File name:

www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe

Full analysis: https://app.any.run/tasks/651f821d-b1c6-4362-b871-a045fddeeb5e
Verdict: Malicious activity
Analysis date: October 31, 2024, 10:55:02
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
lua
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

4A61D021B6849C990480D24A3F2E98E4

SHA1:

563B367A23DAE6CD54FB34D09908739E21F86E9E

SHA256:

9DED1CB75921759C387C43C7C732259B21602A36D77ECD90DFAC97D33966C7B6

SSDEEP:

98304:5r1wE4M+LVg8nJb3DmrrGjAkXoSeMCGr3RgeD5K9xoQHmW7sH1nOcsEdzJXgyeAb:UfKEEK5cb8wYdx8/gYa17

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executable content was dropped or overwritten

      • EXCEL.EXE (PID: 5496)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe (PID: 6340)
    • Executable content was dropped or overwritten

      • www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe (PID: 6340)
      • irsetup.exe (PID: 4692)
      • vstor40_x64.exe (PID: 4476)
    • Reads security settings of Internet Explorer

      • www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe (PID: 6340)
      • install.exe (PID: 7136)
    • Reads the Windows owner or organization settings

      • irsetup.exe (PID: 4692)
    • Process drops legitimate windows executable

      • irsetup.exe (PID: 4692)
      • vstor40_x64.exe (PID: 4476)
      • msiexec.exe (PID: 2588)
      • EXCEL.EXE (PID: 5496)
    • Starts a Microsoft application from unusual location

      • vstor40_x64.exe (PID: 4476)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 2588)
    • Checks Windows Trust Settings

      • install.exe (PID: 7136)
  • INFO

    • Create files in a temporary directory

      • www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe (PID: 6340)
      • irsetup.exe (PID: 4692)
      • install.exe (PID: 7136)
    • Reads the computer name

      • www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe (PID: 6340)
      • irsetup.exe (PID: 4692)
      • vstor40_x64.exe (PID: 4476)
      • install.exe (PID: 7136)
    • Checks supported languages

      • www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe (PID: 6340)
      • irsetup.exe (PID: 4692)
      • vstor40_x64.exe (PID: 4476)
      • install.exe (PID: 7136)
    • Process checks computer location settings

      • www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe (PID: 6340)
    • The process uses the downloaded file

      • www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe (PID: 6340)
    • Reads the machine GUID from the registry

      • vstor40_x64.exe (PID: 4476)
      • install.exe (PID: 7136)
    • Reads the software policy settings

      • install.exe (PID: 7136)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2588)
    • Application launched itself

      • msiexec.exe (PID: 2588)
    • UPX packer has been detected

      • irsetup.exe (PID: 4692)
    • Manual execution by a user

      • rundll32.exe (PID: 2128)
      • rundll32.exe (PID: 3916)
      • uninstall.exe (PID: 6896)
      • uninstall.exe (PID: 2864)
      • rundll32.exe (PID: 4164)
      • EXCEL.EXE (PID: 5496)
    • The process uses Lua

