download:

/SpotX-Official/spotx-official.github.io/main/run.ps1

Full analysis: https://app.any.run/tasks/071575cc-f32b-4b1c-9f91-85390bd50d4e
Verdict: Malicious activity
Analysis date: March 24, 2025, 21:22:42
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
github
arch-html
arch-scr
Indicators:
MIME: text/plain
File info: ASCII text
MD5:

4D7BA313A8E7F3856DBBC16A69DA43A6

SHA1:

8A92A93B9A5D743CB5BF8A6B2C4ACC24BDBA875C

SHA256:

A0BE3873AAAC715D1C6F083DF7BA1C6AF062E9076507CB542279D17A14BA55A3

SSDEEP:

24:g5eIfX0sRzfr7MGjYLz/XCs3/YbxG14/dTIdzAvvrBfI9hk:gI9UroVCsQbogjve9hk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 4784)
    • Uses AES cipher (POWERSHELL)

      • powershell.exe (PID: 4784)
    • Dynamically loads an assembly (POWERSHELL)

      • powershell.exe (PID: 4784)
  • SUSPICIOUS

    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 4784)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 7920)
    • Process drops legitimate windows executable

      • SpotifySetup.exe (PID: 8000)
    • Executable content was dropped or overwritten

      • SpotifySetup.exe (PID: 8000)
    • Converts a specified value to a byte (POWERSHELL)

      • powershell.exe (PID: 4784)
    • Reverses array data (POWERSHELL)

      • powershell.exe (PID: 4784)
    • Uses sleep to delay execution (POWERSHELL)

      • powershell.exe (PID: 4784)
    • Reads security settings of Internet Explorer

      • Spotify.exe (PID: 5428)
    • Application launched itself

      • Spotify.exe (PID: 5428)
    • The process checks if it is being run in the virtual environment

      • Spotify.exe (PID: 5428)
    • Creates a software uninstall entry

      • SpotifySetup.exe (PID: 8000)
  • INFO

    • Disables trace logs

      • powershell.exe (PID: 4784)
    • Execution of CURL command

      • powershell.exe (PID: 4784)
    • Reads the computer name

      • curl.exe (PID: 7600)
      • curl.exe (PID: 7644)
      • SpotifySetup.exe (PID: 8000)
      • Spotify.exe (PID: 5428)
      • Spotify.exe (PID: 2772)
      • Spotify.exe (PID: 7948)
    • Checks supported languages

      • curl.exe (PID: 7600)
      • curl.exe (PID: 7576)
      • curl.exe (PID: 7644)
      • SpotifySetup.exe (PID: 8000)
      • Spotify.exe (PID: 8144)
      • Spotify.exe (PID: 5428)
      • Spotify.exe (PID: 2772)
      • Spotify.exe (PID: 1600)
      • Spotify.exe (PID: 6964)
      • Spotify.exe (PID: 7588)
      • Spotify.exe (PID: 6676)
      • Spotify.exe (PID: 7948)
    • Checks proxy server information

      • powershell.exe (PID: 4784)
      • Spotify.exe (PID: 5428)
    • Create files in a temporary directory

      • curl.exe (PID: 7644)
      • Spotify.exe (PID: 5428)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 7956)
    • Creates files or folders in the user directory

      • SpotifySetup.exe (PID: 8000)
      • Spotify.exe (PID: 2772)
      • Spotify.exe (PID: 5428)
    • Uses string split method (POWERSHELL)

      • powershell.exe (PID: 4784)
    • Converts byte array into ASCII string (POWERSHELL)

      • powershell.exe (PID: 4784)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 4784)
    • Manual execution by a user

      • Spotify.exe (PID: 5428)
    • Reads the software policy settings

      • slui.exe (PID: 5504)
      • Spotify.exe (PID: 5428)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 4784)
    • Process checks computer location settings

      • Spotify.exe (PID: 5428)
      • Spotify.exe (PID: 6964)
    • Reads the machine GUID from the registry

      • Spotify.exe (PID: 5428)
    • Checks whether the specified file exists (POWERSHELL)

      • powershell.exe (PID: 4784)
    • The sample compiled with english language support

      • SpotifySetup.exe (PID: 8000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
160
Monitored processes
19
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start powershell.exe conhost.exe no specs sppextcomobj.exe no specs slui.exe curl.exe no specs curl.exe curl.exe explorer.exe no specs explorer.exe no specs spotifysetup.exe spotify.exe no specs slui.exe no specs spotify.exe spotify.exe no specs spotify.exe no specs spotify.exe spotify.exe no specs spotify.exe no specs spotify.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1600"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.60.564" --field-trial-handle=2432,i,10117358430685699952,395013155946762712,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2528 --mojo-platform-channel-handle=64 /prefetch:8C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Exit code:
0
Version:
1.2.60.564
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
1804C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
2600\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2772"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.60.564" --field-trial-handle=2300,i,10117358430685699952,395013155946762712,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2080 --mojo-platform-channel-handle=2220 /prefetch:3C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
Spotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Exit code:
0
Version:
1.2.60.564
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4784"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ep bypass C:\Users\admin\AppData\Local\Temp\run.ps1C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5428"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
explorer.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Exit code:
0
Version:
1.2.60.564
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5504"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6676"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=gpu-process --string-annotations=is-enterprise-managed=no --start-stack-profiler --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.60.564" --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=1976,i,10117358430685699952,395013155946762712,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=2004 --mojo-platform-channel-handle=1980 /prefetch:2C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Exit code:
0
Version:
1.2.60.564
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6964"C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe" --type=renderer --string-annotations=is-enterprise-managed=no --user-data-dir="C:\Users\admin\AppData\Local\Spotify" --log-severity=disable --user-agent-product="Chrome/131.0.6778.109 Spotify/1.2.60.564" --autoplay-policy=no-user-gesture-required --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=5612,i,10117358430685699952,395013155946762712,262144 --disable-features=BackForwardCache,PartitionAllocDanglingPtr,PartitionAllocUnretainedDanglingPtr --variations-seed-version --enable-logging=handle --log-file=5176 --mojo-platform-channel-handle=5172 /prefetch:1C:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotify.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
LOW
Description:
Spotify
Exit code:
0
Version:
1.2.60.564
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
7084C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
13 787
Read events
13 723
Write events
59
Delete events
5

