File name:

Silverlight_x64 (cnet).exe

Full analysis: https://app.any.run/tasks/8f7ee76e-4e80-4373-8076-4bbf6fc3aa0b
Verdict: Malicious activity
Analysis date: July 22, 2024, 14:09:34
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4DDE36BF591D7AA0B05497AFD40AC2CC

SHA1:

AD8DB31020463E825C0B620D93477B5321C072D8

SHA256:

8D263A6F42A378073B6F057F242A42076F9F4082340153C2E27ECC959C5036AA

SSDEEP:

393216:YwpygvheTgJ/+wP8Ut8ufz/XaAuJdWFJ3+bl:Jsgv4w8U6U/KNzWqbl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Silverlight_x64 (cnet).exe (PID: 1920)
      • coregen.exe (PID: 3648)
      • coregen.exe (PID: 7208)
      • coregen.exe (PID: 7720)
      • coregen.exe (PID: 7600)
      • coregen.exe (PID: 5300)
      • coregen.exe (PID: 7616)
      • coregen.exe (PID: 7996)
      • msiexec.exe (PID: 4156)
      • coregen.exe (PID: 620)
      • coregen.exe (PID: 6932)
      • coregen.exe (PID: 7304)
      • coregen.exe (PID: 908)
      • coregen.exe (PID: 1292)
      • coregen.exe (PID: 7036)
      • coregen.exe (PID: 3444)
      • coregen.exe (PID: 2360)
      • coregen.exe (PID: 6356)
      • coregen.exe (PID: 7324)
      • coregen.exe (PID: 5848)
      • coregen.exe (PID: 2356)
      • coregen.exe (PID: 6148)
      • coregen.exe (PID: 5308)
      • coregen.exe (PID: 7596)
      • coregen.exe (PID: 5156)
      • coregen.exe (PID: 6524)
      • coregen.exe (PID: 8012)
      • coregen.exe (PID: 5720)
      • coregen.exe (PID: 5984)
      • coregen.exe (PID: 7432)
      • coregen.exe (PID: 8036)
      • coregen.exe (PID: 2344)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Silverlight_x64 (cnet).exe (PID: 1920)
      • msiexec.exe (PID: 4156)
      • coregen.exe (PID: 3648)
      • coregen.exe (PID: 7208)
      • coregen.exe (PID: 7720)
      • coregen.exe (PID: 7600)
      • coregen.exe (PID: 5300)
      • coregen.exe (PID: 7616)
      • coregen.exe (PID: 7996)
      • coregen.exe (PID: 7036)
      • coregen.exe (PID: 2360)
      • coregen.exe (PID: 3444)
      • coregen.exe (PID: 6356)
      • coregen.exe (PID: 7324)
      • coregen.exe (PID: 5848)
      • coregen.exe (PID: 2356)
      • coregen.exe (PID: 6148)
      • coregen.exe (PID: 7596)
      • coregen.exe (PID: 5984)
      • coregen.exe (PID: 7432)
      • coregen.exe (PID: 8036)
      • coregen.exe (PID: 2344)
    • Executable content was dropped or overwritten

      • Silverlight_x64 (cnet).exe (PID: 1920)
      • coregen.exe (PID: 3648)
      • coregen.exe (PID: 7720)
      • coregen.exe (PID: 7600)
      • coregen.exe (PID: 7208)
      • coregen.exe (PID: 5300)
      • coregen.exe (PID: 7996)
      • coregen.exe (PID: 7616)
      • coregen.exe (PID: 620)
      • coregen.exe (PID: 7304)
      • coregen.exe (PID: 6932)
      • coregen.exe (PID: 908)
      • coregen.exe (PID: 1292)
      • coregen.exe (PID: 3444)
      • coregen.exe (PID: 7036)
      • coregen.exe (PID: 2360)
      • coregen.exe (PID: 6356)
      • coregen.exe (PID: 7324)
      • coregen.exe (PID: 5848)
      • coregen.exe (PID: 2356)
      • coregen.exe (PID: 7596)
      • coregen.exe (PID: 2344)
      • coregen.exe (PID: 5308)
      • coregen.exe (PID: 5156)
      • coregen.exe (PID: 6524)
      • coregen.exe (PID: 8012)
      • coregen.exe (PID: 5720)
      • coregen.exe (PID: 5984)
      • coregen.exe (PID: 7432)
      • coregen.exe (PID: 8036)
      • coregen.exe (PID: 6148)
    • Starts a Microsoft application from unusual location

