File name:

LunarPatcher_Setup.exe

Full analysis: https://app.any.run/tasks/79428345-e78f-4704-a219-e379b7b866cb
Verdict: Malicious activity
Analysis date: February 03, 2026, 19:19:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
delphi
inno
installer
python
nuitka
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

F681606C95ACB78BAF1840CD384788A3

SHA1:

5222D63AA916E35033E67F39F28333330904289C

SHA256:

99D6A6A066326611D7D6F1178351CE583AA3AA0F711258AE7445E7CCED13984E

SSDEEP:

98304:GBPF0PN/Yi+UKcy9iuPrstBUlf0ORoJ9+66iDdu5xm/xu404+5eucgsRanp7en9o:C4XtYm3lfY54nVABepEbg6xlV3Kc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • LunarPatcher_Setup.tmp (PID: 4152)
    • Process drops legitimate windows executable

      • LunarPatcher.exe (PID: 7284)
      • LunarPatcher.exe (PID: 7048)
    • Process drops python dynamic module

      • LunarPatcher.exe (PID: 7284)
      • LunarPatcher.exe (PID: 7048)
    • The process drops C-runtime libraries

      • LunarPatcher.exe (PID: 7284)
      • LunarPatcher.exe (PID: 7048)
    • NUITKA compiler has been detected

      • LunarPatcher.exe (PID: 7284)
      • LunarPatcher.exe (PID: 7048)
    • Application launched itself

      • LunarPatcher.exe (PID: 7284)
    • Starts CMD.EXE for commands execution

      • LunarPatcher.exe (PID: 6664)
    • Loads Python modules

      • LunarPatcher.exe (PID: 6664)
  • INFO

    • Reads the computer name

      • LunarPatcher_Setup.tmp (PID: 4152)
      • LunarPatcher.exe (PID: 6664)
    • Checks supported languages

      • LunarPatcher_Setup.exe (PID: 4728)
      • LunarPatcher_Setup.tmp (PID: 4152)
      • SearchApp.exe (PID: 5568)
      • LunarPatcher.exe (PID: 7284)
      • LunarPatcher.exe (PID: 7048)
      • LunarPatcher.exe (PID: 6664)
    • Create files in a temporary directory

      • LunarPatcher_Setup.exe (PID: 4728)
      • LunarPatcher_Setup.tmp (PID: 4152)
      • LunarPatcher.exe (PID: 7284)
      • LunarPatcher.exe (PID: 7048)
    • Process checks computer location settings

      • SearchApp.exe (PID: 5568)
    • Reads the machine GUID from the registry

      • SearchApp.exe (PID: 5568)
      • LunarPatcher.exe (PID: 6664)
    • Compiled with Borland Delphi (YARA)

      • LunarPatcher_Setup.exe (PID: 4728)
    • Creates files or folders in the user directory

      • LunarPatcher_Setup.tmp (PID: 4152)
      • LunarPatcher.exe (PID: 6664)
    • Detects InnoSetup installer (YARA)

      • LunarPatcher_Setup.exe (PID: 4728)
    • Creates a software uninstall entry

      • LunarPatcher_Setup.tmp (PID: 4152)
    • The sample compiled with english language support

      • LunarPatcher.exe (PID: 7284)
      • LunarPatcher.exe (PID: 7048)
    • Manual execution by a user

      • LunarPatcher.exe (PID: 7048)
    • Drops script file

      • LunarPatcher.exe (PID: 6664)
    • Checks operating system version

      • LunarPatcher.exe (PID: 6664)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2026:01:02 11:55:47+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 725504
InitializedDataSize: 223744
UninitializedDataSize: -
EntryPoint: 0xb1e60
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Klodus Soft
FileDescription: Lunar Client Patcher Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Lunar Client Patcher
ProductVersion: 3.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
9
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start lunarpatcher_setup.exe no specs lunarpatcher_setup.tmp no specs lunarpatcher.exe no specs lunarpatcher.exe no specs lunarpatcher.exe no specs cmd.exe no specs conhost.exe no specs slui.exe no specs searchapp.exe

