File name:

spacedesk_driver_Win_10_64_v2135.msi

Full analysis: https://app.any.run/tasks/6b2eb58c-d606-4798-9976-4e6863dbcee9
Verdict: Malicious activity
Analysis date: February 12, 2025, 13:30:55
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: spacedesk 2.1.35 Driver Installer, Author: datronicsoft Inc., Keywords: Installer, Comments: Windows Network Display Monitor Software, Template: x64;1033, Revision Number: {5428EC03-323E-468B-A0C3-2A4E4DA60CBE}, Create Time/Date: Thu Jan 30 09:15:12 2025, Last Saved Time/Date: Thu Jan 30 09:15:12 2025, Number of Pages: 500, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
MD5:

AA0527B7268C6CBAB6BE22004DF47AE3

SHA1:

066425CCD483E31C3AA4DCB99674FFFD46BC9E3E

SHA256:

97D23176DEEFFABB6AE48200FDFE377272DDC3F5EA34206B353A1E8A38BE62CB

SSDEEP:

98304:A63qFeBrZ9iQvjUldca1KIQBe4TR5/ECAiqqRUlv9D+gm1msfNi6jqxyV3olPfYG:wXyk4Ui/Kh9cQL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 7056)
      • spacedeskService.exe (PID: 2728)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6476)
      • drvinst.exe (PID: 7116)
      • drvinst.exe (PID: 6548)
      • drvinst.exe (PID: 4468)
      • drvinst.exe (PID: 1412)
      • drvinst.exe (PID: 6544)
      • drvinst.exe (PID: 1468)
      • drvinst.exe (PID: 4944)
      • drvinst.exe (PID: 1480)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6476)
    • Drops a system driver (possible attempt to evade defenses)

      • drvinst.exe (PID: 7116)
      • MSIDBE0.tmp (PID: 4428)
      • drvinst.exe (PID: 6548)
      • MSIE1FD.tmp (PID: 6556)
      • drvinst.exe (PID: 4468)
      • MSIE626.tmp (PID: 3876)
      • drvinst.exe (PID: 1468)
      • MSIE7BE.tmp (PID: 3984)
      • drvinst.exe (PID: 4944)
      • MSIE984.tmp (PID: 2972)
      • drvinst.exe (PID: 1480)
      • msiexec.exe (PID: 6476)
      • drvinst.exe (PID: 2612)
    • Executable content was dropped or overwritten

      • MSIDBE0.tmp (PID: 4428)
      • drvinst.exe (PID: 7116)
      • drvinst.exe (PID: 6548)
      • MSIE1FD.tmp (PID: 6556)
      • drvinst.exe (PID: 4468)
      • MSIE346.tmp (PID: 644)
      • drvinst.exe (PID: 1412)
      • MSIE47F.tmp (PID: 3208)
      • drvinst.exe (PID: 6544)
      • MSIE626.tmp (PID: 3876)
      • drvinst.exe (PID: 1468)
      • MSIE7BE.tmp (PID: 3984)
      • drvinst.exe (PID: 4944)
      • MSIE984.tmp (PID: 2972)
      • drvinst.exe (PID: 1480)
      • drvinst.exe (PID: 2612)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 6364)
    • Likely accesses (executes) a file from the Public directory

      • powershell.exe (PID: 7136)
      • powershell.exe (PID: 4132)
      • powershell.exe (PID: 5536)
    • Starts POWERSHELL.EXE for commands execution

      • spacedeskConsole.exe (PID: 4624)
  • INFO

    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6276)
    • An automatically generated document

      • msiexec.exe (PID: 6276)
    • Reads the software policy settings

      • msiexec.exe (PID: 6276)
      • msiexec.exe (PID: 6476)
      • drvinst.exe (PID: 7116)
      • drvinst.exe (PID: 6548)
      • drvinst.exe (PID: 4468)
      • drvinst.exe (PID: 1412)
      • drvinst.exe (PID: 6544)
      • drvinst.exe (PID: 4944)
      • drvinst.exe (PID: 1480)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 6276)
    • Checks supported languages

