File name:

8fb086a332482c3aed6c55627c3fe83518ee33edea32c49088e3a07afd96d8ea.msi

Full analysis: https://app.any.run/tasks/7af7e2c2-bb07-48a7-bf58-90bff11ff108
Verdict: Malicious activity
Analysis date: July 14, 2024, 09:44:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 14:06:51 2020, Security: 0, Code page: 1252, Revision Number: {0787E9E6-4C56-47D5-BA4D-02D50E26931D}, Number of Words: 2, Subject: NLD MOD CLIENT, Author: NO LIMIT TECHNOLOGY LTD, Name of Creating Application: NLD MOD CLIENT, Template: ;1033, Comments: NLD MOD CLIENT - The SAFE and EASY way to break free from DJI control and support the community!, Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Sat May 18 15:49:12 2024, Number of Pages: 200
MD5:

3681663EF89B66D58BADEC97C3AB9726

SHA1:

78C811113DF391EF1A2CF6AB967FD505D617B5CB

SHA256:

8FB086A332482C3AED6C55627C3FE83518EE33EDEA32C49088E3A07AFD96D8EA

SSDEEP:

98304:ihJ2sZ7Des+dAo10hn99CalEztkXX4Bv8xGhDwgKIfwhjIAaAkLjeCtK4MqxYqYc:LIovd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 2276)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 2276)
    • Reads the date of Windows installation

      • msiexec.exe (PID: 6184)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 6184)
      • NLDMODClient.exe (PID: 5884)
    • Application launched itself

      • adb.exe (PID: 2032)
      • adb.exe (PID: 2020)
    • Executes application which crashes

      • adb.exe (PID: 6732)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 6184)
      • msiexec.exe (PID: 2276)
      • msiexec.exe (PID: 2860)
      • AppLauncher.exe (PID: 4796)
      • NLDMODClient.exe (PID: 2180)
      • NLDMODClient.exe (PID: 5884)
      • adb.exe (PID: 2032)
      • adb.exe (PID: 2020)
      • adb.exe (PID: 6732)
      • adb.exe (PID: 3156)
      • identity_helper.exe (PID: 7504)
    • Reads Environment values

      • msiexec.exe (PID: 6184)
      • msiexec.exe (PID: 2860)
      • AppLauncher.exe (PID: 4796)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3724)
      • msiexec.exe (PID: 2276)
    • Reads the computer name

      • msiexec.exe (PID: 2276)
      • msiexec.exe (PID: 2860)
      • msiexec.exe (PID: 6184)
      • AppLauncher.exe (PID: 4796)
      • NLDMODClient.exe (PID: 2180)
      • NLDMODClient.exe (PID: 5884)
      • adb.exe (PID: 3156)
      • adb.exe (PID: 6732)
      • identity_helper.exe (PID: 7504)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 3724)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 2276)
      • WerFault.exe (PID: 7048)
    • Process checks computer location settings

      • msiexec.exe (PID: 6184)
    • Manual execution by a user

      • NLDMODClient.exe (PID: 5484)
      • NLDMODClient.exe (PID: 5884)
      • msedge.exe (PID: 1740)
    • Create files in a temporary directory

      • adb.exe (PID: 3156)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2276)
    • Reads the software policy settings

      • WerFault.exe (PID: 7048)
    • Application launched itself

      • msedge.exe (PID: 2104)
      • msedge.exe (PID: 1740)
    • Reads Microsoft Office registry keys

      • NLDMODClient.exe (PID: 5884)
      • msedge.exe (PID: 2104)
      • msedge.exe (PID: 1740)
    • Checks proxy server information

      • WerFault.exe (PID: 7048)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (81.9)
.mst | Windows SDK Setup Transform Script (9.2)
.msp | Windows Installer Patch (7.6)
.msi | Microsoft Installer (100)

