File name:

GarminTrainerSetup_31030.exe

Full analysis: https://app.any.run/tasks/be25c1a4-3a2f-4d33-8d7f-6fd0445d3459
Verdict: Malicious activity
Analysis date: August 01, 2025, 06:08:25
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

55EAE9AFB4242DDBAC4A11734BADCADE

SHA1:

C47A969850B7C25F20555740E6CD044A48325042

SHA256:

998E75D03DE65BDAB041BB348426FF8A0D48547A3F883E8E48E6736A27FDAF48

SSDEEP:

98304:VLbkHLWqniKHqvQDzNAJI0PkbdFeFk/aNzNMC/Uk6yeb0R900nDcY9Lv/2B9yXPP:++Sq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • GarminTrainerSetup.exe (PID: 1040)
  • SUSPICIOUS

    • Starts itself from another location

      • GarminTrainerSetup_31030.exe (PID: 5952)
      • GarminTrainerSetup_31030.exe (PID: 1668)
    • Executable content was dropped or overwritten

      • GarminTrainerSetup_31030.exe (PID: 5952)
      • GarminTrainerSetup_31030.exe (PID: 1668)
      • GarminTrainerSetup.exe (PID: 1040)
    • Process drops legitimate windows executable

      • GarminTrainerSetup_31030.exe (PID: 1668)
    • The process creates files with name similar to system file names

      • GarminTrainerSetup_31030.exe (PID: 1668)
    • Searches for installed software

      • GarminTrainerSetup_31030.exe (PID: 1668)
      • dllhost.exe (PID: 620)
    • Reads security settings of Internet Explorer

      • GarminTrainerSetup_31030.exe (PID: 1668)
      • GarminTrainerSetup.exe (PID: 1040)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6980)
    • Creates a software uninstall entry

      • GarminTrainerSetup.exe (PID: 1040)
  • INFO

    • Create files in a temporary directory

      • GarminTrainerSetup_31030.exe (PID: 5952)
      • GarminTrainerSetup_31030.exe (PID: 1668)
    • The sample compiled with english language support

      • GarminTrainerSetup_31030.exe (PID: 5952)
      • GarminTrainerSetup_31030.exe (PID: 1668)
      • GarminTrainerSetup.exe (PID: 1040)
    • Checks supported languages

      • GarminTrainerSetup_31030.exe (PID: 1668)
      • GarminTrainerSetup_31030.exe (PID: 5952)
      • GarminTrainerSetup.exe (PID: 1040)
    • Reads the computer name

      • GarminTrainerSetup_31030.exe (PID: 1668)
      • GarminTrainerSetup.exe (PID: 1040)
    • Reads the machine GUID from the registry

      • GarminTrainerSetup_31030.exe (PID: 1668)
      • GarminTrainerSetup.exe (PID: 1040)
    • Creates files in the program directory

      • GarminTrainerSetup_31030.exe (PID: 1668)
      • GarminTrainerSetup.exe (PID: 1040)
    • Process checks computer location settings

      • GarminTrainerSetup_31030.exe (PID: 1668)
    • Manages system restore points

      • SrTasks.exe (PID: 5644)
    • Reads the software policy settings

      • GarminTrainerSetup_31030.exe (PID: 1668)
      • GarminTrainerSetup.exe (PID: 1040)
    • Launching a file from a Registry key

      • GarminTrainerSetup.exe (PID: 1040)
    • Checks proxy server information

      • GarminTrainerSetup_31030.exe (PID: 1668)
      • GarminTrainerSetup.exe (PID: 1040)
    • Creates files or folders in the user directory

