File name:

prettier.bat

Full analysis: https://app.any.run/tasks/41a1fc53-eda3-470c-831a-c7276a029c40
Verdict: Malicious activity
Analysis date: December 09, 2024, 06:57:45
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
python
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

2C3D34996FE3D6424A492F3139AA7105

SHA1:

2BB8B228CD5ADBBF4F13DA32BFC2BBDFF7FBEB84

SHA256:

AB3E8378AA31584160898D97D1ECFEAD2A63CD977EFACEC98DF375FEFDDA3016

SSDEEP:

98304:9J3cIeN+wcTAScUCYD6Gf+k4l/onUZXFCh0bRwSA2ibMlq0Ti7UJDZ2pli9TZIAQ:3cpeTy6wnGkjt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • prettier.bat.exe (PID: 6728)
      • conhost.exe (PID: 6764)
      • prettier.bat.exe (PID: 6596)
      • RuntimeBroker.exe (PID: 6880)
      • svchost.exe (PID: 6616)
      • cmd.exe (PID: 6748)
      • MusNotificationUx.exe (PID: 4132)
      • conhost.exe (PID: 1344)
      • WaaSMedicAgent.exe (PID: 6288)
      • SIHClient.exe (PID: 5268)
      • MusNotifyIcon.exe (PID: 6564)
      • WmiPrvSE.exe (PID: 6348)
      • svchost.exe (PID: 5092)
      • svchost.exe (PID: 624)
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • prettier.bat.exe (PID: 6596)
    • Process drops python dynamic module

      • prettier.bat.exe (PID: 6596)
    • Process drops legitimate windows executable

      • prettier.bat.exe (PID: 6596)
    • Application launched itself

      • prettier.bat.exe (PID: 6596)
    • Executable content was dropped or overwritten

      • prettier.bat.exe (PID: 6596)
    • Loads Python modules

      • prettier.bat.exe (PID: 6728)
    • Starts CMD.EXE for commands execution

      • prettier.bat.exe (PID: 6728)
  • INFO

    • Reads the computer name

      • prettier.bat.exe (PID: 6596)
    • Checks supported languages

      • prettier.bat.exe (PID: 6596)
      • prettier.bat.exe (PID: 6728)
    • Create files in a temporary directory

      • prettier.bat.exe (PID: 6596)
    • Creates files in the program directory

      • svchost.exe (PID: 6616)
      • MusNotificationUx.exe (PID: 4132)
      • MusNotifyIcon.exe (PID: 6564)
    • Reads security settings of Internet Explorer

      • RuntimeBroker.exe (PID: 6880)
    • Reads the time zone

      • MusNotificationUx.exe (PID: 4132)
      • MusNotifyIcon.exe (PID: 6564)
      • WmiPrvSE.exe (PID: 6348)
    • Reads the software policy settings

