File name:

05bd88a1e30b455386568c9654ec00d1.exe

Full analysis: https://app.any.run/tasks/d889895f-e1ff-452d-9a3d-fa77daafbb67
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 20, 2025, 00:37:17
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

05BD88A1E30B455386568C9654EC00D1

SHA1:

30B2A730BA82FEAC44F81C034DE0E94D61012CCB

SHA256:

A947C9DD7C593CC91FAEA962FC633D45E0ABA2146F2926CFB97FE0AE4AD4C614

SSDEEP:

98304:Gyr0cePb6xIOpi7WWQHJPOF4U3Jidx25AitATa1rV8MGv3sECyhj0zSTtUp82o/G:yv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • 05bd88a1e30b455386568c9654ec00d1.exe (PID: 7480)
      • 05bd88a1e30b455386568c9654ec00d1.exe (PID: 7388)
    • Changes the autorun value in the registry

      • is-DT2JR.tmp (PID: 7508)
    • Actions looks like stealing of personal data

      • InstHelp.exe (PID: 7868)
      • InstHelp.exe (PID: 7924)
    • Steals credentials from Web Browsers

      • InstHelp.exe (PID: 7868)
      • InstHelp.exe (PID: 7924)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 05bd88a1e30b455386568c9654ec00d1.exe (PID: 7480)
      • is-DT2JR.tmp (PID: 7508)
      • ErrorSafeScannerSetup.exe (PID: 7492)
    • Process drops legitimate windows executable

      • is-DT2JR.tmp (PID: 7508)
    • The process drops C-runtime libraries

      • is-DT2JR.tmp (PID: 7508)
    • Creates/Modifies COM task schedule object

      • _RegDLL.tmp (PID: 7660)
      • _RegDLL.tmp (PID: 7720)
      • _RegDLL.tmp (PID: 7772)
      • _RegDLL.tmp (PID: 7804)
      • _RegDLL.tmp (PID: 7828)
    • Reads security settings of Internet Explorer

      • InstHelp.exe (PID: 7868)
      • InstHelp.exe (PID: 7924)
      • uers.exe (PID: 7960)
  • INFO

    • The sample compiled with english language support

      • 05bd88a1e30b455386568c9654ec00d1.exe (PID: 7480)
      • is-DT2JR.tmp (PID: 7508)
      • ErrorSafeScannerSetup.exe (PID: 7492)
    • Checks supported languages

      • ErrorSafeScannerSetup.exe (PID: 7492)
      • is-DT2JR.tmp (PID: 7508)
      • 05bd88a1e30b455386568c9654ec00d1.exe (PID: 7480)
      • _RegDLL.tmp (PID: 7660)
      • _RegDLL.tmp (PID: 7720)
      • _RegDLL.tmp (PID: 7772)
      • _RegDLL.tmp (PID: 7804)
      • _RegDLL.tmp (PID: 7828)
      • InstHelp.exe (PID: 7844)
      • InstHelp.exe (PID: 7868)
      • InstHelp.exe (PID: 7924)
      • EmtERSF.exe (PID: 7932)
      • uers.exe (PID: 7960)
    • Create files in a temporary directory

      • ErrorSafeScannerSetup.exe (PID: 7492)
      • 05bd88a1e30b455386568c9654ec00d1.exe (PID: 7480)
      • is-DT2JR.tmp (PID: 7508)
    • Reads the computer name

      • is-DT2JR.tmp (PID: 7508)
      • _RegDLL.tmp (PID: 7660)
      • _RegDLL.tmp (PID: 7720)
      • _RegDLL.tmp (PID: 7772)
      • _RegDLL.tmp (PID: 7804)
      • _RegDLL.tmp (PID: 7828)
      • InstHelp.exe (PID: 7868)
      • InstHelp.exe (PID: 7924)
      • uers.exe (PID: 7960)
    • Creates files in the program directory

      • is-DT2JR.tmp (PID: 7508)
      • uers.exe (PID: 7960)
    • Autorun file from Registry key