EXIF

FlashPix

LastPrinted: 2009:12:11 11:47:44
ModifyDate: 2020:09:18 14:06:51
Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {0787E9E6-4C56-47D5-BA4D-02D50E26931D}
Words: 2
Subject: NLD MOD CLIENT
Author: NO LIMIT TECHNOLOGY LTD
LastModifiedBy: -
Software: NLD MOD CLIENT
Template: ;1033
Comments: NLD MOD CLIENT - The SAFE and EASY way to break free from DJI control and support the community!
Title: Installation Database
Keywords: Installer, MSI, Database
CreateDate: 2024:05:18 15:49:12
Pages: 200
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
198
Monitored processes
51
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs applauncher.exe no specs nldmodclient.exe no specs nldmodclient.exe nldmodclient.exe no specs nldmodclient.exe adb.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs adb.exe werfault.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
652\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeadb.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
652"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3516 --field-trial-handle=2424,i,14945179612629624052,16366271726488773989,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
780"C:\Program Files (x86)\NO LIMIT TECHNOLOGY LTD\NLD MOD CLIENT\NLDMODClient.exe" C:\Program Files (x86)\NO LIMIT TECHNOLOGY LTD\NLD MOD CLIENT\NLDMODClient.exemsiexec.exe
User:
admin
Company:
NO LIMIT TECHNOLOGY (CYPRUS) LTD
Integrity Level:
MEDIUM
Description:
NLD Mod Client
Exit code:
3221226540
Version:
2.6.1.2
Modules
Images
c:\program files (x86)\no limit technology ltd\nld mod client\nldmodclient.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1348\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeadb.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1740"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate --single-argument https://nolimitdronez.com/birdmap?ref=inappC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2020"C:\Users\admin\AppData\Roaming\NLT\adb.exe" devicesC:\Users\admin\AppData\Roaming\NLT\adb.exeNLDMODClient.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\nlt\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2032"C:\Users\admin\AppData\Roaming\NLT\adb.exe" devicesC:\Users\admin\AppData\Roaming\NLT\adb.exeNLDMODClient.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\roaming\nlt\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2104"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://nolimitdronez.com/birdmap?ref=inappC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeNLDMODClient.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2180"C:\Program Files (x86)\NO LIMIT TECHNOLOGY LTD\NLD MOD CLIENT\NLDMODClient.exe" C:\Program Files (x86)\NO LIMIT TECHNOLOGY LTD\NLD MOD CLIENT\NLDMODClient.exe
msiexec.exe
User:
admin
Company:
NO LIMIT TECHNOLOGY (CYPRUS) LTD
Integrity Level:
HIGH
Description:
NLD Mod Client
Version:
2.6.1.2
Modules
Images
c:\program files (x86)\no limit technology ltd\nld mod client\nldmodclient.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2276C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
20 985
Read events
20 734
Write events
236
Delete events
15

Modification events

(PID) Process:(2276) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
E40800003C8FC871D2D5DA01
(PID) Process:(2276) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
FB9406DA4B99487A6BCB87302BADA876E64EFED5CDB751B5F8BE2388806485C3
(PID) Process:(2276) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\1cfda2.rbs
Value:
31118802
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\1cfda2.rbsLow
Value:
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9AD41DA29C8BAD644A81821FB0D01E16
Operation:writeName:778fc8c71617d0c429920593da0b1d11
Value:
C:\Program Files (x86)\NO LIMIT TECHNOLOGY LTD\NLD MOD CLIENT\
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F9A94FC172E8D3F4A946DEF43F61345C
Operation:writeName:778fc8c71617d0c429920593da0b1d11
Value:
02:\Software\NO LIMIT TECHNOLOGY LTD\NLD MOD CLIENT\Version
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7371785760773B4DAF19240A2BC4F61
Operation:writeName:778fc8c71617d0c429920593da0b1d11
Value:
02:\Software\NO LIMIT TECHNOLOGY LTD\{7C930BE4-FB69-432B-AED7-21218E816A59}\AI_INSTALLPERUSER
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\95EBEE335F755DC439C946AB4A1E5E1D
Operation:writeName:778fc8c71617d0c429920593da0b1d11
Value:
C:\Program Files (x86)\NO LIMIT TECHNOLOGY LTD\NLD MOD CLIENT\NLDMODClient.exe
Executable files
30
Suspicious files
240
Text files
63
Unknown types
1