      • WaaSMedicAgent.exe (PID: 6288)
      • SIHClient.exe (PID: 5268)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:11:30 16:31:08+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.41
CodeSize: 172032
InitializedDataSize: 154624
UninitializedDataSize: -
EntryPoint: 0xce20
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
14
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start prettier.bat.exe prettier.bat.exe no specs cmd.exe no specs conhost.exe no specs svchost.exe no specs runtimebroker.exe no specs musnotificationux.exe no specs conhost.exe no specs waasmedicagent.exe no specs svchost.exe no specs musnotifyicon.exe no specs sihclient.exe wmiprvse.exe no specs svchost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
624C:\WINDOWS\system32\svchost.exe -k wusvcs -p -s WaaSMedicSvcC:\Windows\System32\svchost.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
1344\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeWaaSMedicAgent.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4132%systemroot%\system32\MusNotificationUx.exe ClearActiveNotificationsC:\Windows\System32\MusNotificationUx.exeMusNotification.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
MusNotificationUx.exe
Exit code:
0
Version:
10.0.19041.3693 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\musnotificationux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcp_win.dll
5092C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wuauservC:\Windows\System32\svchost.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
5268C:\WINDOWS\System32\sihclient.exe /cv MnMQib55ek+0urmYrHbGsQ.0.2C:\Windows\System32\SIHClient.exe
upfc.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
SIH Client
Exit code:
2379777
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sihclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\advapi32.dll
6288C:\WINDOWS\System32\WaaSMedicAgent.exe f9a07d14f8806fecbbd45235dc784ad2 MnMQib55ek+0urmYrHbGsQ.0.1.0.0.0C:\Windows\System32\WaaSMedicAgent.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
WaasMedic Agent Exe
Exit code:
0
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\waasmedicagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcrypt.dll
6348C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -EmbeddingC:\Windows\System32\wbem\WmiPrvSE.exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
WMI Provider Host
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\wmiprvse.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ncobjapi.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
6564%systemroot%\system32\MusNotifyIcon.exe NotifyTrayIcon 13C:\Windows\System32\MusNotifyIcon.exeMusNotification.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
MusNotifyIcon.exe
Exit code:
2149884437
Version:
10.0.19041.3693 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\musnotifyicon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6596"C:\Users\admin\AppData\Local\Temp\prettier.bat.exe" C:\Users\admin\AppData\Local\Temp\prettier.bat.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\prettier.bat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6616C:\WINDOWS\System32\svchost.exe -k wsappx -p -s ClipSVCC:\Windows\System32\svchost.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
Total events
9 091
Read events
9 075
Write events
16
Delete events
0

