URL:

https://download.expressvpn.xyz/clients/windows/expressvpn_7.7.8.161.exe

Full analysis: https://app.any.run/tasks/d5f027ad-9c69-4159-86fe-f5f9e336d682
Verdict: Malicious activity
Analysis date: November 20, 2019, 15:09:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

0A8F9B08BAA08E889656718F52D95BBD

SHA1:

AD749EB946B7B93A08BA1129D96786B4CA27477B

SHA256:

B86A6E7B6D8A3BFD66B4D89DF1C1AE0282D59C12F5289BD61AC2952D4E6117C5

SSDEEP:

3:N8SElYXzMmDL/AVgfOfpgy:2SKYXzMmDL/AV4Wgy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • expressvpn_7.7.8.161.exe (PID: 324)
      • expressvpn_7.7.8.161.exe (PID: 1812)
      • ExpressVPN_7.7.8.161.exe (PID: 2852)
      • ExpressVPNNotificationService.exe (PID: 896)
      • ExpressVPN.exe (PID: 2928)
      • XvUtil.exe (PID: 2712)
      • ExpressVPN-Installer.exe (PID: 2648)
      • tapinstall.exe (PID: 3928)
      • nssm.exe (PID: 2876)
      • nssm.exe (PID: 3428)
      • nssm.exe (PID: 1096)
      • nssm.exe (PID: 2560)
      • nssm.exe (PID: 2340)
      • nssm.exe (PID: 3748)
      • expressvpnd.exe (PID: 1404)
      • XvUtil.exe (PID: 3812)
    • Loads dropped or rewritten executable

      • expressvpn_7.7.8.161.exe (PID: 1812)
      • rundll32.exe (PID: 1248)
      • rundll32.exe (PID: 2556)
      • rundll32.exe (PID: 3656)
      • rundll32.exe (PID: 2376)
      • rundll32.exe (PID: 3296)
      • ExpressVPNNotificationService.exe (PID: 896)
      • rundll32.exe (PID: 3792)
      • ExpressVPN.exe (PID: 2928)
      • XvUtil.exe (PID: 2712)
      • ExpressVPN-Installer.exe (PID: 2648)
      • expressvpnd.exe (PID: 1404)
      • XvUtil.exe (PID: 3812)
    • Changes the autorun value in the registry

      • ExpressVPN_7.7.8.161.exe (PID: 2852)
    • Changes settings of System certificates

      • msiexec.exe (PID: 1520)
    • Starts NET.EXE for service management

      • ExpressVPN-Installer.exe (PID: 2648)
      • expressvpnd.exe (PID: 1404)
  • SUSPICIOUS

    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 2344)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 2344)
      • expressvpn_7.7.8.161.exe (PID: 324)
      • expressvpn_7.7.8.161.exe (PID: 1812)
      • ExpressVPN_7.7.8.161.exe (PID: 2852)
      • msiexec.exe (PID: 1520)
      • rundll32.exe (PID: 2376)
      • rundll32.exe (PID: 3296)
      • rundll32.exe (PID: 3656)
      • rundll32.exe (PID: 3792)
      • tapinstall.exe (PID: 3928)
      • DrvInst.exe (PID: 1528)
      • DrvInst.exe (PID: 1852)
    • Executed as Windows Service

      • vssvc.exe (PID: 2584)
      • nssm.exe (PID: 3748)
    • Cleans NTFS data-stream (Zone Identifier)

      • chrome.exe (PID: 2344)
    • Starts itself from another location

      • expressvpn_7.7.8.161.exe (PID: 1812)
    • Searches for installed software

      • ExpressVPN_7.7.8.161.exe (PID: 2852)
    • Creates a software uninstall entry

      • ExpressVPN_7.7.8.161.exe (PID: 2852)
    • Creates files in the program directory

      • ExpressVPN_7.7.8.161.exe (PID: 2852)
      • rundll32.exe (PID: 3296)
      • expressvpnd.exe (PID: 1404)
    • Adds / modifies Windows certificates

      • msiexec.exe (PID: 1520)
    • Uses RUNDLL32.EXE to load library

      • MsiExec.exe (PID: 1412)
      • MsiExec.exe (PID: 1976)
      • DrvInst.exe (PID: 1528)
    • Modifies the open verb of a shell class

      • msiexec.exe (PID: 1520)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 1520)
    • Creates files in the user directory

      • ExpressVPN.exe (PID: 2928)
    • Reads Environment values

      • ExpressVPNNotificationService.exe (PID: 896)
      • ExpressVPN.exe (PID: 2928)
    • Reads Internet Cache Settings