      • msiexec.exe (PID: 6476)
      • msiexec.exe (PID: 7000)
      • MSIDA96.tmp (PID: 6888)
      • MSIDB82.tmp (PID: 6912)
      • drvinst.exe (PID: 7116)
      • MSIDBE0.tmp (PID: 4428)
      • MSIE0D3.tmp (PID: 6468)
      • drvinst.exe (PID: 6548)
      • MSIE1FD.tmp (PID: 6556)
      • drvinst.exe (PID: 6364)
      • MSIE346.tmp (PID: 644)
      • drvinst.exe (PID: 1412)
      • drvinst.exe (PID: 4468)
      • MSIE47F.tmp (PID: 3208)
      • drvinst.exe (PID: 6544)
      • MSIE626.tmp (PID: 3876)
      • drvinst.exe (PID: 1468)
      • MSIE7BE.tmp (PID: 3984)
      • drvinst.exe (PID: 4944)
      • MSIDA66.tmp (PID: 6868)
      • drvinst.exe (PID: 2612)
      • MSIE984.tmp (PID: 2972)
      • drvinst.exe (PID: 1480)
      • spacedeskService.exe (PID: 2728)
      • spacedeskServiceTray.exe (PID: 6612)
      • MSIEBF8.tmp (PID: 6900)
      • MSIEB89.tmp (PID: 6392)
    • Reads the computer name

      • msiexec.exe (PID: 6476)
      • msiexec.exe (PID: 7000)
      • MSIDA96.tmp (PID: 6888)
      • MSIDBE0.tmp (PID: 4428)
      • drvinst.exe (PID: 7116)
      • MSIE0D3.tmp (PID: 6468)
      • drvinst.exe (PID: 6548)
      • MSIE1FD.tmp (PID: 6556)
      • drvinst.exe (PID: 6364)
      • MSIE346.tmp (PID: 644)
      • drvinst.exe (PID: 4468)
      • drvinst.exe (PID: 1412)
      • MSIE47F.tmp (PID: 3208)
      • drvinst.exe (PID: 6544)
      • MSIE626.tmp (PID: 3876)
      • MSIE7BE.tmp (PID: 3984)
      • drvinst.exe (PID: 1468)
      • drvinst.exe (PID: 4944)
      • drvinst.exe (PID: 1480)
      • MSIE984.tmp (PID: 2972)
      • spacedeskService.exe (PID: 2728)
      • spacedeskServiceTray.exe (PID: 6612)
      • MSIEB89.tmp (PID: 6392)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6276)
      • msiexec.exe (PID: 6476)
    • Manages system restore points

      • SrTasks.exe (PID: 6172)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 6476)
      • drvinst.exe (PID: 7116)
      • drvinst.exe (PID: 6548)
      • drvinst.exe (PID: 4468)
      • drvinst.exe (PID: 1412)
      • drvinst.exe (PID: 6544)
      • drvinst.exe (PID: 4944)
      • drvinst.exe (PID: 1468)
      • drvinst.exe (PID: 1480)
    • The sample compiled with english language support

      • msiexec.exe (PID: 6476)
      • MSIDBE0.tmp (PID: 4428)
      • drvinst.exe (PID: 7116)
      • drvinst.exe (PID: 6548)
      • MSIE346.tmp (PID: 644)
      • drvinst.exe (PID: 1412)
      • MSIE47F.tmp (PID: 3208)
      • drvinst.exe (PID: 6544)
      • drvinst.exe (PID: 1480)
      • MSIE984.tmp (PID: 2972)
      • drvinst.exe (PID: 2612)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 6476)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6476)
    • Manual execution by a user

