File name:

StartIsBack++_v2.9.20_patched.exe

Full analysis: https://app.any.run/tasks/1c9309f9-f660-455d-8474-6d1aa20d027e
Verdict: Malicious activity
Analysis date: March 24, 2025, 12:41:46
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

0EB73314DF184EE74B474249783AC8F7

SHA1:

1BD8E0CB15DEAE490A5275AA733D2569C2EC9888

SHA256:

A7BBC17D33FCED6EFC4E56FBEB6DA557C6B5A5E81FEEC634105B31D6E2BE67FE

SSDEEP:

49152:rl5geQnKgOtT/PT4JT4PkTzDZ/GCEGRSdbvpvECsQK14rkjdmlnYIgBwdkArXg31:Z5k2DPsRjZ+C/RSdaQwDjUlDiBbHHgVE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • StartIsBack++_v2.9.20_patched.exe (PID: 2384)
      • StartIsBackCfg.exe (PID: 1852)
    • Executable content was dropped or overwritten

      • StartIsBack++_v2.9.20_patched.exe (PID: 2384)
      • StartIsBackCfg.exe (PID: 1852)
    • Uses TASKKILL.EXE to kill process

      • StartIsBackCfg.exe (PID: 1852)
    • Creates a software uninstall entry

      • StartIsBackCfg.exe (PID: 1852)
    • Creates/Modifies COM task schedule object

      • StartIsBackCfg.exe (PID: 1852)
    • Changes default file association

      • StartIsBackCfg.exe (PID: 1852)
    • Reads the date of Windows installation

      • StartMenuExperienceHost.exe (PID: 6756)
    • Application launched itself

      • StartIsBackCfg.exe (PID: 6120)
    • Write to the desktop.ini file (may be used to cloak folders)

      • StartScreen.exe (PID: 7624)
  • INFO

    • Reads the computer name

      • StartIsBack++_v2.9.20_patched.exe (PID: 2384)
      • StartIsBackCfg.exe (PID: 1852)
      • StartScreen.exe (PID: 2088)
    • Checks supported languages

      • StartIsBack++_v2.9.20_patched.exe (PID: 2384)
      • StartIsBackCfg.exe (PID: 1852)
      • StartMenuExperienceHost.exe (PID: 6756)
      • SearchApp.exe (PID: 6924)
      • TextInputHost.exe (PID: 4616)
      • StartIsBackCfg.exe (PID: 7196)
      • StartScreen.exe (PID: 4744)
    • The sample compiled with english language support

      • StartIsBack++_v2.9.20_patched.exe (PID: 2384)
      • StartIsBackCfg.exe (PID: 1852)
    • Create files in a temporary directory

      • StartIsBack++_v2.9.20_patched.exe (PID: 2384)
      • StartScreen.exe (PID: 7624)
    • The sample compiled with russian language support

      • StartIsBack++_v2.9.20_patched.exe (PID: 2384)
      • StartIsBackCfg.exe (PID: 1852)
    • Creates files or folders in the user directory

      • StartIsBackCfg.exe (PID: 1852)
    • Process checks computer location settings

      • StartIsBack++_v2.9.20_patched.exe (PID: 2384)
      • StartMenuExperienceHost.exe (PID: 6756)
      • SearchApp.exe (PID: 6924)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4640)
      • BackgroundTransferHost.exe (PID: 7096)
    • Checks proxy server information

