no specs air.explorer.pro.v5.4.3.exe no specs air.explorer.pro.v5.4.3.exe no specs air.explorer.pro.v5.4.3.exe ipconfig.exe no specs conhost.exe no specs ipconfig.exe no specs conhost.exe no specs airexplorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
8\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
640C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\INSTALL.cmd" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
904"C:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air.Explorer.Pro.v5.4.3.exe" /S /IC:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air.Explorer.Pro.v5.4.3.execmd.exe
User:
admin
Company:
airexplorer.net
Integrity Level:
MEDIUM
Description:
Air Explorer Pro v5.4.3
Exit code:
3221226540
Version:
5.4.3.0
Modules
Images
c:\users\admin\desktop\air explorer pro 5.4.3 repack ( portable) by kpojiuk\air explorer pro 5.4.3 repack ( portable) by kpojiuk\air.explorer.pro.v5.4.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1580"C:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air.Explorer.Pro.v5.4.3.exe" /S /IC:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air.Explorer.Pro.v5.4.3.exe
cmd.exe
User:
admin
Company:
airexplorer.net
Integrity Level:
HIGH
Description:
Air Explorer Pro v5.4.3
Exit code:
0
Version:
5.4.3.0
Modules
Images
c:\users\admin\desktop\air explorer pro 5.4.3 repack ( portable) by kpojiuk\air explorer pro 5.4.3 repack ( portable) by kpojiuk\air.explorer.pro.v5.4.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1644mode con:cols=100 lines=15C:\Windows\System32\mode.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
DOS Device MODE Utility
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mode.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1960"C:\Program Files\Air Explorer Pro\AirExplorer.exe"C:\Program Files\Air Explorer Pro\AirExplorer.exeAir.Explorer.Pro.v5.4.3.exe
User:
admin
Integrity Level:
HIGH
Description:
Air Explorer
Version:
5.4.3.0
Modules
Images
c:\program files\air explorer pro\airexplorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2100"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3836"C:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air.Explorer.Pro.v5.4.3.exe" C:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air.Explorer.Pro.v5.4.3.exe
explorer.exe
User:
admin
Company:
airexplorer.net
Integrity Level:
HIGH
Description:
Air Explorer Pro v5.4.3
Version:
5.4.3.0
Modules
Images
c:\users\admin\desktop\air explorer pro 5.4.3 repack ( portable) by kpojiuk\air explorer pro 5.4.3 repack ( portable) by kpojiuk\air.explorer.pro.v5.4.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4536"C:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air.Explorer.Pro.v5.4.3.exe" C:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air.Explorer.Pro.v5.4.3.exeexplorer.exe
User:
admin
Company:
airexplorer.net
Integrity Level:
MEDIUM
Description:
Air Explorer Pro v5.4.3
Exit code:
3221226540
Version:
5.4.3.0
Modules
Images
c:\users\admin\desktop\air explorer pro 5.4.3 repack ( portable) by kpojiuk\air explorer pro 5.4.3 repack ( portable) by kpojiuk\air.explorer.pro.v5.4.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4720ipconfig /flushdnsC:\Windows\SysWOW64\ipconfig.exeAir.Explorer.Pro.v5.4.3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IP Configuration Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
10 123
Read events
10 068
Write events
55
Delete events
0

Modification events

(PID) Process:(2100) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2100) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2100) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(2100) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK.zip
(PID) Process:(2100) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2100) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2100) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2100) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2100) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK
(PID) Process:(2100) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
Executable files
30
Suspicious files
3
Text files
46
Unknown types
0

