File name:

ace-video-converter.exe

Full analysis: https://app.any.run/tasks/a7489d7f-5eb1-47dc-99c2-d4eb86f1f090
Verdict: Malicious activity
Analysis date: April 23, 2025, 02:38:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

C65553D09A6195F56E4AA776C45CCFD2

SHA1:

C32A369494F69DDBDB0A39EEEAE0CB49FF8F1E08

SHA256:

902C9F27A9AAA02FDE8CD10C02A198932E09A939A5EDBDC0B30DE537990B9982

SSDEEP:

196608:vTBx9ljzjy2w8jREfclHZhnPPaj9ZmQSAwBvKH:7BDNXVw8dE0BPPanmrKH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • ace-video-converter.exe (PID: 1188)
      • ace-video-converter.exe (PID: 3240)
      • Ace Video Converter.exe (PID: 3192)
    • Registers / Runs the DLL via REGSVR32.EXE

      • ace-video-converter.tmp (PID: 5972)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ace-video-converter.exe (PID: 1188)
      • ace-video-converter.exe (PID: 3240)
      • ace-video-converter.tmp (PID: 5972)
    • Reads security settings of Internet Explorer

      • ace-video-converter.tmp (PID: 6388)
      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
    • There is functionality for taking screenshot (YARA)

      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
    • Reads the Windows owner or organization settings

      • ace-video-converter.tmp (PID: 5972)
    • Process drops legitimate windows executable

      • ace-video-converter.tmp (PID: 5972)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 4040)
      • regsvr32.exe (PID: 7148)
      • regsvr32.exe (PID: 5776)
      • regsvr32.exe (PID: 3008)
      • regsvr32.exe (PID: 3300)
      • regsvr32.exe (PID: 2852)
  • INFO

    • Reads the computer name

      • ace-video-converter.tmp (PID: 6388)
      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
    • Create files in a temporary directory

      • ace-video-converter.exe (PID: 1188)
      • ace-video-converter.exe (PID: 3240)
      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
    • Checks supported languages

      • ace-video-converter.tmp (PID: 6388)
      • ace-video-converter.exe (PID: 1188)
      • ace-video-converter.exe (PID: 3240)
      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
    • Process checks computer location settings

      • ace-video-converter.tmp (PID: 6388)
    • Compiled with Borland Delphi (YARA)

      • ace-video-converter.tmp (PID: 6388)
      • ace-video-converter.tmp (PID: 5972)
      • ace-video-converter.exe (PID: 3240)
      • ace-video-converter.exe (PID: 1188)
    • Detects InnoSetup installer (YARA)

      • ace-video-converter.tmp (PID: 6388)
      • ace-video-converter.exe (PID: 3240)
      • ace-video-converter.tmp (PID: 5972)
      • ace-video-converter.exe (PID: 1188)
    • The sample compiled with english language support

      • ace-video-converter.tmp (PID: 5972)
    • Checks proxy server information

      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
      • slui.exe (PID: 896)
    • Reads mouse settings

      • regsvr32.exe (PID: 7148)
      • Ace Video Converter.exe (PID: 3192)
    • Creates a software uninstall entry

      • ace-video-converter.tmp (PID: 5972)
    • Reads the machine GUID from the registry

      • Ace Video Converter.exe (PID: 3192)
    • Creates files in the program directory

      • ace-video-converter.tmp (PID: 5972)
    • Reads the software policy settings

      • slui.exe (PID: 896)
      • Ace Video Converter.exe (PID: 3192)
    • Creates files or folders in the user directory

      • Ace Video Converter.exe (PID: 3192)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (42.6)
.exe | Win16/32 Executable Delphi generic (19.5)
.exe | Generic Win/DOS Executable (18.9)
.exe | DOS Executable Generic (18.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:01:30 14:21:56+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 3.8.0.0
ProductVersionNumber: 3.8.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: XetoWare
FileDescription: Ace Video Converter Setup
FileVersion: 3.8
LegalCopyright: © 2014 XetoWare
ProductName: Ace Video Converter
ProductVersion: 3.8
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
23
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
start ace-video-converter.exe ace-video-converter.tmp no specs ace-video-converter.exe ace-video-converter.tmp regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs ace video converter.exe rundll32.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
896C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
920C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1040"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\OLEPRO32.DLL"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1188"C:\Users\admin\AppData\Local\Temp\ace-video-converter.exe" C:\Users\admin\AppData\Local\Temp\ace-video-converter.exe
explorer.exe
User:
admin
Company:
XetoWare
Integrity Level:
MEDIUM
Description:
Ace Video Converter Setup
Exit code:
0
Version:
3.8
Modules
Images
c:\users\admin\appdata\local\temp\ace-video-converter.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1240"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\scrrun.dll"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1324"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\ASYCFILT.DLL"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
4
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2420"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msimg32.dll"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
4
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2852"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\COMDLG32.OCX"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3008"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msvbvm60.dll"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3192"C:\Program Files (x86)\XetoWare\Ace Video Converter\Ace Video Converter.EXE"C:\Program Files (x86)\XetoWare\Ace Video Converter\Ace Video Converter.exe
ace-video-converter.tmp
User:
admin
Company:
XetoWare
Integrity Level:
MEDIUM
Description:
Ace Video Converter
Version:
3.08
Modules
Images
c:\program files (x86)\xetoware\ace video converter\ace video converter.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
3 450
Read events
2 995
Write events
333
Delete events
122

