File name:

hvnc (2).zip

Full analysis: https://app.any.run/tasks/563172f1-416a-4a43-a339-19622724c65b
Verdict: Malicious activity
Analysis date: April 07, 2026, 00:44:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
crypto-regex
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

C12817DF9E49EA556D6E842D65058786

SHA1:

FE2FCA13519F255129A0B97C088DB43314470A56

SHA256:

A8CF1517527B2EBD77F18AF4D85B82A7D989E0EA05DC0536A980C8D06E9DA0A6

SSDEEP:

49152:Ko7vLOJqMcfDgiIuPL2SkBBojz1hbQCjm41GSS9sqHE9+xKxqelyCJ/KIGalOUEf:X7vLTMcf52d2P1hbxrGp1HulyCJu9uwJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • Builder.exe (PID: 7196)
    • Adds extension to the Windows Defender exclusion list

      • Builder.exe (PID: 7196)
      • powershell.exe (PID: 6672)
    • Changes Windows Defender settings

      • Builder.exe (PID: 7196)
      • powershell.exe (PID: 6672)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • Builder.exe (PID: 7196)
    • Starts POWERSHELL.EXE for commands execution

      • Builder.exe (PID: 7196)
      • powershell.exe (PID: 6672)
    • Script adds exclusion extension to Windows Defender

      • Builder.exe (PID: 7196)
      • powershell.exe (PID: 6672)
    • Application launched itself

      • powershell.exe (PID: 6672)
    • Uses REG/REGEDIT.EXE to modify or delete registry entries

      • powershell.exe (PID: 6672)
    • Found regular expressions for crypto-addresses (YARA)

      • Builder.exe (PID: 7196)
  • INFO

    • Creates files or folders in the user directory

      • Builder.exe (PID: 7196)
    • Generic archive extractor

      • WinRAR.exe (PID: 7804)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7804)
      • Builder.exe (PID: 7196)
    • Reads the computer name

      • tvnviewer.exe (PID: 2676)
      • Builder.exe (PID: 7196)
    • Checks supported languages

      • tvnviewer.exe (PID: 2676)
      • Builder.exe (PID: 7196)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 7804)
    • Launching a file from the Startup directory

      • Builder.exe (PID: 7196)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7804)
    • Process checks computer location settings

      • Builder.exe (PID: 7196)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 1280)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 1280)
    • Create files in a temporary directory

      • Builder.exe (PID: 7196)
    • There is functionality for taking screenshot (YARA)

      • tvnviewer.exe (PID: 2676)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2022:02:17 12:12:48
ZipCRC: 0x18933401
ZipCompressedSize: 332062
ZipUncompressedSize: 646384
ZipFileName: plink.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1280"C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe" -command Add-MpPreference -ExclusionExtension .exeC:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\oleaut32.dll
1780"C:\WINDOWS\system32\reg.exe" add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations /v LowRiskFileTypes /t REG_SZ /d .exe /fC:\Windows\SysWOW64\reg.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\advapi32.dll
2676"C:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34287\tvnviewer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34287\tvnviewer.exeWinRAR.exe
User:
admin
Company:
GlavSoft LLC.
Integrity Level:
MEDIUM
Description:
TightVNC Viewer
Version:
2, 8, 63, 0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7804.34287\tvnviewer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4112\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6672"C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" powershell.exe -command Add-MpPreference -ExclusionExtension .exe; reg add 'HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments' /v 'SaveZoneInformation' /t REG_DWORD /d 1 /f; reg add 'HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations' /v 'LowRiskFileTypes' /t REG_SZ /d '.exe' /f; reg add 'HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System' /v 'PromptOnSecureDesktop' /t REG_DWORD /d 0 /fC:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Builder.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
7196"C:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34371\Builder.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34371\Builder.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7804.34371\builder.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7536"C:\WINDOWS\system32\reg.exe" add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments /v SaveZoneInformation /t REG_DWORD /d 1 /fC:\Windows\SysWOW64\reg.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\advapi32.dll
7804"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\hvnc (2).zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
8052"C:\WINDOWS\system32\reg.exe" add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v PromptOnSecureDesktop /t REG_DWORD /d 0 /fC:\Windows\SysWOW64\reg.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\advapi32.dll
Total events
11 494
Read events
11 482
Write events
12
Delete events
0