      • Silverlight_x64 (cnet).exe (PID: 1920)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 4156)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 4156)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 4156)
    • Changes Internet Explorer settings (feature browser emulation)

      • msiexec.exe (PID: 4156)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 4156)
    • Reads security settings of Internet Explorer

      • install.exe (PID: 7604)
    • Reads the date of Windows installation

      • install.exe (PID: 7604)
    • Uses RUNDLL32.EXE to load library

      • install.exe (PID: 7604)
  • INFO

    • Reads the computer name

      • Silverlight_x64 (cnet).exe (PID: 1920)
      • install.exe (PID: 7604)
      • msiexec.exe (PID: 4156)
      • msiexec.exe (PID: 5748)
      • msiexec.exe (PID: 7816)
    • Reads the machine GUID from the registry

      • Silverlight_x64 (cnet).exe (PID: 1920)
      • msiexec.exe (PID: 4156)
      • coregen.exe (PID: 3648)
      • coregen.exe (PID: 7208)
      • coregen.exe (PID: 7720)
      • coregen.exe (PID: 7600)
      • coregen.exe (PID: 5300)
      • coregen.exe (PID: 7616)
      • coregen.exe (PID: 7996)
      • coregen.exe (PID: 620)
      • coregen.exe (PID: 6932)
      • coregen.exe (PID: 7304)
      • coregen.exe (PID: 908)
      • coregen.exe (PID: 1292)
      • coregen.exe (PID: 3444)
      • coregen.exe (PID: 2360)
      • coregen.exe (PID: 7036)
      • coregen.exe (PID: 5984)
    • Checks supported languages

      • install.exe (PID: 7604)
      • Silverlight_x64 (cnet).exe (PID: 1920)
      • msiexec.exe (PID: 4156)
      • MSIBD08.tmp (PID: 7912)
      • MSIBCF8.tmp (PID: 3020)
      • msiexec.exe (PID: 5748)
      • coregen.exe (PID: 3648)
      • coregen.exe (PID: 7208)
      • msiexec.exe (PID: 7816)
      • coregen.exe (PID: 7600)
      • coregen.exe (PID: 5300)
      • coregen.exe (PID: 7720)
      • coregen.exe (PID: 7616)
      • coregen.exe (PID: 7996)
      • coregen.exe (PID: 620)
      • coregen.exe (PID: 6932)
      • coregen.exe (PID: 7304)
      • coregen.exe (PID: 1292)
      • coregen.exe (PID: 908)
      • coregen.exe (PID: 2360)
      • coregen.exe (PID: 7036)
      • coregen.exe (PID: 3444)
      • coregen.exe (PID: 6356)
      • coregen.exe (PID: 5848)
      • coregen.exe (PID: 7324)
      • coregen.exe (PID: 2356)
      • coregen.exe (PID: 6148)
      • coregen.exe (PID: 2344)
      • coregen.exe (PID: 7596)
      • coregen.exe (PID: 5156)
      • coregen.exe (PID: 5308)
      • coregen.exe (PID: 6524)
      • coregen.exe (PID: 8012)
      • coregen.exe (PID: 5720)
      • coregen.exe (PID: 5984)
      • coregen.exe (PID: 7432)
      • coregen.exe (PID: 8036)
    • Create files in a temporary directory

      • install.exe (PID: 7604)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 4156)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 4156)
    • Reads the software policy settings

      • msiexec.exe (PID: 4156)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 4156)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 4156)
    • Process checks computer location settings