Process information

PID
CMD
Path
Indicators
Parent process
1524C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2496\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4152"C:\Users\admin\AppData\Local\Temp\is-K8GZ3I8ASE.tmp\LunarPatcher_Setup.tmp" /SL5="$D0232,13681866,950272,C:\Users\admin\AppData\Local\Temp\LunarPatcher_Setup.exe" C:\Users\admin\AppData\Local\Temp\is-K8GZ3I8ASE.tmp\LunarPatcher_Setup.tmpLunarPatcher_Setup.exe
User:
admin
Company:
Klodus Soft
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1054.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-k8gz3i8ase.tmp\lunarpatcher_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
4728"C:\Users\admin\AppData\Local\Temp\LunarPatcher_Setup.exe" C:\Users\admin\AppData\Local\Temp\LunarPatcher_Setup.exeexplorer.exe
User:
admin
Company:
Klodus Soft
Integrity Level:
MEDIUM
Description:
Lunar Client Patcher Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\lunarpatcher_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
4756C:\WINDOWS\system32\cmd.exe /c "ver"C:\Windows\System32\cmd.exeLunarPatcher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
5568"C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mcaC:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Search application
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\combase.dll
6664"C:\Users\admin\AppData\Roaming\Lunar Client Patcher\LunarPatcher.exe"C:\Users\admin\AppData\Roaming\Lunar Client Patcher\LunarPatcher.exeLunarPatcher.exe
User:
admin
Company:
KlodusSoft
Integrity Level:
MEDIUM
Description:
Lunar Client Tool
Version:
3.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\lunar client patcher\lunarpatcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
7048"C:\Users\admin\AppData\Roaming\Lunar Client Patcher\LunarPatcher.exe" C:\Users\admin\AppData\Roaming\Lunar Client Patcher\LunarPatcher.exeexplorer.exe
User:
admin
Company:
KlodusSoft
Integrity Level:
MEDIUM
Description:
Lunar Client Tool
Version:
3.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\lunar client patcher\lunarpatcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
7284"C:\Users\admin\AppData\Roaming\Lunar Client Patcher\LunarPatcher.exe"C:\Users\admin\AppData\Roaming\Lunar Client Patcher\LunarPatcher.exeLunarPatcher_Setup.tmp
User:
admin
Company:
KlodusSoft
Integrity Level:
MEDIUM
Description:
Lunar Client Tool
Version:
3.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\lunar client patcher\lunarpatcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
5 289
Read events
5 204
Write events
77
Delete events
8

Modification events

(PID) Process:(4152) LunarPatcher_Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A4B9C8D1-E2F3-4567-890A-BCDEF1234567}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.7.0
(PID) Process:(4152) LunarPatcher_Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A4B9C8D1-E2F3-4567-890A-BCDEF1234567}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Users\admin\AppData\Roaming\Lunar Client Patcher
(PID) Process:(4152) LunarPatcher_Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A4B9C8D1-E2F3-4567-890A-BCDEF1234567}_is1
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\Lunar Client Patcher\
(PID) Process:(4152) LunarPatcher_Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A4B9C8D1-E2F3-4567-890A-BCDEF1234567}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(4152) LunarPatcher_Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A4B9C8D1-E2F3-4567-890A-BCDEF1234567}_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(4152) LunarPatcher_Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A4B9C8D1-E2F3-4567-890A-BCDEF1234567}_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
(PID) Process:(4152) LunarPatcher_Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A4B9C8D1-E2F3-4567-890A-BCDEF1234567}_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
desktopicon
(PID) Process:(4152) LunarPatcher_Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A4B9C8D1-E2F3-4567-890A-BCDEF1234567}_is1
Operation:writeName:Inno Setup: Language
Value:
english
(PID) Process:(4152) LunarPatcher_Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A4B9C8D1-E2F3-4567-890A-BCDEF1234567}_is1
Operation:writeName:DisplayName
Value:
Lunar Client Patcher version 3.0
(PID) Process:(4152) LunarPatcher_Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A4B9C8D1-E2F3-4567-890A-BCDEF1234567}_is1
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Roaming\Lunar Client Patcher\unins000.exe"
Executable files
65
Suspicious files
26
Text files
1 922
Unknown types
3

