File name:

Medicine.zip

Full analysis: https://app.any.run/tasks/97027daa-9b0d-467c-a7e9-e0e99738263f
Verdict: Malicious activity
Analysis date: February 19, 2026, 10:49:32
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

ABC87FE1CDF19EEF87373CA37DD04CE1

SHA1:

FC1E3B30C5BB53ED2D78676AC3F577A5270CA2F4

SHA256:

AABCF3C7FA394E13BF25FB05804E634C4EB051A91D9546E207457AA33A4DA239

SSDEEP:

98304:nPYhT1MS65nzI1wMnqZF1FXrUNgJeoktnTLvskNUt/74G/lT4hEO28YTlN6WbBW0:gIjxGPYt5XzFE4RZ4K9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 2912)
      • cmd.exe (PID: 7624)
      • cmd.exe (PID: 1856)
      • cmd.exe (PID: 1984)
      • cmd.exe (PID: 8064)
    • Starts application with an unusual extension

      • cmd.exe (PID: 7624)
      • cmd.exe (PID: 1856)
      • cmd.exe (PID: 1984)
      • cmd.exe (PID: 8064)
      • cmd.exe (PID: 2912)
    • Application launched itself

      • cmd.exe (PID: 2912)
      • cmd.exe (PID: 1856)
    • Executing commands from a ".bat" file

      • cmd.exe (PID: 2912)
      • Autodesk License Patcher Installer.exe (PID: 8184)
      • cmd.exe (PID: 1856)
      • Autodesk License Patcher Installer.exe (PID: 8456)
      • Autodesk License Patcher Installer.exe (PID: 5356)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 2912)
      • Autodesk License Patcher Installer.exe (PID: 8184)
      • cmd.exe (PID: 1856)
      • Autodesk License Patcher Installer.exe (PID: 8456)
      • Autodesk License Patcher Installer.exe (PID: 5356)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 7624)
      • cmd.exe (PID: 1984)
      • cmd.exe (PID: 8064)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 8732)
    • Checks supported languages

      • Autodesk License Patcher Installer.exe (PID: 5356)
      • chcp.com (PID: 2284)
      • mode.com (PID: 4212)
      • Autodesk License Patcher Installer.exe (PID: 8184)
      • mode.com (PID: 7728)
      • chcp.com (PID: 3004)
      • mode.com (PID: 4852)
      • chcp.com (PID: 3976)
      • mode.com (PID: 1068)
      • Autodesk License Patcher Installer.exe (PID: 8456)
      • chcp.com (PID: 8480)
      • mode.com (PID: 4516)
      • chcp.com (PID: 4724)
    • Starts MODE.COM to configure console settings

      • mode.com (PID: 4212)
      • mode.com (PID: 7728)
      • mode.com (PID: 4852)
      • mode.com (PID: 1068)
      • mode.com (PID: 4516)
    • The sample compiled with russian language support

      • WinRAR.exe (PID: 8732)
    • Reads the computer name

      • Autodesk License Patcher Installer.exe (PID: 5356)
      • Autodesk License Patcher Installer.exe (PID: 8184)
      • Autodesk License Patcher Installer.exe (PID: 8456)
    • Drops script file

      • Autodesk License Patcher Installer.exe (PID: 5356)
      • cmd.exe (PID: 7624)
      • Autodesk License Patcher Installer.exe (PID: 8184)
      • cmd.exe (PID: 1856)
      • cmd.exe (PID: 1984)
      • Autodesk License Patcher Installer.exe (PID: 8456)
      • cmd.exe (PID: 8064)
      • cmd.exe (PID: 2912)
    • Process checks computer location settings

      • Autodesk License Patcher Installer.exe (PID: 5356)
      • Autodesk License Patcher Installer.exe (PID: 8184)
      • Autodesk License Patcher Installer.exe (PID: 8456)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 8732)
      • Autodesk License Patcher Installer.exe (PID: 5356)
      • Autodesk License Patcher Installer.exe (PID: 8184)
      • Autodesk License Patcher Installer.exe (PID: 8456)
    • Changes the display of characters in the console