      • is-DT2JR.tmp (PID: 7508)
    • Creates a software uninstall entry

      • is-DT2JR.tmp (PID: 7508)
    • Checks proxy server information

      • InstHelp.exe (PID: 7868)
      • InstHelp.exe (PID: 7924)
      • uers.exe (PID: 7960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2006:07:24 11:52:59+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 7.1
CodeSize: 8192
InitializedDataSize: 2211840
UninitializedDataSize: -
EntryPoint: 0x101e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.3.156.2
ProductVersionNumber: 1.3.156.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: ErrorSafe Inc.
FileDescription: ErrorSafe 2006 Setup Wizard
FileVersion: 1,3,156,2
InternalName: Installer.exe
LegalCopyright: Copyright (C) 2006 ErrorSafe. All rights reserved.
OriginalFileName: ErrorSafeScannerSetup.exe
ProductName: ErrorSafe 2006 Setup Wizard
ProductVersion: 1,3,156,2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
16
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 05bd88a1e30b455386568c9654ec00d1.exe errorsafescannersetup.exe is-dt2jr.tmp sppextcomobj.exe no specs slui.exe no specs _regdll.tmp no specs _regdll.tmp no specs _regdll.tmp no specs _regdll.tmp no specs _regdll.tmp no specs insthelp.exe no specs insthelp.exe insthelp.exe emtersf.exe no specs uers.exe no specs 05bd88a1e30b455386568c9654ec00d1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7388"C:\Users\admin\AppData\Local\Temp\05bd88a1e30b455386568c9654ec00d1.exe" C:\Users\admin\AppData\Local\Temp\05bd88a1e30b455386568c9654ec00d1.exeexplorer.exe
User:
admin
Company:
ErrorSafe Inc.
Integrity Level:
MEDIUM
Description:
ErrorSafe 2006 Setup Wizard
Exit code:
3221226540
Version:
1,3,156,2
Modules
Images
c:\users\admin\appdata\local\temp\05bd88a1e30b455386568c9654ec00d1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7480"C:\Users\admin\AppData\Local\Temp\05bd88a1e30b455386568c9654ec00d1.exe" C:\Users\admin\AppData\Local\Temp\05bd88a1e30b455386568c9654ec00d1.exe
explorer.exe
User:
admin
Company:
ErrorSafe Inc.
Integrity Level:
HIGH
Description:
ErrorSafe 2006 Setup Wizard
Exit code:
0
Version:
1,3,156,2
Modules
Images
c:\users\admin\appdata\local\temp\05bd88a1e30b455386568c9654ec00d1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7492C:\Users\admin\AppData\Local\Temp\ErrorSafeScannerSetup.exe /norestart /verysilentC:\Users\admin\AppData\Local\Temp\ErrorSafeScannerSetup.exe
05bd88a1e30b455386568c9654ec00d1.exe
User:
admin
Company:
ErrorSafe Inc.
Integrity Level:
HIGH
Description:
ErrorSafe Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\errorsafescannersetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7508"C:\Users\admin\AppData\Local\Temp\is-LEEJP.tmp\is-DT2JR.tmp" /SL4 $4024C "C:\Users\admin\AppData\Local\Temp\ErrorSafeScannerSetup.exe" 1955929 52224 /norestart /verysilentC:\Users\admin\AppData\Local\Temp\is-LEEJP.tmp\is-DT2JR.tmp
ErrorSafeScannerSetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.42.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-leejp.tmp\is-dt2jr.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7620C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7652"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7660_RegDLL.tmp 1344 1348C:\Users\admin\AppData\Local\Temp\is-H7AQO.tmp\_isetup\_RegDLL.tmpis-DT2JR.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
479930586
Modules
Images
c:\users\admin\appdata\local\temp\is-h7aqo.tmp\_isetup\_regdll.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7720_RegDLL.tmp 1344 1348C:\Users\admin\AppData\Local\Temp\is-H7AQO.tmp\_isetup\_RegDLL.tmpis-DT2JR.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
479930586
Modules
Images
c:\users\admin\appdata\local\temp\is-h7aqo.tmp\_isetup\_regdll.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7772_RegDLL.tmp 1344 1348C:\Users\admin\AppData\Local\Temp\is-H7AQO.tmp\_isetup\_RegDLL.tmpis-DT2JR.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
479930586
Modules
Images
c:\users\admin\appdata\local\temp\is-h7aqo.tmp\_isetup\_regdll.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7804_RegDLL.tmp 1344 1348C:\Users\admin\AppData\Local\Temp\is-H7AQO.tmp\_isetup\_RegDLL.tmpis-DT2JR.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
479930586
Modules
Images
c:\users\admin\appdata\local\temp\is-h7aqo.tmp\_isetup\_regdll.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
Total events
9 273
Read events
2 582
Write events
6 691
Delete events
0