      • irsetup.exe (PID: 4692)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | MS generic-sfx Cabinet File Unpacker (32/64bit MSCFU) (82.5)
.exe | Win32 Executable MS Visual C++ (generic) (7.3)
.exe | Win64 Executable (generic) (6.5)
.dll | Win32 Dynamic Link Library (generic) (1.5)
.exe | Win32 Executable (generic) (1)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:08:28 18:19:40+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 10
CodeSize: 26112
InitializedDataSize: 50688
UninitializedDataSize: -
EntryPoint: 0x301c
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 4.5.0.0
ProductVersionNumber: 4.5.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
Comments: FIGEN YAZILIM EVI TIC. LTD. STI.
CompanyName: FIGEN YAZILIM EVI TIC. LTD. STI.
FileDescription: Poctgoyercini Excel Eklentisi Setup
FileVersion: 4.5.0.0
InternalName: sf_rt
LegalCopyright: Figensoft Copyright © 2011 - 2023
LegalTrademarks: Poctgoyercini Excel Eklentisi Setup
OriginalFileName: suf_launch.exe
ProductName: Poctgoyercini Excel Eklentisi
ProductVersion: 4.5.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
164
Monitored processes
28
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start www.poctgoyercini.com_sms_excel_addin_v6.50.exe THREAT irsetup.exe vstor40_x64.exe install.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs addinutil.exe no specs conhost.exe no specs addinutil.exe no specs conhost.exe no specs rundll32.exe no specs rundll32.exe no specs vstoinstaller.exe rundll32.exe no specs rundll32.exe no specs vstoinstaller.exe uninstall.exe no specs uninstall.exe rundll32.exe no specs rundll32.exe no specs vstoinstaller.exe excel.exe splwow64.exe no specs www.poctgoyercini.com_sms_excel_addin_v6.50.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1748\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAddInUtil.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1768VSTOInstaller.exe /install file:///C:/Users/admin/Desktop/SMSEXCELADDIN_PG.vstoC:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual Studio Tools for Office Solution Installer
Exit code:
4294967093
Version:
10.0.60828.0 built by: VSTO_Rel
Modules
Images
c:\program files\common files\microsoft shared\vsto\10.0\vstoinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2128"rundll32.exe" "c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\vstoee.dll",InstallVstoSolution C:\Users\admin\Desktop\SMSEXCELADDIN_PG.vstoC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
2224"c:\WINDOWS\Microsoft.NET\Framework64\v3.5\addinutil.exe" -AddInRoot:"c:\Program Files (x86)\Common Files\Microsoft Shared\VSTA\AppInfoDocument\." -RebuildC:\Windows\Microsoft.NET\Framework64\v3.5\AddInUtil.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
AddInUtil.exe
Exit code:
0
Version:
3.5.30729.9141 built by: WinRelRS6
Modules
Images
c:\windows\microsoft.net\framework64\v3.5\addinutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2588C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2864"C:\Users\admin\Desktop\uninstall.exe" C:\Users\admin\Desktop\uninstall.exe
explorer.exe
User:
admin
Company:
Indigo Rose Corporation
Integrity Level:
HIGH
Description:
Setup Application
Exit code:
12
Version:
9.6.0.1
Modules
Images
c:\users\admin\desktop\uninstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3676"C:\Users\admin\AppData\Local\Temp\www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe" C:\Users\admin\AppData\Local\Temp\www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exeexplorer.exe
User:
admin
Company:
FIGEN YAZILIM EVI TIC. LTD. STI.
Integrity Level:
MEDIUM
Description:
Poctgoyercini Excel Eklentisi Setup
Exit code:
3221226540
Version:
4.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\www.poctgoyercini.com_sms_excel_addin_v6.50.exe
c:\windows\system32\ntdll.dll
3832c:\Windows\System32\MsiExec.exe -Embedding 64E5E733B46AE9A7206A4D7594B86822 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3832"rundll32.exe" "c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\vstoee.dll",InstallVstoSolution C:\Users\admin\Desktop\SMSEXCELADDIN_PG.vstoC:\Windows\SysWOW64\rundll32.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3916"rundll32.exe" "c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\vstoee.dll",InstallVstoSolution C:\Users\admin\Desktop\SMSEXCELADDIN_PG.vstoC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
Total events
38 478
Read events
37 196
Write events
1 266
Delete events
16

Modification events

(PID) Process:(2588) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
1C0A0000533EF764832BDB01
(PID) Process:(2588) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
C029C4498550316B765E4C497D753651583F7AAF2C25D5716343A476AEED45A7
(PID) Process:(2588) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2588) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:c:\Config.Msi\
Value:
(PID) Process:(2588) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:c:\Config.Msi\90aa4.rbs
Value:
31140739
(PID) Process:(2588) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:c:\Config.Msi\90aa4.rbsLow
Value:
(PID) Process:(2588) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACD7412E4BDD5424193BDEE5BBA2636E
Operation:writeName:6EA0063C0A397BD37BAA54DB851F335B
Value:
02:\SOFTWARE\Microsoft\VSTA Runtime Setup\v10.0.31119\Install
(PID) Process:(2588) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E4BD88386A69FA498F277ECC214E817
Operation:writeName:6EA0063C0A397BD37BAA54DB851F335B
Value:
c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\msvcr90.dll
(PID) Process:(2588) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9BA4899E4018DB34F88F23D4D8A68F69
Operation:writeName:6EA0063C0A397BD37BAA54DB851F335B
Value:
c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\msvcp90.dll
(PID) Process:(2588) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F82E61F66BE0564C937495374CFBBE8
Operation:writeName:6EA0063C0A397BD37BAA54DB851F335B
Value:
c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\msvcm90.dll
Executable files
206
Suspicious files
35
Text files
87
Unknown types
7