Dropped files

PID
Process
Filename
Type
2100WinRAR.exeC:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\PORTABLE.cmdtext
MD5:2D8F5DA57546F6090E37E71697722BCB
SHA256:BCE1A2E6080AA96B2E00AB8893EC7D590138C7F0A89553381B64856D2CD3DA3F
2100WinRAR.exeC:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air.Explorer.Pro.v5.4.3.exeexecutable
MD5:F605FB65F91B61098DAFC46020C6EE3D
SHA256:9B39AE106B47099B4F01DE3A3DC32261D03134EDAAF6B88F7B8ECCF0F745A05D
3836Air.Explorer.Pro.v5.4.3.exeC:\Users\admin\AppData\Local\Temp\nsm615E.tmp\LangDLL.dllexecutable
MD5:109B201717AB5EF9B5628A9F3EFEF36F
SHA256:20E642707EF82852BCF153254CB94B629B93EE89A8E8A03F838EEF6CBB493319
1580Air.Explorer.Pro.v5.4.3.exeC:\Program Files\Air Explorer Pro\AWSSDK.S3.dllexecutable
MD5:A69A676B76B4820C91BA824898121E71
SHA256:EE38A8A2456B33802CF7820F4EC99FB33B95DA8A948C4E0EF4D0A8A7BA6430E0
2100WinRAR.exeC:\Users\admin\Desktop\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\Air Explorer Pro 5.4.3 RePack ( Portable) by KpoJIuK\INSTALL.cmdtext
MD5:B14ABABD52F05F633D2372BF75851624
SHA256:55BDA7BFEDE617E617B310018D07A015B7D2DB8FE6FE7EAA03092C8CD41B1258
1580Air.Explorer.Pro.v5.4.3.exeC:\Program Files\Air Explorer Pro\Microsoft.Azure.Storage.Blob.dllexecutable
MD5:8ACB5944383BF70F229AF9E231C56897
SHA256:10C0DD5583EE9149B294491000E3233E8B713DBCD294DFDBFF54C249661CD18E
1580Air.Explorer.Pro.v5.4.3.exeC:\Program Files\Air Explorer Pro\GongSolutions.WPF.DragDrop.dllexecutable
MD5:137F3735D19DD6F6599D3334B6269491
SHA256:86BD4E36D14E9B69CFAFA5ED6677986F7083ABC34A054F003502C769D5FD1A82
1580Air.Explorer.Pro.v5.4.3.exeC:\Program Files\Air Explorer Pro\BouncyCastle.Crypto.dllexecutable
MD5:5FD58D5786B83E1053CD408B54447E40
SHA256:62BEF0333E8FD3F919B4530C20DA14DB9E69DDE329303BE5109B544AA6C496D8
1580Air.Explorer.Pro.v5.4.3.exeC:\Program Files\Air Explorer Pro\ICSharpCode.SharpZipLib.dllexecutable
MD5:2F3D44DC3EE37683A467BE140B1C056B
SHA256:41AD2469AE8EA58E4C13BAAC096E89A04376C98D1B8265515D575978432D39B4
1580Air.Explorer.Pro.v5.4.3.exeC:\Program Files\Air Explorer Pro\CircularProgressBar.dllexecutable
MD5:E3E063960755CB09EFD78B5D88349E98
SHA256:49CB487E04374BB027E54DA755F79FD6A2F2E9D328C4A95E43C1DDEC71F733A2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
57
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2060
MoUsoCoreWorker.exe
GET
200
2.16.164.98:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2060
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1824
backgroundTaskHost.exe
GET
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3656
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1824
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/DigiCertGlobalRootG2.crl
unknown
whitelisted
7144
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7144
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4032
svchost.exe
239.255.255.250:1900
whitelisted
4452
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2272
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.23.209.176:443
www.bing.com
Akamai International B.V.
GB
unknown
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2060
MoUsoCoreWorker.exe
2.16.164.98:80
crl.microsoft.com
Akamai International B.V.
NL
unknown
2060
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
unknown
4656
SearchApp.exe
2.23.209.176:443
www.bing.com
Akamai International B.V.
GB
unknown
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.23.209.176
  • 2.23.209.185
  • 2.23.209.179
  • 2.23.209.177
  • 2.23.209.187
  • 2.23.209.189
  • 2.23.209.158
  • 2.23.209.160
  • 2.23.209.182
whitelisted
crl.microsoft.com
  • 2.16.164.98
  • 2.16.164.96
  • 2.16.164.33
  • 2.16.164.88
  • 2.16.164.32
  • 2.16.164.34
  • 2.16.164.16
  • 2.16.164.114
  • 2.16.164.130
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.174
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.75
  • 20.190.159.68
  • 20.190.159.73
  • 20.190.159.64
  • 20.190.159.71
  • 40.126.31.69
  • 40.126.31.67
whitelisted
go.microsoft.com
  • 23.43.62.58
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.23
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted

Threats

No threats detected
No debug info