Modification events

(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}
Operation:delete keyName:(default)
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0713E8A8-850A-101B-AFC0-4210102A8DA7}
Operation:delete keyName:(default)
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0713E8A8-850A-101B-AFC0-4210102A8DA7}\InprocServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}
Operation:delete keyName:(default)
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}
Operation:delete keyName:(default)
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B66834C6-2E60-11CE-8748-524153480004}\InprocServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{612A8624-0FB3-11CE-8747-524153480004}
Operation:delete keyName:(default)
Value:
Executable files
35
Suspicious files
13
Text files
162
Unknown types
0

Dropped files

PID
Process
Filename
Type
1188ace-video-converter.exeC:\Users\admin\AppData\Local\Temp\is-QP3MM.tmp\ace-video-converter.tmpexecutable
MD5:D7FD24094728B56012F16AE8AFED07B7
SHA256:B3B9FE1F1EC947568413023534D15C811E0320C63A2B273F6F291ADCDD5C530D
5972ace-video-converter.tmpC:\Program Files (x86)\XetoWare\Ace Video Converter\unins000.exeexecutable
MD5:D7FD24094728B56012F16AE8AFED07B7
SHA256:B3B9FE1F1EC947568413023534D15C811E0320C63A2B273F6F291ADCDD5C530D
5972ace-video-converter.tmpC:\Program Files (x86)\XetoWare\Ace Video Converter\Ace Video Converter.exeexecutable
MD5:0EAF3E150D0D58875D872A6832ABF724
SHA256:1BD55C8C1F44E971843A7F38796CC69C6FEC34E65EB0818E51568A770FC92A31
5972ace-video-converter.tmpC:\Users\admin\AppData\Local\Temp\is-6J4K1.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3240ace-video-converter.exeC:\Users\admin\AppData\Local\Temp\is-UBR1K.tmp\ace-video-converter.tmpexecutable
MD5:D7FD24094728B56012F16AE8AFED07B7
SHA256:B3B9FE1F1EC947568413023534D15C811E0320C63A2B273F6F291ADCDD5C530D
5972ace-video-converter.tmpC:\Program Files (x86)\XetoWare\Ace Video Converter\is-622V5.tmpexecutable
MD5:D7FD24094728B56012F16AE8AFED07B7
SHA256:B3B9FE1F1EC947568413023534D15C811E0320C63A2B273F6F291ADCDD5C530D
5972ace-video-converter.tmpC:\Program Files (x86)\XetoWare\Ace Video Converter\is-7HHB2.tmpexecutable
MD5:8813605F017B912A4C775800A96B3D43
SHA256:8D6E290E45F2C5E2FE8DC46C70CBA8D00ABC4CC67A0CD312150ED2E6CBE8EF62
5972ace-video-converter.tmpC:\Users\admin\AppData\Local\Temp\is-6J4K1.tmp\itdownload.dllexecutable
MD5:D82A429EFD885CA0F324DD92AFB6B7B8
SHA256:B258C4D7D2113DEE2168ED7E35568C8E03341E24E3EAFC7A22A0D62E32122EF3
5972ace-video-converter.tmpC:\Program Files (x86)\XetoWare\Ace Video Converter\is-FHEAU.tmpexecutable
MD5:0EAF3E150D0D58875D872A6832ABF724
SHA256:1BD55C8C1F44E971843A7F38796CC69C6FEC34E65EB0818E51568A770FC92A31
5972ace-video-converter.tmpC:\Windows\SysWOW64\COMCTL32.OCXexecutable
MD5:E2BED335446B7321FF38A138B3962E8A
SHA256:A071A89CA5F35FF51A5631B7EA7AA882EEE1E8787640AB2E0C1F192F677EC443
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
24
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3192
Ace Video Converter.exe
GET
301
162.125.66.15:80
http://dl.dropbox.com/u/91425842/avcVersion.txt
unknown
whitelisted
6040
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6040
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3192
Ace Video Converter.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEA6isGT21L%2B%2BLXlK7gS%2BvZE%3D
unknown
whitelisted
3192
Ace Video Converter.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
5496
MoUsoCoreWorker.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6040
SIHClient.exe
52.149.20.212:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6040
SIHClient.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6040
SIHClient.exe
13.95.31.18:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 2.23.181.156
whitelisted
google.com
  • 142.250.185.238
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
www.cooctdlfast.com
unknown
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
dl.dropbox.com
  • 162.125.66.15
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted

Threats

No threats detected
No debug info