      • SearchApp.exe (PID: 6924)
    • Reads the machine GUID from the registry

      • SearchApp.exe (PID: 6924)
    • Reads the software policy settings

      • SearchApp.exe (PID: 6924)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:05:08 19:27:11+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 32256
InitializedDataSize: 55808
UninitializedDataSize: -
EntryPoint: 0x1741
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1000
ProductVersionNumber: 1.0.0.1000
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: www.startisback.com
FileDescription: StartIsBack++ setup SFX
FileVersion: 1.0.0
LegalCopyright: Copyright (C) 2012-2017, Tihiy
OriginalFileName: 7-zip SfxSetup.exe
ProductName: StartIsBack
ProductVersion: 1.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
171
Monitored processes
35
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start startisback++_v2.9.20_patched.exe startisbackcfg.exe sppextcomobj.exe no specs slui.exe no specs startscreen.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs explorer.exe no specs startscreen.exe no specs textinputhost.exe no specs startmenuexperiencehost.exe no specs tiworker.exe no specs searchapp.exe startisbackcfg.exe no specs backgroundtransferhost.exe no specs mobsync.exe no specs backgroundtransferhost.exe startisbackcfg.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs startscreen.exe no specs startscreen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
552\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
896"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1852"C:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\StartIsBackCfg.exe" /install C:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\StartIsBackCfg.exe
StartIsBack++_v2.9.20_patched.exe
User:
admin
Integrity Level:
MEDIUM
Description:
StartIsBack configuration
Exit code:
0
Version:
5.9.20.3594
Modules
Images
c:\users\admin\appdata\local\temp\sibsfx.0d00a950\startisbackcfg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2088"C:\Users\admin\AppData\Local\StartIsBack\StartScreen.exe" /unpinC:\Users\admin\AppData\Local\StartIsBack\StartScreen.exeexplorer.exe
User:
admin
Company:
www.startisback.com
Integrity Level:
MEDIUM
Description:
StartIsBack Helper Tool
Exit code:
0
Version:
5.9.8
Modules
Images
c:\users\admin\appdata\local\startisback\startscreen.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\combase.dll
c:\windows\syswow64\ucrtbase.dll
2384"C:\Users\admin\AppData\Local\Temp\StartIsBack++_v2.9.20_patched.exe" C:\Users\admin\AppData\Local\Temp\StartIsBack++_v2.9.20_patched.exe
explorer.exe
User:
admin
Company:
www.startisback.com
Integrity Level:
MEDIUM
Description:
StartIsBack++ setup SFX
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\startisback++_v2.9.20_patched.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4236\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4256C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -EmbeddingC:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Modules Installer Worker
Version:
10.0.19041.3989 (WinBuild.160101.0800)
Modules
Images
c:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\tiworker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
4400\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4556taskkill.exe /F /IM explorer*C:\Windows\SysWOW64\taskkill.exeStartIsBackCfg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4616"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
123.26505.0.0
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
Total events
32 749
Read events
32 269
Write events
447
Delete events
33

Modification events

(PID) Process:(1852) StartIsBackCfg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\StartIsBack\
(PID) Process:(1852) StartIsBackCfg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack
Operation:writeName:Publisher
Value:
startisback.com
(PID) Process:(1852) StartIsBackCfg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack
Operation:writeName:NoModify
Value:
1
(PID) Process:(1852) StartIsBackCfg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack
Operation:writeName:NoRepair
Value:
1
(PID) Process:(1852) StartIsBackCfg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack
Operation:writeName:DisplayName
Value:
StartIsBack++
(PID) Process:(1852) StartIsBackCfg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\StartIsBack\StartIsBackCfg.exe,0
(PID) Process:(1852) StartIsBackCfg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack
Operation:writeName:DisplayVersion
Value:
2.9.20
(PID) Process:(1852) StartIsBackCfg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack
Operation:writeName:UninstallString
Value:
C:\Users\admin\AppData\Local\StartIsBack\StartIsBackCfg.exe /uninstall
(PID) Process:(1852) StartIsBackCfg.exeKey:HKEY_CLASSES_ROOT\CLSID\{c71c41f1-ddad-42dc-a8fc-f5bfc61df958}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1852) StartIsBackCfg.exeKey:HKEY_CLASSES_ROOT\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c9}
Operation:writeName:ImplementsVerbs
Value:
startpin;startunpin
Executable files
23
Suspicious files
61
Text files
101
Unknown types
0

