File name:

SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531

Full analysis: https://app.any.run/tasks/ad064859-633e-484a-9be9-72fa3f42a24c
Verdict: Malicious activity
Analysis date: November 04, 2024, 00:50:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

F164888A6FBC646B093F6AF6663F4E63

SHA1:

3C0BB9F9A4AD9B1C521AD9FC30EC03668577C97C

SHA256:

8C5A3597666F418B5C857E68C9A13B7B6D037EA08A988204B572F053450ADD67

SSDEEP:

98304:R/TvjMleJaJ4kJQeSWSeWdzPSkAdsC5pqNP+/YTXjM/cIcSoIov1UXuykZyzZ2Cg:mriEcSB6mCsb5x

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 6704)
      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
    • Reads the date of Windows installation

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 6704)
      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
    • Application launched itself

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 6704)
    • The process creates files with name similar to system file names

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 1804)
      • regsvr32.exe (PID: 7100)
    • Executable content was dropped or overwritten

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
    • Process drops legitimate windows executable

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
    • Creates a software uninstall entry

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
    • Starts SC.EXE for service management

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
    • The process executes via Task Scheduler

      • explorer.exe (PID: 5788)
  • INFO

    • Checks supported languages

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 6704)
      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
    • Process checks computer location settings

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 6704)
      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
    • Reads the computer name

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 6704)
      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
    • The process uses the downloaded file

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 6704)
      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
    • Creates files in the program directory

      • SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe (PID: 5196)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:11:02 13:43:18+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.41
CodeSize: 151552
InitializedDataSize: 10995712
UninitializedDataSize: -
EntryPoint: 0x8c18
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 22621.4317.67.1
ProductVersionNumber: 22621.4317.67.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: ExplorerPatcher Developers
FileDescription: ExplorerPatcher Setup Program
FileVersion: 22621.4317.67.1
InternalName: ep_setup.exe
LegalCopyright: (C) 2021-2024 ExplorerPatcher Developers. All rights reserved.
OriginalFileName: ep_setup.exe
ProductName: ExplorerPatcher
ProductVersion: 22621.4317.67.1
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
15
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start securiteinfo.com.win64.riskware.explorerpatcher.b.21185.8531.exe no specs securiteinfo.com.win64.riskware.explorerpatcher.b.21185.8531.exe sc.exe no specs conhost.exe no specs regsvr32.exe no specs regsvr32.exe no specs explorer.exe no specs explorer.exe no specs startmenuexperiencehost.exe no specs textinputhost.exe no specs searchapp.exe no specs mobsync.exe no specs sppextcomobj.exe no specs slui.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1196"C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mcaC:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Search application
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ntmarta.dll
1712"C:\WINDOWS\explorer.exe" C:\Windows\explorer.exeSecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
2
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
1804"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\ExplorerPatcher\ep_weather_host.dll"C:\Windows\System32\regsvr32.exeSecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2432\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4176"C:\WINDOWS\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe" -ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mcaC:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\windows\systemapps\microsoft.windows.startmenuexperiencehost_cw5n1h2txyewy\startmenuexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wincorlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
4508C:\WINDOWS\System32\mobsync.exe -EmbeddingC:\Windows\System32\mobsync.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Sync Center
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mobsync.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5008"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
123.26505.0.0
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
5196"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe" C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe
SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe
User:
admin
Company:
ExplorerPatcher Developers
Integrity Level:
HIGH
Description:
ExplorerPatcher Setup Program
Exit code:
0
Version:
22621.4317.67.1
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.win64.riskware.explorerpatcher.b.21185.8531.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5788"C:\WINDOWS\explorer.exe" /NoUACCheckC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shcore.dll
6704"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exe" C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeexplorer.exe
User:
admin
Company:
ExplorerPatcher Developers
Integrity Level:
MEDIUM
Description:
ExplorerPatcher Setup Program
Exit code:
0
Version:
22621.4317.67.1
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.win64.riskware.explorerpatcher.b.21185.8531.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
28 105
Read events
27 791
Write events
287
Delete events
27