Dropped files

PID
Process
Filename
Type
6340www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exeexecutable
MD5:6CCBB32F704537B2A48E7F19306D5A8F
SHA256:A412F87C3A56AF9CACFF6B216EA95E68A630D1652CE1FFEF30AD6E32D05853CB
4692irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPGimage
MD5:0CBE6F2BD01D8D0EF2E7E0EE70671E37
SHA256:C14D3E7D5A3AD622021F54B2B9049AD1DE78AB3F44C03964B62ADEF8D64F4D64
4476vstor40_x64.exeC:\4a23dfd79856504f12fb30\vstor40_x64.cabcompressed
MD5:B0C2E188C1B05FFAEEEDBEA1F5D2FAB2
SHA256:7EC18C4BA95412F62FDA3A7D9AED83B8F4898AB5B93A0D5A55160C0FD03A8DF7
4692irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\office_tool\vstor40_x86.exeexecutable
MD5:7A57B77C2CF1F22C408B32AA1D54C2C1
SHA256:681BB354DD5476F63258026A2CEE9F6A68C9E4AB27DBFA029456620F212E4E1D
4692irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPGimage
MD5:5E088935115FCA3BD9772E7A521521B1
SHA256:E93314AF64ACBE0915093BE1017FA931AA6420E18C89AA9ADFF699D3A9BE546F
4476vstor40_x64.exeC:\4a23dfd79856504f12fb30\vstor40_x64.msiexecutable
MD5:D873488D7D417B8310B3519B9651030F
SHA256:AE0F8D05580EB085FA9A8C2DCB6FAD0048EF492C0CD278217FD8D4CB99E48556
4692irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\office_tool\vstor40_x64.exeexecutable
MD5:69C7F5486BA44B1600B3DC9F25347242
SHA256:75219EA8DEA06F15BE5830761C2381FF17B841FAB3B4BD4A6F04D3C5D8DE4DC6
4476vstor40_x64.exeC:\4a23dfd79856504f12fb30\install.exeexecutable
MD5:D633FD62D38A9F2A656329E7CF272F88
SHA256:571BDBB819EE8F1FFCB7879441CD5AF2B90EF9A62CB60A5A2BCC7BA73514CF03
4476vstor40_x64.exeC:\4a23dfd79856504f12fb30\eula.1033.txttext
MD5:BE6142E24326C7E3F1030B95BBA80D1B
SHA256:030B04CE7FADC9DA232BE9A76BF35D9ECCCE7EB8C37C5E238095D71397A5AFD7
4692irsetup.exeC:\Users\admin\AppData\Local\Temp\www.PoctGoyercini.com SMS EXCEL ADDIN Setup Log.txttext
MD5:04D3D8675F56AE4A8FC6D5A71E960729
SHA256:70B56E2C24D2AC2311DEE7A3F728C1A94A0E6D971D2CB0549C4BF37C24752349
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
63
DNS requests
38
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.32.185.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4004
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7136
install.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/CSPCA.crl
unknown
whitelisted
3860
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3676
SIHClient.exe
GET
200
23.32.185.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1172
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5488
MoUsoCoreWorker.exe
23.32.185.131:80
www.microsoft.com
AKAMAI-AS
BR
whitelisted
2.23.209.168:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4004
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.164.106
  • 2.16.164.9
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 23.32.185.131
whitelisted
www.bing.com
  • 2.23.209.168
  • 2.23.209.176
  • 2.23.209.183
  • 2.23.209.167
  • 2.23.209.162
  • 2.23.209.178
  • 2.23.209.173
  • 2.23.209.177
  • 2.23.209.181
  • 104.126.37.186
  • 104.126.37.137
  • 104.126.37.131
  • 104.126.37.176
  • 104.126.37.177
  • 104.126.37.171
  • 104.126.37.123
  • 104.126.37.128
  • 104.126.37.130
whitelisted
google.com
  • 142.250.186.78
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.2
  • 40.126.31.71
  • 20.190.159.0
  • 20.190.159.4
  • 20.190.159.71
  • 20.190.159.73
  • 40.126.31.73
whitelisted
th.bing.com
  • 2.23.209.185
  • 2.23.209.181
  • 2.23.209.180
  • 2.23.209.178
  • 2.23.209.175
  • 2.23.209.176
  • 2.23.209.183
  • 2.23.209.179
  • 2.23.209.177
  • 2.23.209.168
  • 2.23.209.173
  • 2.23.209.160
  • 2.23.209.156
  • 2.23.209.167
  • 2.23.209.162
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted

Threats

No threats detected
Process
Message
VSTOInstaller.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
VSTOInstaller.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
VSTOInstaller.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
VSTOInstaller.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
VSTOInstaller.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
VSTOInstaller.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
VSTOInstaller.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
VSTOInstaller.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
VSTOInstaller.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230