      • ExpressVPN.exe (PID: 2928)
    • Creates files in the Windows directory

      • DrvInst.exe (PID: 1528)
      • DrvInst.exe (PID: 1852)
    • Executed via COM

      • DrvInst.exe (PID: 1528)
      • DrvInst.exe (PID: 1852)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 1528)
      • DrvInst.exe (PID: 1852)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 1528)
      • DrvInst.exe (PID: 1852)
    • Starts SC.EXE for service management

      • expressvpnd.exe (PID: 1404)
    • Uses NETSH.EXE for network configuration

      • XvUtil.exe (PID: 3812)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 2344)
      • msiexec.exe (PID: 1520)
    • Reads the hosts file

      • chrome.exe (PID: 1896)
      • chrome.exe (PID: 2344)
    • Reads Internet Cache Settings

      • chrome.exe (PID: 2344)
    • Changes settings of System certificates

      • chrome.exe (PID: 2344)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 2584)
    • Creates files in the program directory

      • msiexec.exe (PID: 1520)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1520)
    • Searches for installed software

      • DrvInst.exe (PID: 1528)
    • Reads settings of System Certificates

      • ExpressVPNNotificationService.exe (PID: 896)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
119
Monitored processes
65
Malicious processes
23
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs expressvpn_7.7.8.161.exe expressvpn_7.7.8.161.exe expressvpn_7.7.8.161.exe vssvc.exe no specs msiexec.exe msiexec.exe no specs rundll32.exe no specs rundll32.exe rundll32.exe no specs msiexec.exe no specs rundll32.exe rundll32.exe rundll32.exe expressvpn.exe expressvpnnotificationservice.exe xvutil.exe no specs expressvpn-installer.exe tapinstall.exe drvinst.exe rundll32.exe no specs drvinst.exe nssm.exe no specs nssm.exe no specs nssm.exe no specs nssm.exe no specs nssm.exe no specs net.exe no specs net1.exe no specs nssm.exe no specs expressvpnd.exe xvutil.exe no specs sc.exe no specs net.exe no specs net1.exe no specs net.exe no specs net1.exe no specs netsh.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
324"C:\Users\admin\Downloads\expressvpn_7.7.8.161.exe" C:\Users\admin\Downloads\expressvpn_7.7.8.161.exe
chrome.exe
User:
admin
Company:
ExpressVPN
Integrity Level:
MEDIUM
Description:
ExpressVPN
Exit code:
0
Version:
7.7.8.161
Modules
Images
c:\users\admin\downloads\expressvpn_7.7.8.161.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
444"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,3207724735020144132,8011526629135158438,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=11231566061845274271 --mojo-platform-channel-handle=4112 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
896"C:\Program Files\ExpressVPN\expressvpn-ui\ExpressVPNNotificationService.exe" C:\Program Files\ExpressVPN\expressvpn-ui\ExpressVPNNotificationService.exe
expressvpn_7.7.8.161.exe
User:
admin
Company:
ExpressVPN
Integrity Level:
MEDIUM
Description:
ExpressVPN Notifications
Exit code:
0
Version:
7.7.8.161
Modules
Images
c:\program files\expressvpn\expressvpn-ui\expressvpnnotificationservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
920"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2412 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1032C:\Windows\system32\net1 stop expressvpnsplittunnelC:\Windows\system32\net1.exenet.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
1096"C:\Program Files\ExpressVPN\expressvpn-ui\..\bootstrap\x86\nssm.exe" set ExpressVPNService AppParameters --workdir C:\ProgramData\ExpressVPN\v4\ --client-version 7.7.8 --client-build 7.7.8.161 --verbose startC:\Program Files\ExpressVPN\bootstrap\x86\nssm.exeExpressVPN-Installer.exe
User:
admin
Company:
ExpressVPN
Integrity Level:
HIGH
Description:
Service Manager
Exit code:
0
Version:
2.24-1-ga3819d9
Modules
Images
c:\program files\expressvpn\bootstrap\x86\nssm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
1248rundll32.exe "C:\Windows\Installer\MSI1698.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_3872453 9 WixSharp Setup!ExpressVpn.Client.Setup.CustomActions.SetWindowsBuildC:\Windows\system32\rundll32.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1404"C:\Program Files\ExpressVPN\expressvpn-ui\..\expressvpnd\expressvpnd.exe" --workdir C:\ProgramData\ExpressVPN\v4\ --client-version 7.7.8 --client-build 7.7.8.161 --verbose startC:\Program Files\ExpressVPN\expressvpnd\expressvpnd.exe
nssm.exe
User:
SYSTEM
Company:
ExpressVPN
Integrity Level:
SYSTEM
Description:
ExpressVPN Service
Exit code:
0
Version:
3.0.5
Modules
Images
c:\program files\expressvpn\expressvpnd\expressvpnd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
1412C:\Windows\system32\MsiExec.exe -Embedding 5E479FDC0FC01786A42263A38EE9270EC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1520C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
5 346
Read events
3 119
Write events
2 157
Delete events
70

