File name:

ace-video-converter.exe

Full analysis: https://app.any.run/tasks/a7489d7f-5eb1-47dc-99c2-d4eb86f1f090
Verdict: Malicious activity
Analysis date: April 23, 2025, 02:38:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

C65553D09A6195F56E4AA776C45CCFD2

SHA1:

C32A369494F69DDBDB0A39EEEAE0CB49FF8F1E08

SHA256:

902C9F27A9AAA02FDE8CD10C02A198932E09A939A5EDBDC0B30DE537990B9982

SSDEEP:

196608:vTBx9ljzjy2w8jREfclHZhnPPaj9ZmQSAwBvKH:7BDNXVw8dE0BPPanmrKH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • ace-video-converter.exe (PID: 1188)
      • ace-video-converter.exe (PID: 3240)
      • Ace Video Converter.exe (PID: 3192)
    • Registers / Runs the DLL via REGSVR32.EXE

      • ace-video-converter.tmp (PID: 5972)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ace-video-converter.tmp (PID: 6388)
      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
    • Executable content was dropped or overwritten

      • ace-video-converter.exe (PID: 1188)
      • ace-video-converter.exe (PID: 3240)
      • ace-video-converter.tmp (PID: 5972)
    • Reads the Windows owner or organization settings

      • ace-video-converter.tmp (PID: 5972)
    • Process drops legitimate windows executable

      • ace-video-converter.tmp (PID: 5972)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3300)
      • regsvr32.exe (PID: 5776)
      • regsvr32.exe (PID: 2852)
      • regsvr32.exe (PID: 4040)
      • regsvr32.exe (PID: 7148)
      • regsvr32.exe (PID: 3008)
    • There is functionality for taking screenshot (YARA)

      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
  • INFO

    • Create files in a temporary directory

      • ace-video-converter.exe (PID: 1188)
      • ace-video-converter.exe (PID: 3240)
      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
    • Checks supported languages

      • ace-video-converter.exe (PID: 1188)
      • ace-video-converter.tmp (PID: 6388)
      • ace-video-converter.exe (PID: 3240)
      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
    • Reads the computer name

      • ace-video-converter.tmp (PID: 6388)
      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
    • Process checks computer location settings

      • ace-video-converter.tmp (PID: 6388)
    • The sample compiled with english language support

      • ace-video-converter.tmp (PID: 5972)
    • Compiled with Borland Delphi (YARA)

      • ace-video-converter.exe (PID: 1188)
      • ace-video-converter.exe (PID: 3240)
      • ace-video-converter.tmp (PID: 6388)
      • ace-video-converter.tmp (PID: 5972)
    • Creates files in the program directory

      • ace-video-converter.tmp (PID: 5972)
    • Detects InnoSetup installer (YARA)

      • ace-video-converter.exe (PID: 3240)
      • ace-video-converter.tmp (PID: 5972)
      • ace-video-converter.exe (PID: 1188)
      • ace-video-converter.tmp (PID: 6388)
    • Checks proxy server information

      • ace-video-converter.tmp (PID: 5972)
      • Ace Video Converter.exe (PID: 3192)
      • slui.exe (PID: 896)
    • Reads mouse settings

      • regsvr32.exe (PID: 7148)
      • Ace Video Converter.exe (PID: 3192)
    • Creates a software uninstall entry

      • ace-video-converter.tmp (PID: 5972)
    • Creates files or folders in the user directory

      • Ace Video Converter.exe (PID: 3192)
    • Reads the machine GUID from the registry

      • Ace Video Converter.exe (PID: 3192)
    • Reads the software policy settings

      • slui.exe (PID: 896)
      • Ace Video Converter.exe (PID: 3192)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (42.6)
.exe | Win16/32 Executable Delphi generic (19.5)
.exe | Generic Win/DOS Executable (18.9)
.exe | DOS Executable Generic (18.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:01:30 14:21:56+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 3.8.0.0
ProductVersionNumber: 3.8.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: XetoWare
FileDescription: Ace Video Converter Setup
FileVersion: 3.8
LegalCopyright: © 2014 XetoWare
ProductName: Ace Video Converter
ProductVersion: 3.8
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
23
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
start ace-video-converter.exe ace-video-converter.tmp no specs ace-video-converter.exe ace-video-converter.tmp regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs ace video converter.exe rundll32.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
896C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
920C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1040"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\OLEPRO32.DLL"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1188"C:\Users\admin\AppData\Local\Temp\ace-video-converter.exe" C:\Users\admin\AppData\Local\Temp\ace-video-converter.exe
explorer.exe
User:
admin
Company:
XetoWare
Integrity Level:
MEDIUM
Description:
Ace Video Converter Setup
Exit code:
0
Version:
3.8
Modules
Images
c:\users\admin\appdata\local\temp\ace-video-converter.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1240"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\scrrun.dll"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1324"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\ASYCFILT.DLL"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
4
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2420"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msimg32.dll"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
4
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2852"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\COMDLG32.OCX"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3008"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msvbvm60.dll"C:\Windows\SysWOW64\regsvr32.exeace-video-converter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3192"C:\Program Files (x86)\XetoWare\Ace Video Converter\Ace Video Converter.EXE"C:\Program Files (x86)\XetoWare\Ace Video Converter\Ace Video Converter.exe
ace-video-converter.tmp
User:
admin
Company:
XetoWare
Integrity Level:
MEDIUM
Description:
Ace Video Converter
Version:
3.08
Modules
Images
c:\program files (x86)\xetoware\ace video converter\ace video converter.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
3 450
Read events
2 995
Write events
333
Delete events
122