Dropped files

PID
Process
Filename
Type
2276msiexec.exeC:\WINDOWS\Installer\1cfda1.msi
MD5:
SHA256:
3724msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIF028.tmpexecutable
MD5:AD6FAED544D1F3B892268E4B47425736
SHA256:759936D197E6098BE606432002B78067C3FEB2DBC294F5776B1C8C3A38314F0B
3724msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIFCCF.tmpexecutable
MD5:AD6FAED544D1F3B892268E4B47425736
SHA256:759936D197E6098BE606432002B78067C3FEB2DBC294F5776B1C8C3A38314F0B
3724msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIEE20.tmpexecutable
MD5:AD6FAED544D1F3B892268E4B47425736
SHA256:759936D197E6098BE606432002B78067C3FEB2DBC294F5776B1C8C3A38314F0B
3724msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIFCF0.tmpexecutable
MD5:AD6FAED544D1F3B892268E4B47425736
SHA256:759936D197E6098BE606432002B78067C3FEB2DBC294F5776B1C8C3A38314F0B
3724msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIF136.tmpexecutable
MD5:AD6FAED544D1F3B892268E4B47425736
SHA256:759936D197E6098BE606432002B78067C3FEB2DBC294F5776B1C8C3A38314F0B
3724msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIF0E5.tmpexecutable
MD5:A43940E45269855A510FBCB4B40A9B21
SHA256:4FF4B41A9550EDBA51E5AEA398538D43C782B1338EAF9866423213A4A8558695
3724msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIF115.tmpexecutable
MD5:AD6FAED544D1F3B892268E4B47425736
SHA256:759936D197E6098BE606432002B78067C3FEB2DBC294F5776B1C8C3A38314F0B
2276msiexec.exeC:\WINDOWS\Installer\MSI41.tmpexecutable
MD5:AD6FAED544D1F3B892268E4B47425736
SHA256:759936D197E6098BE606432002B78067C3FEB2DBC294F5776B1C8C3A38314F0B
2276msiexec.exeC:\WINDOWS\Installer\MSI1AC.tmpbinary
MD5:01F8CCA3A61C3C51DA367B99641422E3
SHA256:517E5A2D8FC773A09C1F95388ECCA0E9E391B149221F2EC0184B27B36CB4EBCA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
129
DNS requests
69
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
314 b
whitelisted
3652
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
5884
NLDMODClient.exe
GET
200
85.184.166.133:80
http://abcdefghijklmnopqrstuvwxyxzabcdefghijklmnopqrstuvwxyzabcdefghij.com/NLDAppUpdate.json
DK
binary
469 b
unknown
2180
NLDMODClient.exe
GET
200
85.184.166.133:80
http://abcdefghijklmnopqrstuvwxyxzabcdefghijklmnopqrstuvwxyzabcdefghij.com/scrolltxt.txt
DK
text
563 b
unknown
5884
NLDMODClient.exe
POST
200
85.184.166.133:80
http://abcdefghijklmnopqrstuvwxyxzabcdefghijklmnopqrstuvwxyzabcdefghij.com/
DK
binary
1.03 Kb
unknown
5884
NLDMODClient.exe
GET
200
85.184.166.133:80
http://abcdefghijklmnopqrstuvwxyxzabcdefghijklmnopqrstuvwxyzabcdefghij.com/scrolltxt.txt
DK
text
563 b
unknown
5884
NLDMODClient.exe
POST
200
85.184.166.133:80
http://abcdefghijklmnopqrstuvwxyxzabcdefghijklmnopqrstuvwxyzabcdefghij.com/
DK
text
14.0 Kb
unknown
2180
NLDMODClient.exe
POST
200
85.184.166.133:80
http://abcdefghijklmnopqrstuvwxyxzabcdefghijklmnopqrstuvwxyzabcdefghij.com/
DK
text
14.0 Kb
unknown
2064
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
7048
WerFault.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.23.209.150:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
4656
SearchApp.exe
2.23.209.150:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4
System
192.168.100.255:138
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3652
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3652
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4656
SearchApp.exe
2.23.209.149:443
www.bing.com
Akamai International B.V.
GB
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 40.127.240.158
  • 20.73.194.208
whitelisted
www.bing.com
  • 2.23.209.150
  • 2.23.209.149
  • 2.23.209.176
  • 2.23.209.177
  • 2.23.209.158
  • 2.23.209.182
  • 2.23.209.179
  • 2.23.209.181
  • 2.23.209.160
  • 104.126.37.137
  • 104.126.37.130
  • 104.126.37.139
  • 104.126.37.128
  • 104.126.37.186
  • 104.126.37.131
  • 104.126.37.153
  • 104.126.37.129
  • 104.126.37.145
whitelisted
google.com
  • 216.58.206.46
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.76
  • 40.126.32.72
  • 40.126.32.138
  • 20.190.160.20
  • 40.126.32.134
  • 20.190.160.17
  • 20.190.160.14
  • 40.126.32.74
whitelisted
go.microsoft.com
  • 2.19.105.250
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.31
whitelisted
abcdefghijklmnopqrstuvwxyxzabcdefghijklmnopqrstuvwxyzabcdefghij.com
  • 85.184.166.133
unknown
ping.nolimitdronez.com
  • 85.184.166.133
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted

Threats

No threats detected
No debug info