Modification events

(PID) Process:(5196) SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher
Operation:writeName:UninstallString
Value:
"C:\Program Files\ExplorerPatcher\ep_setup.exe" /uninstall
(PID) Process:(5196) SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher
Operation:writeName:DisplayName
Value:
ExplorerPatcher
(PID) Process:(5196) SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher
Operation:writeName:Publisher
Value:
VALINET Solutions SRL
(PID) Process:(5196) SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher
Operation:writeName:NoModify
Value:
1
(PID) Process:(5196) SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher
Operation:writeName:NoRepair
Value:
1
(PID) Process:(5196) SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher
Operation:writeName:DisplayVersion
Value:
22621.4317.67.1
(PID) Process:(5196) SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher
Operation:writeName:VersionMajor
Value:
67
(PID) Process:(5196) SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher
Operation:writeName:VersionMinor
Value:
1
(PID) Process:(5196) SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher
Operation:writeName:DisplayIcon
Value:
C:\WINDOWS\explorer.exe
(PID) Process:(1804) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6EA9C2D-4982-4827-9204-0AC532959F6D}
Operation:writeName:AppID
Value:
{A6EA9C2D-4982-4827-9204-0AC532959F6D}
Executable files
14
Suspicious files
135
Text files
131
Unknown types
0

Dropped files

PID
Process
Filename
Type
1196SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133751550469182186.txt~RF8d589.TMP
MD5:
SHA256:
5196SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeC:\Program Files\ExplorerPatcher\ep_dwm.exeexecutable
MD5:6563C5338177FF66050EADFE3960C567
SHA256:315AF6DF079B31BAC26156C9DDA8CC415C76408A39972346C238888AAFF79921
5196SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeC:\Windows\dxgi.dllexecutable
MD5:047B192A9C703FC5A2C2764DB869FF5C
SHA256:1971C57F88849B4069BE06D3784E0968755C916FA1564A3F8F05610D3B02CDCC
5196SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\ExplorerPatcher\Properties (ExplorerPatcher).lnkbinary
MD5:A1721A2AEE430EC8C5E6C862C50CAB4F
SHA256:DF67CD17EFF7115ADC3EC14F8A1D31B578E45CFE2752D84C7D5E8977455D47AC
5196SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeC:\Program Files\ExplorerPatcher\ExplorerPatcher.IA-32.dllexecutable
MD5:E5BB14C2B9AF4D5BF6C38E0759F454DD
SHA256:A4FD75AC8F852EDC8BDB88A705EEEE2C93F6EC51EF9FA0739A11A690A067C66D
5196SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeC:\Program Files\ExplorerPatcher\ep_setup.exeexecutable
MD5:F164888A6FBC646B093F6AF6663F4E63
SHA256:8C5A3597666F418B5C857E68C9A13B7B6D037EA08A988204B572F053450ADD67
1196SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133751550469182186.txttext
MD5:EBA9D627AEFA0148EA256382E454768F
SHA256:85F02886D53B7427792E54BCEE97D366AD46F78CF90AA25DCC3FAE29ED7FA7F8
1196SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133751550469182186.txt.~tmptext
MD5:EBA9D627AEFA0148EA256382E454768F
SHA256:85F02886D53B7427792E54BCEE97D366AD46F78CF90AA25DCC3FAE29ED7FA7F8
1196SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Cache\fbaf94e759052658216786bfbabcdced1b67a5c2.tbresbinary
MD5:74CB2B2BFB2DF7FC23ED7E3C93094B7B
SHA256:AFC619D4CA3ABD91408EB766EC33BD1C51F9F0C829EAC26BA99C241F36E4E62C
5196SecuriteInfo.com.Win64.Riskware.ExplorerPatcher.B.21185.8531.exeC:\Program Files\ExplorerPatcher\ep_gui.dllexecutable
MD5:81CD6D96F81B1E54AA327A4AF6BCBE85
SHA256:B23BAB1F5DC85C9E10145EEB32214D6CFE02FB5ABCF956A37A3C9DD7E09FEE67
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
56
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
GET
302
204.79.197.219:80
http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/3F0945AE4BC25ECE16353588B05D30B61/twinui.pcshell.pdb
unknown
whitelisted
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEE4o94a2bBo7lCzSxA63QqU%3D
unknown
whitelisted
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D
unknown
whitelisted
GET
302
204.79.197.219:80
http://msdl.microsoft.com/download/symbols/StartUI.pdb/0B81EEDEEB6FF49A7EC7F23C15C216771/StartUI.pdb
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.23.209.187:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 20.73.194.208
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.23.209.187
  • 2.23.209.149
  • 2.23.209.182
  • 2.23.209.133
  • 2.23.209.130
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.72
  • 20.190.160.22
  • 20.190.160.20
  • 40.126.32.138
  • 20.190.160.17
  • 40.126.32.140
  • 40.126.32.76
whitelisted
r.bing.com
  • 2.23.209.130
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.182
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
github.com
  • 140.82.121.3
shared

Threats

No threats detected
No debug info