Dropped files

PID
Process
Filename
Type
4152LunarPatcher_Setup.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lunar Client Patcher.lnkbinary
MD5:CF41BB0D588705EEB3710BBE2439264B
SHA256:10B407FFCF564120CD98F9FA2E06D0CF4D5815837147AD5F6481FF37C09A6848
4728LunarPatcher_Setup.exeC:\Users\admin\AppData\Local\Temp\is-K8GZ3I8ASE.tmp\LunarPatcher_Setup.tmpexecutable
MD5:FA305E7D86E9E1304FF9ADAF85C082F7
SHA256:1671EDDFFD7591629B11CD14BF3A8F7E21E31CFEFC0E2327FA5D28145F90217F
4152LunarPatcher_Setup.tmpC:\Users\admin\AppData\Roaming\Lunar Client Patcher\is-JX90F9KX8X.tmpexecutable
MD5:7450A954F75CBEF27B1603A6EFFD2B6B
SHA256:68DA42F1E65247D5CFD27068F6E9C0248C3C90153CF95728DEE0AEDA4B9134E1
4152LunarPatcher_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-UTSN2FRW9O.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
4152LunarPatcher_Setup.tmpC:\Users\admin\AppData\Roaming\Lunar Client Patcher\unins000.exeexecutable
MD5:7450A954F75CBEF27B1603A6EFFD2B6B
SHA256:68DA42F1E65247D5CFD27068F6E9C0248C3C90153CF95728DEE0AEDA4B9134E1
4152LunarPatcher_Setup.tmpC:\Users\admin\AppData\Roaming\Lunar Client Patcher\LunarPatcher.exebinary
MD5:7F7CCE6BA5AF9EFACCB253311AFAB6C2
SHA256:15DDECC7A09CF500DC6D857D75963A7C8B601A4103803364AC53A53776999E14
7284LunarPatcher.exeC:\Users\admin\AppData\Local\Temp\onefile_7284_134146199751634609\main.dllexecutable
MD5:5E151633879B58A90F56250A6545DFA7
SHA256:F3654CC1A5215D3F096674C5E97032D9BA83E487204BCAFA9356CA56B3508C96
7284LunarPatcher.exeC:\Users\admin\AppData\Local\Temp\onefile_7284_134146199751634609\_decimal.pydexecutable
MD5:1CDD7239FC63B7C8A2E2BC0A08D9EA76
SHA256:384993B2B8CFCBF155E63F0EE2383A9F9483DE92AB73736FF84590A0C4CA2690
7284LunarPatcher.exeC:\Users\admin\AppData\Local\Temp\onefile_7284_134146199751634609\_asyncio.pydexecutable
MD5:6C2A86342ADE2FAC9454B83A49D17694
SHA256:CF0EDFD508D11BFFB63D1B104B6099E0F14EA0FADA762F88364E7163F2185F06
4152LunarPatcher_Setup.tmpC:\Users\admin\AppData\Roaming\Lunar Client Patcher\is-0GL8WEQHF4.tmpbinary
MD5:7F7CCE6BA5AF9EFACCB253311AFAB6C2
SHA256:15DDECC7A09CF500DC6D857D75963A7C8B601A4103803364AC53A53776999E14
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
36
TCP/UDP connections
30
DNS requests
24
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3344
svchost.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
5920
SIHClient.exe
GET
304
20.165.94.63:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5920
SIHClient.exe
GET
200
13.95.31.18:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
5920
SIHClient.exe
GET
200
20.165.94.63:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
5920
SIHClient.exe
GET
304
20.165.94.63:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5568
SearchApp.exe
GET
200
52.123.129.254:443
https://dual-s-ring.msedge.net/apc/trans.gif?730db4c7683f3b03fe2b0b1729fbac00
US
image
43 b
unknown
5568
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEA8fFXWCzc0zc0vcX82UGjM%3D
US
binary
313 b
whitelisted
5920
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
US
binary
409 b
whitelisted
5568
SearchApp.exe
GET
200
150.171.109.194:443
https://mr-prod-t.msedge.net/apc/trans.gif?83d83374430cd6a8a7a1c61c32826641
US
image
43 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3344
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
6200
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3344
svchost.exe
23.216.77.6:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
5568
SearchApp.exe
2.16.241.207:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
5568
SearchApp.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
5568
SearchApp.exe
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3412
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
google.com
  • 142.251.208.14
whitelisted
self.events.data.microsoft.com
  • 52.168.117.169
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.22
  • 23.216.77.13
  • 23.216.77.8
  • 23.216.77.20
  • 23.216.77.37
  • 23.216.77.18
  • 23.216.77.26
  • 23.216.77.12
whitelisted
www.bing.com
  • 2.16.241.207
  • 2.16.241.205
  • 2.16.241.218
  • 2.16.241.222
  • 2.23.227.208
  • 2.23.227.221
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.0
  • 40.126.31.73
  • 40.126.31.131
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.1
  • 40.126.31.71
whitelisted
slscr.update.microsoft.com
  • 20.165.94.63
whitelisted

Threats

PID
Process
Class
Message
5568
SearchApp.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
No debug info