      • spacedeskConsole.exe (PID: 4624)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 4132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: spacedesk 2.1.35 Driver Installer
Author: datronicsoft Inc.
Keywords: Installer
Comments: Windows Network Display Monitor Software
Template: x64;1033
RevisionNumber: {5428EC03-323E-468B-A0C3-2A4E4DA60CBE}
CreateDate: 2025:01:30 09:15:12
ModifyDate: 2025:01:30 09:15:12
Pages: 500
Words: 2
Software: Windows Installer XML Toolset (3.11.2.4516)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
180
Monitored processes
40
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msida66.tmp no specs msida96.tmp no specs msidb82.tmp no specs msidbe0.tmp drvinst.exe drvinst.exe no specs msie0d3.tmp no specs drvinst.exe msie1fd.tmp drvinst.exe msie346.tmp drvinst.exe msie47f.tmp drvinst.exe msie626.tmp drvinst.exe msie7be.tmp drvinst.exe msie984.tmp drvinst.exe drvinst.exe msieb2b.tmp no specs spacedeskservice.exe no specs spacedeskservicetray.exe no specs msieb89.tmp no specs msiebf8.tmp no specs msiecd3.tmp no specs spacedeskconsole.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
644"C:\WINDOWS\Installer\MSIE346.tmp" -install_hid,C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles\C:\Windows\Installer\MSIE346.tmp
msiexec.exe
User:
admin
Company:
datronicsoft
Integrity Level:
MEDIUM
Description:
spacedesk Setup Custom Action
Exit code:
0
Version:
0.2.1.35
Modules
Images
c:\windows\installer\msie346.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1412DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{98c8e0b7-97ef-9447-b40f-4bd38cdd7714}\spacedeskDriverHid.inf" "9" "4427793e7" "00000000000001F8" "WinSta0\Default" "0000000000000200" "208" "C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1468DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{0dea9bc6-3a92-ea4e-a47f-7c6f83823b37}\spacedeskDriverAudio.inf" "9" "447268673" "0000000000000208" "WinSta0\Default" "0000000000000200" "208" "C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1480DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{204a61cc-fa67-9243-a745-403a9e10754e}\spacedeskDriverBus.inf" "9" "4522ade83" "0000000000000224" "WinSta0\Default" "0000000000000228" "208" "C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1544\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2612DrvInst.exe "2" "1" "ROOT\SPACEDESK_VIRTUAL_BUS\0000" "C:\WINDOWS\System32\DriverStore\FileRepository\spacedeskdriverbus.inf_amd64_866ccd67be8813b9\spacedeskdriverbus.inf" "oem12.inf:*:*:1.0.462.45:Root\VID_DATRONICSOFT_PID_SPACEDESK_VIRTUAL_BUS_0001," "4522ade83" "0000000000000220"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2728"C:\Program Files\datronicsoft\spacedesk\spacedeskService.exe"C:\Program Files\datronicsoft\spacedesk\spacedeskService.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files\datronicsoft\spacedesk\spacedeskservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\ucrtbase.dll
2972"C:\WINDOWS\Installer\MSIE984.tmp" -install_bus,C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles\C:\Windows\Installer\MSIE984.tmp
msiexec.exe
User:
admin
Company:
datronicsoft
Integrity Level:
MEDIUM
Description:
spacedesk Setup Custom Action
Exit code:
0
Version:
0.2.1.35
Modules
Images
c:\windows\installer\msie984.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3208"C:\WINDOWS\Installer\MSIE47F.tmp" -install_iddcx,C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles\,0C:\Windows\Installer\MSIE47F.tmp
msiexec.exe
User:
admin
Company:
datronicsoft
Integrity Level:
MEDIUM
Description:
spacedesk Setup Custom Action
Exit code:
0
Version:
0.2.1.35
Modules
Images
c:\windows\installer\msie47f.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3744\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
56 076
Read events
55 692
Write events
350
Delete events
34