      • install.exe (PID: 7604)
    • Creates files in the program directory

      • coregen.exe (PID: 3648)
      • coregen.exe (PID: 7208)
      • coregen.exe (PID: 7720)
      • coregen.exe (PID: 7600)
      • coregen.exe (PID: 5300)
      • coregen.exe (PID: 7616)
      • coregen.exe (PID: 7996)
      • coregen.exe (PID: 620)
      • coregen.exe (PID: 6932)
      • coregen.exe (PID: 7304)
      • coregen.exe (PID: 908)
      • coregen.exe (PID: 1292)
      • coregen.exe (PID: 2360)
      • coregen.exe (PID: 7036)
      • coregen.exe (PID: 3444)
      • coregen.exe (PID: 6356)
      • coregen.exe (PID: 7324)
      • coregen.exe (PID: 2356)
      • coregen.exe (PID: 6148)
      • coregen.exe (PID: 2344)
      • coregen.exe (PID: 5848)
      • coregen.exe (PID: 7596)
      • coregen.exe (PID: 5308)
      • coregen.exe (PID: 5156)
      • coregen.exe (PID: 6524)
      • coregen.exe (PID: 8012)
      • coregen.exe (PID: 5720)
      • coregen.exe (PID: 5984)
      • coregen.exe (PID: 7432)
      • coregen.exe (PID: 8036)
    • Application launched itself

      • msiexec.exe (PID: 4156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2004:06:25 00:14:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 7.1
CodeSize: 30720
InitializedDataSize: 3072
UninitializedDataSize: -
EntryPoint: 0x5892
OSVersion: 5.2
ImageVersion: 5.2
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.1.50907.0
ProductVersionNumber: 5.5.31.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Self-Extracting Cabinet
FileVersion: 5.1.50907.0
InternalName: SFXCAB.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: SFXCAB.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.5.0031.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
210
Monitored processes
73
Malicious processes
3
Suspicious processes
5

Behavior graph

Click at the process to see the details
start silverlight_x64 (cnet).exe install.exe no specs install.exe msiexec.exe msibcf8.tmp no specs msibd08.tmp no specs slui.exe no specs msiexec.exe no specs msiexec.exe no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs coregen.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
620"C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\coregen.exe" Microsoft.Xna.Framework.dllC:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.50907.0 built by: SL_V5_SVC
Modules
Images
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
908"C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\coregen.exe" System.Windows.dllC:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.50907.0 built by: SL_V5_SVC
Modules
Images
c:\windows\syswow64\imagehlp.dll
1292"C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\coregen.exe" System.Windows.Xna.dllC:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.50907.0 built by: SL_V5_SVC
1300\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execoregen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
1792\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execoregen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
1832\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execoregen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
1920"C:\Users\admin\AppData\Local\Temp\Silverlight_x64 (cnet).exe" C:\Users\admin\AppData\Local\Temp\Silverlight_x64 (cnet).exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Self-Extracting Cabinet
Version:
5.1.50907.0
Modules
Images
c:\users\admin\appdata\local\temp\silverlight_x64 (cnet).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2344"C:\Program Files\Microsoft Silverlight\5.1.50907.0\coregen.exe" System.Runtime.Serialization.dllC:\Program Files\Microsoft Silverlight\5.1.50907.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.50907.0 built by: SL_V5_SVC
2356"C:\Program Files\Microsoft Silverlight\5.1.50907.0\coregen.exe" System.Net.dllC:\Program Files\Microsoft Silverlight\5.1.50907.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.50907.0 built by: SL_V5_SVC
2360"C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\coregen.exe" System.ServiceModel.dllC:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.50907.0 built by: SL_V5_SVC
Modules
Images
c:\program files (x86)\microsoft silverlight\5.1.50907.0\coregen.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\aclayers.dll
c:\windows\syswow64\msvcrt.dll
Total events
17 411
Read events
12 858
Write events
4 526
Delete events
27

Modification events

(PID) Process:(4156) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
3C1000007E171BD040DCDA01
(PID) Process:(4156) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
5CED114879383F822D16DEFF7E7E892601F51BDABF196A2F425C45915D90CEDB
(PID) Process:(4156) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(4156) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:c:\Config.Msi\
Value:
(PID) Process:(4156) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:c:\Config.Msi\42b23a.rbs
Value:
31120448
(PID) Process:(4156) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:c:\Config.Msi\42b23a.rbsLow
Value:
(PID) Process:(4156) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9274B1F3DD752DD46B78DE222629060E
Operation:writeName:D7314F9862C648A4DB8BE2A5B47BE100
Value:
02:\SOFTWARE\Microsoft\Silverlight\Version
(PID) Process:(4156) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3423D96D489FA0A4AB1A4EE3658C0DA6
Operation:writeName:D7314F9862C648A4DB8BE2A5B47BE100
Value:
22:\SOFTWARE\Microsoft\Silverlight\Version
(PID) Process:(4156) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Silverlight
Operation:writeName:Version
Value:
1.0.0.0
(PID) Process:(4156) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Silverlight
Operation:writeName:Version
Value:
1.0.0.0
Executable files
416
Suspicious files
27
Text files
6
Unknown types
9