Modification events

(PID) Process:(7804) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7804) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7804) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(7804) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\hvnc (2).zip
(PID) Process:(7804) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7804) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7804) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7804) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7804) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@C:\WINDOWS\System32\acppage.dll,-6002
Value:
Windows Batch File
(PID) Process:(8052) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Operation:writeName:PromptOnSecureDesktop
Value:
0
Executable files
6
Suspicious files
0
Text files
10
Unknown types
3

Dropped files

PID
Process
Filename
Type
7804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34371\tunnel.battext
MD5:456445C4E7C1BC2512332C43392C52D2
SHA256:DDA973586965CF14E8B438F99A8EF91C8F4618A0AB0CAE5D3750D37C833F3E0B
1280powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_vhfwxlel.st1.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34287\readme.txttext
MD5:74EBD08EB4422DBA25CC12C11FA29E74
SHA256:ECB1E56BACA667A9A61F307A29F7D8519548E2DBDA3615ACDCD5146C21075B73
7804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34287\plink.exeexecutable
MD5:11ECC536E4157907ED803F956E72F43D
SHA256:049E86E6C3F73CDF6147075A2EAB50C009874EA9B0B174A150ADD6FB73C1D9B4
7804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34287\tunnel.battext
MD5:456445C4E7C1BC2512332C43392C52D2
SHA256:DDA973586965CF14E8B438F99A8EF91C8F4618A0AB0CAE5D3750D37C833F3E0B
7804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34287\Builder.exeexecutable
MD5:915E9F5C50320EB1E1A14767C330799B
SHA256:2D51BB007B3808F51F43EE0766B42147EDBD354E01B838759811E6EE47C6E797
7804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34371\plink.exeexecutable
MD5:11ECC536E4157907ED803F956E72F43D
SHA256:049E86E6C3F73CDF6147075A2EAB50C009874EA9B0B174A150ADD6FB73C1D9B4
7804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34371\readme.txttext
MD5:74EBD08EB4422DBA25CC12C11FA29E74
SHA256:ECB1E56BACA667A9A61F307A29F7D8519548E2DBDA3615ACDCD5146C21075B73
7804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34371\tvnviewer.exeexecutable
MD5:63A5E12E05F8D0C2AD1F3D6C078F2FA9
SHA256:DE633283D2C0F8FCA31F55B13C0F7216347C8D88330E52A0A693C7CEF19FD98E
7804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7804.34287\tvnviewer.exeexecutable
MD5:63A5E12E05F8D0C2AD1F3D6C078F2FA9
SHA256:DE633283D2C0F8FCA31F55B13C0F7216347C8D88330E52A0A693C7CEF19FD98E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
90
TCP/UDP connections
38
DNS requests
23
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
5316
svchost.exe
POST
400
20.190.160.22:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
binary
203 b
whitelisted
5316
svchost.exe
POST
400
20.190.160.22:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
binary
203 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/FlightSettings/FSService?ProcessorClockSpeed=3094&IsRetailOS=1&OEMManufacturerName=DELL&FlightingPolicyValue=3&EnablePreviewBuilds=4294967295&OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&ManagePreviewBuilds=3&BranchReadinessLevelSource=0&AttrDataVer=186&ProcessorCores=6&BranchReadinessLevelRaw=16&TotalPhysicalRAM=6144&TPMVersion=0&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&DeviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&App=FSS&AppVer=10.0&SmartActiveHoursState=1&ActiveHoursStart=20&SecureBootCapable=0&ActiveHoursEnd=13&DeviceFamily=Windows.Desktop
US
87.3 Kb
whitelisted
5392
svchost.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
5392
svchost.exe
GET
200
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.74 Kb
whitelisted
5316
svchost.exe
POST
400
20.190.160.22:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
binary
203 b
whitelisted
5316
svchost.exe
POST
400
20.190.160.22:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
binary
203 b
whitelisted
5316
svchost.exe
POST
400
20.190.160.22:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
binary
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5392
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.204.161:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
5276
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3428
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
5392
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 51.104.136.2
whitelisted
www.bing.com
  • 2.16.204.161
  • 2.16.204.141
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
google.com
  • 172.217.16.206
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.133
  • 20.190.160.131
  • 40.126.32.136
  • 20.190.160.67
  • 40.126.32.68
  • 20.190.160.128
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
  • 23.55.110.211
  • 23.55.110.193
whitelisted
www.microsoft.com
  • 23.59.18.102
  • 88.221.169.152
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted

Threats

PID
Process
Class
Message
5392
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info