Dropped files

PID
Process
Filename
Type
2384StartIsBack++_v2.9.20_patched.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\Orbs\Shamrock.orbexecutable
MD5:EF55E07E1A2E47BB2BB749046CD150B2
SHA256:1A8DAC51758C66A1BB03FBC227B5EDB52EF7379FA3603B62EB3307005D06C9B5
2384StartIsBack++_v2.9.20_patched.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\Styles\Plain10.msstylesexecutable
MD5:A69385279536210958FB9C86CAB229D6
SHA256:3955FC60D3B7C4A1BADD831FDE82269261407CF9D459C65B429E8ABC769ADEED
1852StartIsBackCfg.exeC:\Users\admin\AppData\Local\StartIsBack\Orbs\StartIsBack_Ei8htOrb_v2_by_PainteR.bmpimage
MD5:641328C75E6B117545211DB22DAFCAA0
SHA256:76A72C9AD77843B58223DD588483AC1265A31C15AAEB47EE66D1925DE787644B
1852StartIsBackCfg.exeC:\Users\admin\AppData\Local\StartIsBack\StartIsBackCfg.exeexecutable
MD5:C392E6AA793E52A0AECA50A9F2A3610B
SHA256:39883CB9FA44F6E0FC09E539F23047E36C8DCDDB356CD26DEED8A8E9F495F077
1852StartIsBackCfg.exeC:\Users\admin\AppData\Local\StartIsBack\Orbs\Shamrock.orbexecutable
MD5:EF55E07E1A2E47BB2BB749046CD150B2
SHA256:1A8DAC51758C66A1BB03FBC227B5EDB52EF7379FA3603B62EB3307005D06C9B5
1852StartIsBackCfg.exeC:\Users\admin\AppData\Local\StartIsBack\StartScreen.exeexecutable
MD5:A2D6E2201BE02973328038457AA64BBA
SHA256:F4E76ABF0DF055FAE97863708412773B51197BAE0DDD9692A9509E824D847DF0
2384StartIsBack++_v2.9.20_patched.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\StartIsBack32.dllexecutable
MD5:4795F1E028E7AB6368FA64DCCD451671
SHA256:5ED82AA747C6F2A7164CC5DA5449A0B094DE27EEF3BE51E496DBCD9B367D9022
2384StartIsBack++_v2.9.20_patched.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\Styles\Windows 7.msstylesexecutable
MD5:B6A2892C151CCD59D0B4C4C1777DAAC5
SHA256:0C6E681A8091BA888E58473CCEEAE590C88A405BB30DCB344F940ACF27290CE8
1852StartIsBackCfg.exeC:\Users\admin\AppData\Local\StartIsBack\StartIsBack32.dllexecutable
MD5:4795F1E028E7AB6368FA64DCCD451671
SHA256:5ED82AA747C6F2A7164CC5DA5449A0B094DE27EEF3BE51E496DBCD9B367D9022
2384StartIsBack++_v2.9.20_patched.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\StartIsBack64.dllexecutable
MD5:BED4FFEF522B5B10F2605FF01EE3C288
SHA256:125BC1C4EECD6724BB48A0562E0E9CF9322911E3E9517408D9467D903F9232CA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
35
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
744
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7096
BackgroundTransferHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5024
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5024
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2104
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2112
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
744
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.32
  • 2.16.164.40
  • 2.16.164.18
  • 2.16.164.51
  • 2.16.164.9
  • 2.16.164.120
whitelisted
login.live.com
  • 40.126.32.136
  • 20.190.160.65
  • 40.126.32.68
  • 20.190.160.132
  • 20.190.160.14
  • 20.190.160.2
  • 20.190.160.4
  • 40.126.32.76
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
www.bing.com
  • 2.19.96.130
  • 2.19.96.104
  • 2.19.96.115
  • 2.19.96.90
  • 2.19.96.9
  • 2.19.96.11
  • 2.19.96.8
  • 2.19.96.82
  • 2.19.96.19
whitelisted
th.bing.com
  • 2.23.227.215
  • 2.23.227.221
  • 2.23.227.208
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted

Threats

No threats detected
No debug info