File name:

18718147901.zip

Full analysis: https://app.any.run/tasks/cc4c3fd2-d682-4077-916b-3573b672f25d
Verdict: Malicious activity
Analysis date: August 23, 2024, 06:55:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
netreactor
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

8202AEFFEED1B879F5B992BDEF18EF2F

SHA1:

F2279A88212F5985E4E7D9662FE2EBA5997E4CA9

SHA256:

B29761381A053E09AEC14FBF7323CBB1ADB91B28F021DBC3E8EA3E1AB01EC718

SSDEEP:

12288:9z7i5XeuqolnMA5+AlxwJB7Oq8cne11reEnioEN33+BCOZo:B6XzqolnMA5+AlxS8q8Ce11reEnioENH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 6576)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6780)
    • Executable content was dropped or overwritten

      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6780)
      • dllhost.exe (PID: 7008)
    • Detected use of alternative data streams (AltDS)

      • dllhost.exe (PID: 7008)
    • Searches for installed software

      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6780)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 1084)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6164)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 4408)
    • Reads security settings of Internet Explorer

      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 1084)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6780)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 4408)
    • Creates file in the systems drive root

      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6780)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 1084)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 4408)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6576)
    • Manual execution by a user

      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6780)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6772)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 1084)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 7104)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 4408)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 5180)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6164)
    • Reads the machine GUID from the registry

      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6780)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 1084)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 4408)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6164)
    • Reads the computer name

      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6780)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 1084)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 4408)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6164)
    • Checks supported languages

      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6780)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 1084)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 4408)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6164)
    • Create files in a temporary directory

      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6780)
    • .NET Reactor protector has been detected

      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6780)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 1084)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 6164)
      • 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe (PID: 4408)
    • Reads security settings of Internet Explorer

      • dllhost.exe (PID: 7008)
    • Creates files in the program directory

      • dllhost.exe (PID: 7008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x43555270
ZipCompressedSize: 349517
ZipUncompressedSize: 420864
ZipFileName: 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
10
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe THREAT 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe rundll32.exe no specs Copy/Move/Rename/Delete/Link Object 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe no specs THREAT 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe no specs THREAT 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe no specs THREAT 7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe

Process information

PID
CMD
Path
Indicators
Parent process
1084"C:\Users\admin\Desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe" C:\Users\admin\Desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe
explorer.exe
User:
admin
Company:
Team EFA
Integrity Level:
HIGH
Description:
PathWaveLicensePatcher
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4408"C:\Users\admin\Desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe" C:\Users\admin\Desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe
explorer.exe
User:
admin
Company:
Team EFA
Integrity Level:
HIGH
Description:
PathWaveLicensePatcher
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
5180"C:\Program Files\Keysight\EEsof_License_Tools\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe" C:\Program Files\Keysight\EEsof_License_Tools\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exeexplorer.exe
User:
admin
Company:
Team EFA
Integrity Level:
MEDIUM
Description:
PathWaveLicensePatcher
Exit code:
3221226540
Version:
1.1.0.0
Modules
Images
c:\program files\keysight\eesof_license_tools\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6164"C:\Program Files\Keysight\EEsof_License_Tools\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe" C:\Program Files\Keysight\EEsof_License_Tools\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe
explorer.exe
User:
admin
Company:
Team EFA
Integrity Level:
HIGH
Description:
PathWaveLicensePatcher
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\program files\keysight\eesof_license_tools\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6344C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6576"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\18718147901.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6772"C:\Users\admin\Desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe" C:\Users\admin\Desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exeexplorer.exe
User:
admin
Company:
Team EFA
Integrity Level:
MEDIUM
Description:
PathWaveLicensePatcher
Exit code:
3221226540
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6780"C:\Users\admin\Desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe" C:\Users\admin\Desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe
explorer.exe
User:
admin
Company:
Team EFA
Integrity Level:
HIGH
Description:
PathWaveLicensePatcher
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
7008C:\WINDOWS\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\System32\dllhost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
7104"C:\Users\admin\Desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe" C:\Users\admin\Desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exeexplorer.exe
User:
admin
Company:
Team EFA
Integrity Level:
MEDIUM
Description:
PathWaveLicensePatcher
Exit code:
3221226540
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
24 406
Read events
24 377
Write events
29
Delete events
0

Modification events

(PID) Process:(6576) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6576) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6576) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6576) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\18718147901.zip
(PID) Process:(6576) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6576) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6576) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6576) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6576) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(6576) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFCF000000340000008F0400001B020000
Executable files
3
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
67807ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exeC:\Users\admin\AppData\Local\Temp\Costura\5A592F4BF0B08476E943B3354CF373DB\32\flexnetpatchlibrary.dllexecutable
MD5:B9847D663B7A10CCED392F602ED2C3C8
SHA256:8853B4A31A42285199B3A8ADF6601D8A06C0CECDC9AB1546B34F8FDCE8489C9A
6576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6576.44565\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0eexecutable
MD5:55F4887C87847DB68DD23C1F208B5C72
SHA256:7CA27A3C0D39A85D6AB3DBA561F7B31100931CD1B4CE07D699CA4987910C4D0E
7008dllhost.exeC:\Program Files\Keysight\EEsof_License_Tools\7ca27a3c0d39a85d6ab3dba561f7b31100931cd1b4ce07d699ca4987910c4d0e.exeexecutable
MD5:55F4887C87847DB68DD23C1F208B5C72
SHA256:7CA27A3C0D39A85D6AB3DBA561F7B31100931CD1B4CE07D699CA4987910C4D0E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
30
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3144
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6952
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6296
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2468
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4760
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2468
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3144
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3144
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3144
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 40.127.240.158
whitelisted
google.com
  • 142.250.74.206
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.73
  • 20.190.159.64
  • 20.190.159.68
  • 20.190.159.75
  • 20.190.159.2
  • 20.190.159.4
  • 40.126.31.67
  • 40.126.31.71
  • 20.190.159.23
  • 40.126.31.73
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 40.68.123.157
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.31
whitelisted

Threats

No threats detected
No debug info