Modification events

(PID) Process:(6616) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
Operation:writeName:ProductName
Value:
Windows 10 Pro
(PID) Process:(6616) svchost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ClipSVC\Parameters
Operation:writeName:ProcessBiosKey
Value:
1
(PID) Process:(5268) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}\/SLS/{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:Expires
Value:
2024-12-11 06:58:21
(PID) Process:(5268) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}\/SLS/{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:LastModified
Value:
2001-01-01 00:00:00
(PID) Process:(5268) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}\/SLS/{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:PotentialFailover
Value:
0
(PID) Process:(5268) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}\/SLS/{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:Data
Value:
<?xml version="1.0" encoding="utf-8"?><ServiceEnvironment ServiceID="522D76A4-93E1-47F8-B8CE-07C937AD1A1E" ID="DNSResiliency-CloudFlare-Live" Revision="1"><DNSConfigData><DNSconfigs elementVersion="1"><DNSconfig hostname="slscr.update.microsoft.com" pingtest="/sls/ping" domain=".update.microsoft.com" dnsserver="162.159.36.2"></DNSconfig><DNSconfig hostname="fe3cr.delivery.mp.microsoft.com" pingtest="/clientwebservice/ping" domain=".delivery.mp.microsoft.com" dnsserver="162.159.36.2"></DNSconfig></DNSconfigs><Flags elementVersion="1"><FeatureSwitchOn>1</FeatureSwitchOn><EnforceNRPTRule>0</EnforceNRPTRule><EnforceDomain>0</EnforceDomain><SkipDefaultDNSResolver>0</SkipDefaultDNSResolver></Flags></DNSConfigData></ServiceEnvironment>
(PID) Process:(5268) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}\/SLS/{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:ETag
Value:
"XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
(PID) Process:(5268) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\dns
Operation:writeName:Data
Value:
<?xml version="1.0" encoding="utf-8"?><ServiceEnvironment ServiceID="522D76A4-93E1-47F8-B8CE-07C937AD1A1E" ID="DNSResiliency-CloudFlare-Live" Revision="1"><DNSConfigData><DNSconfigs elementVersion="1"><DNSconfig hostname="slscr.update.microsoft.com" pingtest="/sls/ping" domain=".update.microsoft.com" dnsserver="162.159.36.2"></DNSconfig><DNSconfig hostname="fe3cr.delivery.mp.microsoft.com" pingtest="/clientwebservice/ping" domain=".delivery.mp.microsoft.com" dnsserver="162.159.36.2"></DNSconfig></DNSconfigs><Flags elementVersion="1"><FeatureSwitchOn>1</FeatureSwitchOn><EnforceNRPTRule>0</EnforceNRPTRule><EnforceDomain>0</EnforceDomain><SkipDefaultDNSResolver>0</SkipDefaultDNSResolver></Flags></DNSConfigData></ServiceEnvironment>
(PID) Process:(5268) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{E7A50285-D08D-499D-9FF8-180FDC2332BC}\/SLS/{E7A50285-D08D-499D-9FF8-180FDC2332BC}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:Expires
Value:
2024-12-10 18:58:23
(PID) Process:(5268) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{E7A50285-D08D-499D-9FF8-180FDC2332BC}\/SLS/{E7A50285-D08D-499D-9FF8-180FDC2332BC}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:LastModified
Value:
2001-01-01 00:00:00
Executable files
49
Suspicious files
9
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6596prettier.bat.exeC:\Users\admin\AppData\Local\Temp\_MEI65962\_decimal.pydexecutable
MD5:F3377F3DE29579140E2BBAEEFD334D4F
SHA256:B715D1C18E9A9C1531F21C02003B4C6726742D1A2441A1893BC3D79D7BB50E91
6596prettier.bat.exeC:\Users\admin\AppData\Local\Temp\_MEI65962\VCRUNTIME140.dllexecutable
MD5:862F820C3251E4CA6FC0AC00E4092239
SHA256:36585912E5EAF83BA9FEA0631534F690CCDC2D7BA91537166FE53E56C221E153
6596prettier.bat.exeC:\Users\admin\AppData\Local\Temp\_MEI65962\_socket.pydexecutable
MD5:FE896371430BD9551717EF12A3E7E818
SHA256:35246B04C6C7001CA448554246445A845CE116814A29B18B617EA38752E4659B
6596prettier.bat.exeC:\Users\admin\AppData\Local\Temp\_MEI65962\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:928BE2A3FC2E88BDA5CA0808324E97C4
SHA256:CC6C2FDF1C34FA82036165B111F91220BCF7E43AAB79DFB284F982F0590BEBB1
6596prettier.bat.exeC:\Users\admin\AppData\Local\Temp\_MEI65962\_bz2.pydexecutable
MD5:CB8C06C8FA9E61E4AC5F22EEBF7F1D00
SHA256:FC3B481684B926350057E263622A2A5335B149A0498A8D65C4F37E39DD90B640
6596prettier.bat.exeC:\Users\admin\AppData\Local\Temp\_MEI65962\_hashlib.pydexecutable
MD5:32D76C9ABD65A5D2671AEEDE189BC290
SHA256:838D5C8B7C3212C8429BAF612623ABBBC20A9023EEC41E34E5461B76A285B86C
6596prettier.bat.exeC:\Users\admin\AppData\Local\Temp\_MEI65962\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:7699C096202DA0DB6B07FAFC914D60ED
SHA256:0052515763A1A31D2527A2EB2523FB7B88D8E55C4E4DA5EF352B565476BF21E0
6596prettier.bat.exeC:\Users\admin\AppData\Local\Temp\_MEI65962\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:4CB14835B061F42179D5251E744FD667
SHA256:F9AAAABF78FEB39A1D8E971F5CE047D1C4A896A80409B800F1F7112CDCE420ED
6616svchost.exeC:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_Windows-10-Pro.swidtagxml
MD5:CAB432C4918E1CFF493C9668B2338104
SHA256:2CE9E3A7CF26A6706D8078C732D8211AEB76E9FAA5C6D3A026E32B077EDF23DF
6596prettier.bat.exeC:\Users\admin\AppData\Local\Temp\_MEI65962\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:6177998C2CE574A177E524746B77EFE7
SHA256:A0AA340274D4BB46B6D9547D647AB7DC16C229577BBAB836E6A4F3307F310332
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
33
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5268
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5268
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6460
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
2.23.209.174:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4308
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.23.209.174
  • 2.23.209.177
  • 2.23.209.176
  • 2.23.209.175
  • 2.23.209.180
  • 2.23.209.173
  • 2.23.209.171
  • 2.23.209.183
  • 2.23.209.182
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.142
whitelisted
login.live.com
  • 20.190.159.0
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.4
  • 40.126.31.73
  • 20.190.159.2
  • 40.126.31.71
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.32.186.57
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info