      • cmd.exe (PID: 7624)
      • cmd.exe (PID: 1856)
      • cmd.exe (PID: 1984)
      • cmd.exe (PID: 8064)
      • cmd.exe (PID: 2912)
    • Manual execution by a user

      • Autodesk License Patcher Installer.exe (PID: 8184)
      • Autodesk License Patcher Installer.exe (PID: 8456)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2026:01:21 08:58:56
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Autodesk License Patcher Installer/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
179
Monitored processes
38
Malicious processes
0
Suspicious processes
7

Behavior graph

Click at the process to see the details
start winrar.exe autodesk license patcher installer.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs mode.com no specs reg.exe no specs fltmc.exe no specs cmd.exe conhost.exe no specs chcp.com no specs mode.com no specs reg.exe no specs fltmc.exe no specs ping.exe no specs autodesk license patcher installer.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs mode.com no specs reg.exe no specs fltmc.exe no specs cmd.exe conhost.exe no specs chcp.com no specs mode.com no specs reg.exe no specs fltmc.exe no specs ping.exe no specs autodesk license patcher installer.exe cmd.exe no specs conhost.exe no specs chcp.com no specs mode.com no specs reg.exe no specs fltmc.exe no specs ping.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1068mode con: cols=70 lines=15 C:\Windows\SysWOW64\mode.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DOS Device MODE Utility
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\mode.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1424ping 127.0.0.1 -n 15 C:\Windows\SysWOW64\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
TCP/IP Ping Command
Exit code:
3221225786
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1856C:\WINDOWS\system32\cmd.exe /c ""C:\AutodeskLicensePatcherInstaller\AutodeskLicensePatcherInstaller.bat" "C:\Windows\SysWOW64\cmd.exeAutodesk License Patcher Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1984"cmd.exe" /x /d /r set "f0=C:\AutodeskLicensePatcherInstaller\AutodeskLicensePatcherInstaller.bat" &call "C:\AutodeskLicensePatcherInstaller\AutodeskLicensePatcherInstaller.bat" C:\Windows\SysWOW64\cmd.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
3221225786
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2284chcp 1254 C:\Windows\SysWOW64\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Change CodePage Utility
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\ulib.dll
2912C:\WINDOWS\system32\cmd.exe /c ""C:\AutodeskLicensePatcherInstaller\AutodeskLicensePatcherInstaller.bat" "C:\Windows\SysWOW64\cmd.exeAutodesk License Patcher Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3004chcp 1254 C:\Windows\SysWOW64\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3120C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3976chcp 1254 C:\Windows\SysWOW64\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Change CodePage Utility
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4064\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
5 704
Read events
5 678
Write events
13
Delete events
13

Modification events

(PID) Process:(8732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(8732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(8732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(8732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Medicine.zip
(PID) Process:(8732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(8732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(8732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(8732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2912) cmd.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\WINDOWS\system32\cmd.exe.FriendlyAppName
Value:
Windows Command Processor
(PID) Process:(2912) cmd.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\WINDOWS\system32\cmd.exe.ApplicationCompany
Value:
Microsoft Corporation
Executable files
13
Suspicious files
0
Text files
4
Unknown types
30