Modification events

(PID) Process:(6476) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000AE005066527DDB014C190000801B0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6476) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000AE005066527DDB014C190000801B0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6476) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
480000000000000005629066527DDB014C190000801B0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6476) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
480000000000000005629066527DDB014C190000801B0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6476) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000FAC49266527DDB014C190000801B0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6476) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000F1289566527DDB014C190000801B0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6476) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6476) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
480000000000000051DC0267527DDB014C190000801B0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6476) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000493F0567527DDB014C190000EC1B0000E8030000010000000000000000000000841EFF27B2810E439ADF791BF075C7CA00000000000000000000000000000000
(PID) Process:(7056) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
Executable files
66
Suspicious files
97
Text files
12
Unknown types
16

Dropped files

PID
Process
Filename
Type
6476msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6476msiexec.exeC:\Windows\Installer\13d4e7.msi
MD5:
SHA256:
6476msiexec.exeC:\Windows\Installer\MSID891.tmp
MD5:
SHA256:
6476msiexec.exeC:\Windows\Temp\~DFBCDA9B00B4C64E90.TMPbinary
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
6276msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:9989E1E40D855EF32690E8589794CEB1
SHA256:AF5145B9CB8D9D5EA26B7D45A70C0260967B5D43C2CCC30318EDD294DD734E03
6276msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_74F67001B3C2D533D99B6A2860970A04binary
MD5:5B52522D5B9A398B02E021928033CB85
SHA256:D63B627323DCF1D7B91C64AFBAFF0293D611771E6292E00EB1AEEBD351BB9C8A
6276msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:35ED87150A4412BEC98B37AF517280DA
SHA256:3E08F092069DDA8548E749E79F8D32FBE95CEB7AB7BECD100B6126E8F2C02644
6276msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_74F67001B3C2D533D99B6A2860970A04binary
MD5:0F3406BA60168C9F296707D700299B87
SHA256:D1B6D32D7364467CB8B05B6B210E26C6B81F3D72BC5B75B68681B536ADA730D1
6276msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI87B1.tmpexecutable
MD5:4FDD16752561CF585FED1506914D73E0
SHA256:AECD2D2FE766F6D439ACC2BBF1346930ECC535012CF5AD7B3273D2875237B7E7
6276msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:0F33BD58B02B90A047B6B85EA192419B
SHA256:FDFDB04FACFE93509EAD3E97DBA9165CB16F1625FE384AA8FA4E4700BBB85A1B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
49
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3416
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3416
svchost.exe
GET
200
23.48.23.141:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6276
msiexec.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6276
msiexec.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
6276
msiexec.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA4bLnp0JeaKiM0Z462JHJc%3D
unknown
whitelisted
1176
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5544
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5544
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6156
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
3416
svchost.exe
23.48.23.141:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
3416
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
936
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
6276
msiexec.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1176
svchost.exe
20.190.160.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 23.48.23.141
  • 23.48.23.139
  • 23.48.23.143
  • 23.48.23.192
  • 23.48.23.138
  • 23.48.23.140
  • 23.48.23.190
  • 23.48.23.191
  • 23.48.23.137
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
login.live.com
  • 20.190.160.131
  • 20.190.160.66
  • 20.190.160.128
  • 20.190.160.64
  • 40.126.32.74
  • 40.126.32.138
  • 20.190.160.65
  • 40.126.32.134
whitelisted
www.bing.com
  • 104.126.37.161
  • 104.126.37.152
  • 104.126.37.160
  • 104.126.37.145
  • 104.126.37.154
  • 104.126.37.155
  • 104.126.37.139
  • 104.126.37.153
  • 104.126.37.146
  • 2.19.96.104
  • 2.19.96.130
  • 2.19.96.128
  • 2.19.96.121
  • 2.19.96.10
  • 2.19.96.112
  • 2.19.96.123
  • 2.19.96.98
  • 2.19.96.120
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

No threats detected
No debug info