Dropped files

PID
Process
Filename
Type
1920Silverlight_x64 (cnet).exeC:\6479fcd657d32e7a027c384449\silverlight.7z
MD5:
SHA256:
4156msiexec.exeC:\WINDOWS\Installer\42b238.msiexecutable
MD5:185CAE55DB77C41AE96DAB78C7CBAF6A
SHA256:5D21C6124570646C38FC537CCC96BED0DEE290F3BBCDF6069EEB30337AE083E4
1920Silverlight_x64 (cnet).exeC:\6479fcd657d32e7a027c384449\install.res.dllexecutable
MD5:6A1BB0FA3A7EE1D0ED1291CB168E38F2
SHA256:A7A5283F564A2108A24F6180AAE90D3800F7D49872A284C2AC9F8DAA15BD33DF
4156msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:FB64A9EBEDF48D3895381D5B7D80743D
SHA256:EA21D495930AD76F267A33A0F593DBF0C7EA75E457FCAE49A29DAAD8BD920F42
1920Silverlight_x64 (cnet).exeC:\6479fcd657d32e7a027c384449\microsoft_defaults.exeexecutable
MD5:64CADAEF6DCF7B6A6171FC1A2BEE94A1
SHA256:5720BD8E18456D0B96CD4BDBB715C2217A1EE30609DD05C195895874105A557C
4156msiexec.exeC:\WINDOWS\Installer\42b23b.msiexecutable
MD5:185CAE55DB77C41AE96DAB78C7CBAF6A
SHA256:5D21C6124570646C38FC537CCC96BED0DEE290F3BBCDF6069EEB30337AE083E4
1920Silverlight_x64 (cnet).exeC:\6479fcd657d32e7a027c384449\install.exeexecutable
MD5:DF0D5D37C2A2225148579486FA7043B7
SHA256:963F37570FEE71BD9E86F592F86C898729446E2D18FA1F08D236B3F9CC4D31F3
4156msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C0018BB1B5834735BFA60CD063B31956binary
MD5:FC1193C6345AC35188AA3DE0F824CEB7
SHA256:BDFB8FAFF4C0C0A15C642890A5544BD32F930F55CA199470DBD4736A32D6E200
1920Silverlight_x64 (cnet).exeC:\6479fcd657d32e7a027c384449\silverlight.msiexecutable
MD5:185CAE55DB77C41AE96DAB78C7CBAF6A
SHA256:5D21C6124570646C38FC537CCC96BED0DEE290F3BBCDF6069EEB30337AE083E4
4156msiexec.exeC:\WINDOWS\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIconimage
MD5:CDD148269B61A4A225E9C6CDDA3D3283
SHA256:95B4CAF370F18E73FB13E5B155A6A70A7E2CB72E9681B7DD8963C613D5BF6B3F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
32
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4156
msiexec.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4716
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
whitelisted
5620
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7856
svchost.exe
4.209.32.198:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
2760
svchost.exe
40.113.103.199:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4156
msiexec.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
unknown
3552
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4716
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.159.68
  • 20.190.159.0
  • 20.190.159.75
  • 40.126.31.69
  • 20.190.159.2
  • 20.190.159.71
  • 20.190.159.73
  • 40.126.31.67
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 172.217.18.14
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
www.bing.com
  • 2.23.209.192
  • 2.23.209.191
  • 2.23.209.136
  • 2.23.209.186
  • 2.23.209.188
  • 2.23.209.189
  • 2.23.209.135
  • 2.23.209.133
  • 2.23.209.130
whitelisted
licensing.mp.microsoft.com
  • 4.209.32.67
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
No debug info