Modification events

(PID) Process:(2344) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2344) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2344) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2344) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2344) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2344) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2344) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2344) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:1512-13197841398593750
Value:
0
(PID) Process:(2344) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(2344) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:2344-13218736166185500
Value:
259
Executable files
151
Suspicious files
96
Text files
617
Unknown types
33

Dropped files

PID
Process
Filename
Type
2344chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ec5f30e7-053c-46e0-8ef9-3695e4e11bc8.tmp
MD5:
SHA256:
2344chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp
MD5:
SHA256:
2344chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.oldtext
MD5:
SHA256:
2344chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF39aad1.TMPtext
MD5:
SHA256:
2344chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
2344chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.oldtext
MD5:
SHA256:
2344chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldtext
MD5:
SHA256:
2344chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
MD5:
SHA256:
2344chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.oldtext
MD5:
SHA256:
2344chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.oldtext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
32
DNS requests
30
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1896
chrome.exe
GET
204
216.58.207.67:80
http://www.gstatic.com/generate_204
US
whitelisted
1896
chrome.exe
GET
302
172.217.18.110:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx
US
html
511 b
whitelisted
1896
chrome.exe
GET
302
172.217.18.110:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx
US
html
532 b
whitelisted
2344
chrome.exe
GET
200
91.199.212.52:80
http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt
GB
der
1.37 Kb
whitelisted
1896
chrome.exe
GET
200
13.32.12.235:80
http://x.ss2.us/x.cer
US
der
1.27 Kb
whitelisted
1896
chrome.exe
GET
200
84.15.64.140:80
http://r1---sn-cpux-8ov6.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx?cms_redirect=yes&mip=85.206.166.82&mm=28&mn=sn-cpux-8ov6&ms=nvh&mt=1574262510&mv=m&mvi=0&pl=23&shardbypass=yes
LT
crx
293 Kb
whitelisted
1896
chrome.exe
GET
200
84.15.64.141:80
http://r2---sn-cpux-8ov6.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx?cms_redirect=yes&mip=85.206.166.82&mm=28&mn=sn-cpux-8ov6&ms=nvh&mt=1574262510&mv=m&mvi=1&pcm2cms=yes&pl=23&shardbypass=yes
LT
crx
862 Kb
whitelisted
2344
chrome.exe
GET
200
91.199.212.52:80
http://crt.comodoca.com/COMODORSAAddTrustCA.crt
GB
der
1.37 Kb
whitelisted
1896
chrome.exe
GET
200
13.107.4.50:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.4 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1896
chrome.exe
216.58.207.35:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
1896
chrome.exe
172.217.22.77:443
accounts.google.com
Google Inc.
US
whitelisted
1896
chrome.exe
99.84.92.15:443
download.expressvpn.xyz
AT&T Services, Inc.
US
unknown
1896
chrome.exe
172.217.18.100:443
www.google.com
Google Inc.
US
whitelisted
1896
chrome.exe
172.217.18.99:443
ssl.gstatic.com
Google Inc.
US
whitelisted
1896
chrome.exe
13.107.4.50:80
www.download.windowsupdate.com
Microsoft Corporation
US
whitelisted
1896
chrome.exe
99.84.92.29:443
download.expressvpn.xyz
AT&T Services, Inc.
US
unknown
1896
chrome.exe
172.217.16.206:443
clients2.google.com
Google Inc.
US
whitelisted
1896
chrome.exe
216.58.207.67:80
www.gstatic.com
Google Inc.
US
whitelisted
1896
chrome.exe
13.32.12.235:80
x.ss2.us
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
clientservices.googleapis.com
  • 216.58.207.35
whitelisted
download.expressvpn.xyz
  • 99.84.92.15
  • 99.84.92.29
  • 99.84.92.97
  • 99.84.92.31
whitelisted
accounts.google.com
  • 172.217.22.77
shared
x.ss2.us
  • 13.32.12.232
  • 13.32.12.235
  • 13.32.12.4
  • 13.32.12.252
whitelisted
www.google.com
  • 172.217.18.100
malicious
ssl.gstatic.com
  • 172.217.18.99
whitelisted
www.download.windowsupdate.com
  • 13.107.4.50
whitelisted
www.gstatic.com
  • 216.58.207.67
whitelisted
clients2.google.com
  • 172.217.16.206
whitelisted
redirector.gvt1.com
  • 172.217.18.110
whitelisted

Threats

No threats detected
No debug info