Dropped files

PID
Process
Filename
Type
8732WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa8732.32470\noNLM\TeklaStructures_application.dll
MD5:
SHA256:
8732WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa8732.32470\Autodesk License Patcher Installer\Bonus\Bloatware CleanUp.exeexecutable
MD5:30BC3A4843995DB743E3CE3F43CB1CD2
SHA256:8CA203F91FBDC5FD20F63FC8409CE52785852306DE1922F8C14F5D1CE0C01820
8732WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa8732.32470\Autodesk License Patcher Installer\Autodesk License Patcher Installer.exeexecutable
MD5:BFBBD32C3E2DE71F98130D62A5A3BA55
SHA256:FF7A02F0C6B3806B76BD4E78515F05730303F7D1A0BC1976DBE85EBAFF0D60C7
8732WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa8732.32470\noNLM\Tekla.Account.Identity.dllexecutable
MD5:D14F83B21EAA0B14C275DE3B847E3317
SHA256:CA2A803526EE6D2529D37D1D6688B3DBA12344DD12CCC420DF9D57F53F5AE6A3
8732WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa8732.32470\noNLM\Readme.txttext
MD5:898CE21132FB8798B93FA64C75451160
SHA256:B2CA322698343FB05651E284C583AB7EAB021F61BE2919A65D286C7CC7DAFBBD
5356Autodesk License Patcher Installer.exeC:\AutodeskLicensePatcherInstaller\Files\Task\Autodesk.xmlbinary
MD5:DBFED3FF9DC6CA06E2CF0E2E63098D66
SHA256:409A178ED9B9C0929FD9F3B8C3A58AFD1B3370C53BAF49B4956CF9A79F50D398
5356Autodesk License Patcher Installer.exeC:\AutodeskLicensePatcherInstaller\Files\Tweak\UnNamed.jsonbinary
MD5:BA3088F87EDFCCEB1E084C971DB40601
SHA256:E0371582686D18B48EDB9E956057B52AA97DE8C034EE79AAB10FFB5331711651
8732WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa8732.32470\Autodesk License Patcher Installer\Bonus\Internet Connection.exeexecutable
MD5:49678287613D87E6E4D0BC76C233E923
SHA256:B43A07452C682626AF5C96A9BCB7EA9C36406FAF089BCAD236D55BB33928B143
8732WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa8732.32470\Autodesk License Patcher Installer\ReadMe.txttext
MD5:C399464B1C985F2F2D57766EDBC6ABDF
SHA256:955CF5B12B2004DDBF9FCE3BA3DDD52E1CD5F4DF6FE130082C30F23CCDED8397
5356Autodesk License Patcher Installer.exeC:\AutodeskLicensePatcherInstaller\Files\Tweak\Tweak.regbinary
MD5:2859C8E3C69A5D627C88B6E695EA3A2E
SHA256:C41C2D93CA317CC19AA49C48DCF681D1074DCA34695A061202C202BE62DB3745
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
27
DNS requests
18
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3656
svchost.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
unknown
whitelisted
8968
SIHClient.exe
GET
304
20.165.94.63:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
whitelisted
8968
SIHClient.exe
GET
200
40.69.42.241:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
unknown
whitelisted
8968
SIHClient.exe
GET
200
20.165.94.63:443
https://slscr.update.microsoft.com/sls/ping
unknown
whitelisted
8968
SIHClient.exe
GET
304
20.165.94.63:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
whitelisted
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
unknown
whitelisted
3656
svchost.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
unknown
whitelisted
3656
svchost.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.204.150:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
172.66.2.5:80
ocsp.digicert.com
CLOUDFLARENET
US
whitelisted
3656
svchost.exe
23.216.77.42:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3656
svchost.exe
23.59.18.102:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
6768
MoUsoCoreWorker.exe
23.59.18.102:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
23.59.18.102:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
356
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
self.events.data.microsoft.com
  • 52.168.117.175
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.16.204.150
  • 2.16.204.149
  • 2.16.204.153
  • 2.16.204.156
  • 2.16.204.145
  • 2.16.204.155
  • 2.16.204.148
  • 2.16.204.146
  • 2.16.204.152
whitelisted
ocsp.digicert.com
  • 172.66.2.5
  • 162.159.142.9
whitelisted
google.com
  • 172.217.16.174
whitelisted
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.20
  • 23.216.77.25
  • 23.216.77.22
  • 23.216.77.30
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
www.microsoft.com
  • 23.59.18.102
  • 88.221.169.152
whitelisted
login.live.com
  • 20.190.159.75
  • 40.126.31.2
  • 20.190.159.0
  • 40.126.31.3
  • 20.190.159.4
  • 20.190.159.23
  • 40.126.31.67
  • 40.126.31.0
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted

Threats

PID
Process
Class
Message
3656
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info