Modification events

(PID) Process:(7480) 05bd88a1e30b455386568c9654ec00d1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Error Safe Free
Operation:writeName:ProductCode
Value:
UERS-9999-8882-7773
(PID) Process:(7480) 05bd88a1e30b455386568c9654ec00d1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Error Safe Free
Operation:writeName:mxhrs
Value:
120
(PID) Process:(7480) 05bd88a1e30b455386568c9654ec00d1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Error Safe Free
Operation:writeName:inst_t_yr
Value:
E9070300040014000000250016006A03
(PID) Process:(7720) _RegDLL.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1640DE0E-75E4-4a83-B5D1-2492BC7EBA8F}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(7720) _RegDLL.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AE4026CC-B7BA-48E8-8FB3-2C35099670A1}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7720) _RegDLL.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AE4026CC-B7BA-48E8-8FB3-2C35099670A1}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7720) _RegDLL.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{B0F4BC0F-EAEA-43B5-8CE6-DAD3CC9B29A2}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7720) _RegDLL.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B0F4BC0F-EAEA-43B5-8CE6-DAD3CC9B29A2}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7720) _RegDLL.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{489B338E-E4AB-489A-91D4-69970A541CF9}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7720) _RegDLL.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{489B338E-E4AB-489A-91D4-69970A541CF9}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
35
Suspicious files
13
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
7508is-DT2JR.tmpC:\Program Files (x86)\ErrorSafe Free\is-2FU4T.tmp
MD5:
SHA256:
7508is-DT2JR.tmpC:\Program Files (x86)\ErrorSafe Free\resource.xml
MD5:
SHA256:
7508is-DT2JR.tmpC:\Users\admin\AppData\Local\Temp\is-H7AQO.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
748005bd88a1e30b455386568c9654ec00d1.exeC:\Users\admin\AppData\Local\Temp\ErrorSafeScannerSetup.exeexecutable
MD5:9B912399CF098C1D3D1FDB6E2BA19814
SHA256:A8C43A9045F3F2AF06779C416D093EB3AE755351D161D9B19DD16C1D2E598A95
7492ErrorSafeScannerSetup.exeC:\Users\admin\AppData\Local\Temp\is-LEEJP.tmp\is-DT2JR.tmpexecutable
MD5:B683339CE008E97A0243A0F83BCA1E09
SHA256:5C6B8A1AB73CD03140040A3093E0D8466C666CD3FE17E8660DBC1A30D0B6F925
7508is-DT2JR.tmpC:\Program Files (x86)\ErrorSafe Free\is-EKV84.tmpexecutable
MD5:A67E8F56FCAE253D3EF2E17076B0F92F
SHA256:0A9631B6C023549E5BB0685C7E17BE5141F546B5179730C61551C30E7D1D134F
7508is-DT2JR.tmpC:\Users\admin\AppData\Local\Temp\is-H7AQO.tmp\_isetup\_setup64.tmpexecutable
MD5:42BF074B99A445614BD19C6E5724A01A
SHA256:0A6C41612400C3400466A0583DBB0E6C9BD310393704807E4F9617AA53ABDED6
7508is-DT2JR.tmpC:\Users\admin\AppData\Local\Temp\is-H7AQO.tmp\_isetup\_RegDLL.tmpexecutable
MD5:BB211D7A8CEA15072DE7425403508C17
SHA256:E71EC712064F193C367B0BB95A07A6DD9EB450BE1BE12CD48073FEFA1C3E0E58
7508is-DT2JR.tmpC:\Program Files (x86)\ErrorSafe Free\unins000.exeexecutable
MD5:77B0A42E0592C8B288D879EFF4DD4019
SHA256:030E764383E27073584C92B6E8BFE7832F6EF3EF810CA56B0A2C1D2CA71A8AB5
7508is-DT2JR.tmpC:\Program Files (x86)\ErrorSafe Free\is-IKKOG.tmpexecutable
MD5:77B0A42E0592C8B288D879EFF4DD4019
SHA256:030E764383E27073584C92B6E8BFE7832F6EF3EF810CA56B0A2C1D2CA71A8AB5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
23
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7924
InstHelp.exe
GET
500
13.248.169.48:80
http://instlog.errorsafe.com/stats.php?site_id=install&aid=keyin_UERS_install_9999_156.2&lid=keyin&affid=keyin
unknown
unknown
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7736
SIHClient.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8036
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7736
SIHClient.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1196
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
7924
InstHelp.exe
13.248.169.48:80
instlog.errorsafe.com
AMAZON-02
US
unknown
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.31.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
instlog.errorsafe.com
  • 13.248.169.48
  • 76.223.54.146
unknown
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.31.131
  • 20.190.159.73
  • 40.126.31.3
  • 40.126.31.73
  • 20.190.159.64
  • 40.126.31.2
  • 20.190.159.2
  • 40.126.31.1
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 104.79.89.142
whitelisted

Threats

No threats detected
No debug info