Modification events

(PID) Process:(8000) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Spotify Web Helper
Value:
(PID) Process:(8000) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
(PID) Process:(8000) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayName
Value:
Spotify
(PID) Process:(8000) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayVersion
Value:
1.2.60.564.gcc6305cb
(PID) Process:(8000) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:Version
Value:
1.2.60.564.gcc6305cb
(PID) Process:(8000) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallDate
Value:
20250324
(PID) Process:(8000) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\Spotify
(PID) Process:(8000) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:NoModify
Value:
1
(PID) Process:(8000) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:NoRepair
Value:
1
(PID) Process:(8000) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:Publisher
Value:
Spotify AB
Executable files
18
Suspicious files
303
Text files
44
Unknown types
2

Dropped files

PID
Process
Filename
Type
7644curl.exeC:\Users\admin\AppData\Local\Temp\SpotX_Temp-2025-03-24_21-22-56\SpotifySetup.exe
MD5:
SHA256:
4784powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\8IQ7CBN33S86CYSMJ9D4.tempbinary
MD5:2C233AD94D40E31CCE89515B86639D2F
SHA256:CE2A3569D3F5ECD79BAC160E876A068F9ADAE88824F4C9B3A3119FB738132B30
8000SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_8000_16_~binary
MD5:017ACFCF49364437E9349E284265E6FA
SHA256:ABA11A95E4C38E157D7217F026EB53A3A3611BDB5702839A5BDF403EACB5534C
8000SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_8000_26_~binary
MD5:7B11CE2276F96AD7804DE44FB93A1485
SHA256:E1CC55FC4C51BB8E45AC2D8EEE4CBBC0FE8061C3800AA3A4B022E7CE7C865EAF
8000SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_8000_14_~binary
MD5:E3E38A1F6B5D15394575411BF5FF6D03
SHA256:C8C67EC091F94E8EE3FDECB97959BA4A0306BFCA03622F705FC2A9829CF98559
8000SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_8000_20_~binary
MD5:53415E9C671683BFF6B82551331091EF
SHA256:874BBEFA5E1664B99807B1BEA3736B904DCB936A53B99E11CF69B7FB9EB1289A
8000SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_8000_8_~binary
MD5:F774C61DBF4CBF171DFBD8B6F5EB152B
SHA256:EB76D12996E22D3EB5D429B9BBAAF7FF9BCEEA924A480BD589ED157A583E93D5
8000SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_8000_12_~binary
MD5:84090FE7F890D22FCE237E9E227CD2A6
SHA256:93B44D4FE094C4CF35CF318389601FFAD29CA24B1C27C113E23F26E79DB18002
8000SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_8000_28_~binary
MD5:89A92E8FCEF0300DA43DD0BD238CDDC5
SHA256:485887327BAEAA22FB93E352A3C8C1A03C2CEEA13F76DA459F12AFBE1C29E827
8000SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_8000_24_~binary
MD5:31FF03AADF269B3F6BC8DB713D1EF516
SHA256:ADE0AC010BAAD6BDDB1C9DCE56BFB8B53E1406D60DB7B4C9B6999827D5E38FC8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
39
DNS requests
44
Threats
16

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.194:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.48.23.194:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4008
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7808
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7808
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5428
Spotify.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.194:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.48.23.194:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4784
powershell.exe
185.199.110.133:443
raw.githubusercontent.com
FASTLY
US
whitelisted
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 23.48.23.194
  • 23.48.23.191
  • 23.48.23.145
  • 23.48.23.146
  • 23.48.23.139
  • 23.48.23.134
  • 23.48.23.192
  • 23.48.23.137
  • 23.48.23.141
whitelisted
raw.githubusercontent.com
  • 185.199.110.133
  • 185.199.111.133
  • 185.199.108.133
  • 185.199.109.133
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
login.live.com
  • 40.126.31.71
  • 20.190.159.128
  • 40.126.31.3
  • 20.190.159.4
  • 20.190.159.73
  • 40.126.31.2
  • 20.190.159.71
  • 40.126.31.129
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 2.23.77.188
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
download.scdn.co
  • 199.232.214.248
  • 199.232.210.248
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
2772
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2772
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2772
Spotify.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
2772
Spotify.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
2772
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2772
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2772
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2772
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2772
Spotify.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info