      • GarminTrainerSetup.exe (PID: 1040)
      • GarminTrainerSetup_31030.exe (PID: 1668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:09:17 05:33:38+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.16
CodeSize: 299008
InitializedDataSize: 287232
UninitializedDataSize: -
EntryPoint: 0x2df71
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 3.10.3.0
ProductVersionNumber: 3.10.3.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Garmin
FileDescription: Garmin Aviation Trainers
FileVersion: 3.10.3.0
InternalName: setup
LegalCopyright: Copyright (c) Garmin. All rights reserved.
OriginalFileName: GarminTrainerSetup.exe
ProductName: Garmin Aviation Trainers
ProductVersion: 3.10.3.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
8
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start garmintrainersetup_31030.exe garmintrainersetup_31030.exe garmintrainersetup.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
620C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
1040"C:\Users\admin\AppData\Local\Temp\{5C92D512-B1FF-47BD-8A6C-BBF26E020488}\.be\GarminTrainerSetup.exe" -q -burn.elevated BurnPipe.{50DAF358-290C-433F-BC51-0BB97C09C906} {A85036C7-A6F0-428A-ACF8-464396EB0B64} 1668C:\Users\admin\AppData\Local\Temp\{5C92D512-B1FF-47BD-8A6C-BBF26E020488}\.be\GarminTrainerSetup.exe
GarminTrainerSetup_31030.exe
User:
admin
Company:
Garmin
Integrity Level:
HIGH
Description:
Garmin Aviation Trainers
Version:
3.10.3.0
Modules
Images
c:\users\admin\appdata\local\temp\{5c92d512-b1ff-47bd-8a6c-bbf26e020488}\.be\garmintrainersetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1668"C:\Users\admin\AppData\Local\Temp\{5D0C862A-F9BA-4436-A97E-32A0055B55DC}\.cr\GarminTrainerSetup_31030.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\GarminTrainerSetup_31030.exe" -burn.filehandle.attached=572 -burn.filehandle.self=592 C:\Users\admin\AppData\Local\Temp\{5D0C862A-F9BA-4436-A97E-32A0055B55DC}\.cr\GarminTrainerSetup_31030.exe
GarminTrainerSetup_31030.exe
User:
admin
Company:
Garmin
Integrity Level:
MEDIUM
Description:
Garmin Aviation Trainers
Version:
3.10.3.0
Modules
Images
c:\users\admin\appdata\local\temp\{5d0c862a-f9ba-4436-a97e-32a0055b55dc}\.cr\garmintrainersetup_31030.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2324C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5644C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exedllhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5952"C:\Users\admin\AppData\Local\Temp\GarminTrainerSetup_31030.exe" C:\Users\admin\AppData\Local\Temp\GarminTrainerSetup_31030.exe
explorer.exe
User:
admin
Company:
Garmin
Integrity Level:
MEDIUM
Description:
Garmin Aviation Trainers
Version:
3.10.3.0
Modules
Images
c:\users\admin\appdata\local\temp\garmintrainersetup_31030.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6840\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6980C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
7 249
Read events
7 032
Write events
197
Delete events
20

Modification events

(PID) Process:(620) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
480000000000000009ED37C8AA02DC016C0200007C170000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(620) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000B6DB5EC8AA02DC016C0200007C170000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6980) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Leave)
Value:
48000000000000003F7BA1C8AA02DC01441B0000F8070000E80300000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6980) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{a5a30fa2-3d06-4e9f-b5f4-a01df9d1fcba}\Elements\24000001
Operation:writeName:Element
Value:
{5b970157-8568-11eb-b45c-806e6f6e6963}
(PID) Process:(6980) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{a5a30fa2-3d06-4e9f-b5f4-a01df9d1fcba}\Elements\25000004
Operation:writeName:Element
Value:
0000000000000000
(PID) Process:(1040) GarminTrainerSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000833437C8AA02DC0110040000B8070000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(620) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000C41F57C8AA02DC016C0200007C170000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(620) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000005E4757C8AA02DC016C0200007C170000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(620) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000C7DF58C8AA02DC016C0200007C170000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(620) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
Executable files
38
Suspicious files
13
Text files
30
Unknown types
6