Modification events

(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}
Operation:delete keyName:(default)
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0713E8A8-850A-101B-AFC0-4210102A8DA7}
Operation:delete keyName:(default)
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0713E8A8-850A-101B-AFC0-4210102A8DA7}\InprocServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}
Operation:delete keyName:(default)
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}
Operation:delete keyName:(default)
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B66834C6-2E60-11CE-8748-524153480004}\InprocServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(3300) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{612A8624-0FB3-11CE-8747-524153480004}
Operation:delete keyName:(default)
Value:
Executable files
35
Suspicious files
13
Text files
162
Unknown types
0

Dropped files

PID
Process
Filename
Type
1188ace-video-converter.exeC:\Users\admin\AppData\Local\Temp\is-QP3MM.tmp\ace-video-converter.tmpexecutable
MD5:D7FD24094728B56012F16AE8AFED07B7
SHA256:B3B9FE1F1EC947568413023534D15C811E0320C63A2B273F6F291ADCDD5C530D
5972ace-video-converter.tmpC:\Users\admin\AppData\Local\Temp\is-6J4K1.tmp\_isetup\_setup64.tmpexecutable
MD5:C8871EFD8AF2CF4D9D42D1FF8FADBF89
SHA256:E4FC574A01B272C2D0AED0EC813F6D75212E2A15A5F5C417129DD65D69768F40
5972ace-video-converter.tmpC:\Program Files (x86)\XetoWare\Ace Video Converter\unins000.exeexecutable
MD5:D7FD24094728B56012F16AE8AFED07B7
SHA256:B3B9FE1F1EC947568413023534D15C811E0320C63A2B273F6F291ADCDD5C530D
3240ace-video-converter.exeC:\Users\admin\AppData\Local\Temp\is-UBR1K.tmp\ace-video-converter.tmpexecutable
MD5:D7FD24094728B56012F16AE8AFED07B7
SHA256:B3B9FE1F1EC947568413023534D15C811E0320C63A2B273F6F291ADCDD5C530D
5972ace-video-converter.tmpC:\Program Files (x86)\XetoWare\Ace Video Converter\is-FHEAU.tmpexecutable
MD5:0EAF3E150D0D58875D872A6832ABF724
SHA256:1BD55C8C1F44E971843A7F38796CC69C6FEC34E65EB0818E51568A770FC92A31
5972ace-video-converter.tmpC:\Users\admin\AppData\Local\Temp\is-6J4K1.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
5972ace-video-converter.tmpC:\Program Files (x86)\XetoWare\Ace Video Converter\Ace Video Converter.exeexecutable
MD5:0EAF3E150D0D58875D872A6832ABF724
SHA256:1BD55C8C1F44E971843A7F38796CC69C6FEC34E65EB0818E51568A770FC92A31
5972ace-video-converter.tmpC:\Windows\SysWOW64\MSCOMCTL.OCXexecutable
MD5:D268668751EE22997D7EF1417034CB04
SHA256:FAC6736251D3C61ECBD63BE0420D1C75D5CD0442181D479013330155CA37D358
5972ace-video-converter.tmpC:\Windows\SysWOW64\COMDLG32.OCXexecutable
MD5:AB412429F1E5FB9708A8CDEA07479099
SHA256:E32D8BBE8E6985726742B496520FA47827F3B428648FA1BC34ECFFDD9BDAC240
5972ace-video-converter.tmpC:\Windows\SysWOW64\is-2A5IN.tmpexecutable
MD5:D268668751EE22997D7EF1417034CB04
SHA256:FAC6736251D3C61ECBD63BE0420D1C75D5CD0442181D479013330155CA37D358
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
24
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6040
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6040
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3192
Ace Video Converter.exe
GET
301
162.125.66.15:80
http://dl.dropbox.com/u/91425842/avcVersion.txt
unknown
whitelisted
3192
Ace Video Converter.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
3192
Ace Video Converter.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEA6isGT21L%2B%2BLXlK7gS%2BvZE%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
5496
MoUsoCoreWorker.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6040
SIHClient.exe
52.149.20.212:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6040
SIHClient.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6040
SIHClient.exe
13.95.31.18:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 2.23.181.156
whitelisted
google.com
  • 142.250.185.238
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
www.cooctdlfast.com
unknown
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
dl.dropbox.com
  • 162.125.66.15
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted

Threats

No threats detected
No debug info