Dropped files

PID
Process
Filename
Type
1668GarminTrainerSetup_31030.exeC:\Users\admin\AppData\Local\Temp\{5C92D512-B1FF-47BD-8A6C-BBF26E020488}\.ba\TrainerUILib.dllexecutable
MD5:44AD05C1314B5C9D9B2AEBAE19A9DEED
SHA256:AB8D63BCE69B51E1DAEF8ACA797AB027B426FDB3616A59EC1A7B5BCB56E75549
1668GarminTrainerSetup_31030.exeC:\Users\admin\AppData\Local\Temp\{5C92D512-B1FF-47BD-8A6C-BBF26E020488}\.ba\BootstrapperCore.configxml
MD5:6E8B1376253A0FDD41F34C807B58C6DE
SHA256:F79890B9BBC3E6C8E4D4468ADCE49BBA998C2C9CD7FDDCBEFDC207C000A28425
1668GarminTrainerSetup_31030.exeC:\Users\admin\AppData\Local\Temp\{5C92D512-B1FF-47BD-8A6C-BBF26E020488}\.ba\Microsoft.Deployment.WindowsInstaller.dllexecutable
MD5:1A5CAEA6734FDD07CAA514C3F3FB75DA
SHA256:CF06D4ED4A8BAF88C82D6C9AE0EFC81C469DE6DA8788AB35F373B350A4B4CDCA
1668GarminTrainerSetup_31030.exeC:\Users\admin\AppData\Local\Temp\{5C92D512-B1FF-47BD-8A6C-BBF26E020488}\.ba\ManagedBootstrapperUI.dllexecutable
MD5:6F29273C6696558599DB95B23CC2E66E
SHA256:EC3C4522ABFF3A2FCD6B2C8A89D715AEF3ED5A8FB3F46C96AEFFAE96814BF44A
1668GarminTrainerSetup_31030.exeC:\Users\admin\AppData\Local\Temp\{5C92D512-B1FF-47BD-8A6C-BBF26E020488}\.ba\System.Threading.Tasks.Extensions.dllexecutable
MD5:0F384AFCF671483188B9019D3B7457A7
SHA256:2C9CAD6410E37E44FA73CCCB576F418184F1AE5A0A257E165A136BDAA941A0C6
1668GarminTrainerSetup_31030.exeC:\Users\admin\AppData\Local\Temp\{5C92D512-B1FF-47BD-8A6C-BBF26E020488}\.ba\BootstrapperCore.dllexecutable
MD5:B0D10A2A622A322788780E7A3CBB85F3
SHA256:F2C2B3CE2DF70A3206F3111391FFC7B791B32505FA97AEF22C0C2DBF6F3B0426
1668GarminTrainerSetup_31030.exeC:\Users\admin\AppData\Local\Temp\{5C92D512-B1FF-47BD-8A6C-BBF26E020488}\.ba\mbapreq.thmxml
MD5:A20778EC90A094A62A6C3A6AB2A6DC7D
SHA256:F8C3A03F47F0B9B3C20F0522A2481DA28C77FECDBB302F8DD8FBED87758CBAEA
5952GarminTrainerSetup_31030.exeC:\Users\admin\AppData\Local\Temp\{5D0C862A-F9BA-4436-A97E-32A0055B55DC}\.cr\GarminTrainerSetup_31030.exeexecutable
MD5:55EAE9AFB4242DDBAC4A11734BADCADE
SHA256:998E75D03DE65BDAB041BB348426FF8A0D48547A3F883E8E48E6736A27FDAF48
1668GarminTrainerSetup_31030.exeC:\Users\admin\AppData\Local\Temp\{5C92D512-B1FF-47BD-8A6C-BBF26E020488}\.ba\Prism.dllexecutable
MD5:C4BDF5182ABB66BE01669C4441020A0B
SHA256:6F30A8859EE3FB2F3866D50F79572C2D02E70B1F2831D894FDD8446FD3DBB1BD
1668GarminTrainerSetup_31030.exeC:\Users\admin\AppData\Local\Temp\{5C92D512-B1FF-47BD-8A6C-BBF26E020488}\.ba\InstallerAppCenterCrashReporting.dllexecutable
MD5:D02D6524A41B6866E78D64D5949E2B89
SHA256:3A2D7B0E43D56376BFE9DFAD318E0C1B1314FA089E4DDFF98E8AE3B83C98DDEC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
36
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.3.109.244:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4224
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
23.216.77.25:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3556
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3556
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1668
GarminTrainerSetup_31030.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1040
GarminTrainerSetup.exe
GET
200
2.16.241.14:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
1040
GarminTrainerSetup.exe
GET
200
2.16.241.14:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1040
GarminTrainerSetup.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
1040
GarminTrainerSetup.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5288
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.216.77.25:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.3.109.244:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4224
svchost.exe
20.190.160.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4224
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 172.217.16.206
whitelisted
crl.microsoft.com
  • 23.216.77.25
  • 23.216.77.20
  • 23.216.77.42
  • 23.216.77.6
  • 23.216.77.28
  • 2.16.241.14
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 23.3.109.244
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.160.67
  • 20.190.160.130
  • 40.126.32.74
  • 40.126.32.134
  • 20.190.160.20
  • 20.190.160.64
  • 20.190.160.4
  • 40.126.32.138
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
slscr.update.microsoft.com
  • 20.165.94.63
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
client.wns.windows.com
  • 20.59.87.226
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted

Threats

No threats detected
Process
Message
GarminTrainerSetup_31030.exe
Info
GarminTrainerSetup_31030.exe
:
GarminTrainerSetup_31030.exe
MBA: MBA RUNNING: 3.10.3.0
GarminTrainerSetup_31030.exe
GarminTrainerSetup_31030.exe
Info
GarminTrainerSetup_31030.exe
:
GarminTrainerSetup_31030.exe
MBA: Command: Action:Install Display:Full Restart:Prompt CommandLine:null LayoutDirectory:null Resume:None SplashScreen:0 Relation:None Passthrough:False CommandLineArray:
GarminTrainerSetup_31030.exe
GarminTrainerSetup_31030.exe
Info
GarminTrainerSetup_31030.exe
: