File name:

pedablesetup.exe

Full analysis: https://app.any.run/tasks/883db0d7-2b50-46eb-b3a2-e752fa035ecf
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 04, 2024, 09:41:50
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

63DD1C8E2F3E3957B5B53FC7A380A83C

SHA1:

B5B070D9C11BD66F4AF7181FB39DC0B5F472E8C7

SHA256:

B92EB6CEB56A894358F642CDEE6C80C71D71B07B0140BCA3BC5C8F839B7C1E1C

SSDEEP:

3072:AnQKO1LtRSBrhabS7ygxKQObUSViJYfMl8NHkPDzJ96gXRirtcff9/Y:yQj1Qrsb0xZSVrHN8JEgXRoCni

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • pedablesetup.exe (PID: 4276)
    • Process requests binary or script from the Internet

      • pedable.exe (PID: 5032)
    • Executable content was dropped or overwritten

      • nchsetup.exe (PID: 3812)
      • pedable.exe (PID: 5032)
      • tbsetup.exe (PID: 5616)
      • pedablesetup.exe (PID: 4276)
    • Application launched itself

      • tbsetup.exe (PID: 5616)
    • Potential Corporate Privacy Violation

      • pedable.exe (PID: 5032)
    • Starts itself from another location

      • nchsetup.exe (PID: 3812)
  • INFO

    • Checks supported languages

      • pedablesetup.exe (PID: 4276)
      • nchsetup.exe (PID: 3812)
    • Create files in a temporary directory

      • pedablesetup.exe (PID: 4276)
    • Reads the computer name

      • pedablesetup.exe (PID: 4276)
      • nchsetup.exe (PID: 3812)
    • The process uses the downloaded file

      • pedablesetup.exe (PID: 4276)
    • Process checks computer location settings

      • pedablesetup.exe (PID: 4276)
    • Application launched itself

      • msedge.exe (PID: 1164)
      • msedge.exe (PID: 6292)
    • Manual execution by a user

      • msedge.exe (PID: 6292)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 7304)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:10:27 03:28:15+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: -
InitializedDataSize: 141824
UninitializedDataSize: -
EntryPoint: 0x20af
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (Australian)
CharacterSet: Unicode
CompanyName: NCH Software
FileDescription: Pedable
FileVersion: 2.01
LegalCopyright: NCH Software
InternalName: Pedable
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
202
Monitored processes
59
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start pedablesetup.exe nchsetup.exe sppextcomobj.exe no specs slui.exe pedable.exe pedable.exe no specs tbsetup.exe tbsetup.exe n1s.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs pedablesetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
488"C:\Users\admin\AppData\Local\Temp\n1s.exe" "C:\Users\admin\AppData\Local\Temp\tbsetup.exe"C:\Users\admin\AppData\Local\Temp\n1s.exe
tbsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
NCH Toolbox
Exit code:
0
Version:
1.13
Modules
Images
c:\users\admin\appdata\local\temp\n1s.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1164"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.nch.com.au/toolbox/versions.htmlC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exen1s.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1184"C:\Users\admin\AppData\Local\Temp\pedablesetup.exe" C:\Users\admin\AppData\Local\Temp\pedablesetup.exeexplorer.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
Pedable
Exit code:
3221226540
Version:
2.01
Modules
Images
c:\users\admin\appdata\local\temp\pedablesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1504"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2184 --field-trial-handle=2416,i,9939224724809977074,16271453246533702073,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2180"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=1720 --field-trial-handle=2424,i,2010610476519593674,10012981014478166207,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2300"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2020 --field-trial-handle=2424,i,2010610476519593674,10012981014478166207,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2372"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4676 --field-trial-handle=2424,i,2010610476519593674,10012981014478166207,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3812"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe" "C:\Users\admin\AppData\Local\Temp\pedablesetup.exe"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe
pedablesetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
Pedable
Exit code:
0
Version:
2.01
Modules
Images
c:\users\admin\appdata\local\temp\n1s\nchsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3844"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=2200 --field-trial-handle=2424,i,2010610476519593674,10012981014478166207,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3928"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2412 --field-trial-handle=2416,i,9939224724809977074,16271453246533702073,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
8 372
Read events
8 327
Write events
43
Delete events
2

Modification events

(PID) Process:(3812) nchsetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\NCH Swift Sound\Pedable\Settings
Operation:writeName:VistaCheck
Value:
1
(PID) Process:(3812) nchsetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\NCH Swift Sound\Pedable\Settings
Operation:delete valueName:InstallNonAdmin
Value:
(PID) Process:(3812) nchsetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\NCH Swift Sound\Pedable\Settings
Operation:delete valueName:_InstallNonAdmin
Value:
(PID) Process:(3812) nchsetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\NCH Swift Sound\Pedable\Settings
Operation:writeName:InstallerPath
Value:
C:\Program Files (x86)\NCH Swift Sound\Pedable
(PID) Process:(3812) nchsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NCH Swift Sound\Pedable\Settings
Operation:writeName:InstallerPath
Value:
C:\Program Files (x86)\NCH Swift Sound\Pedable
(PID) Process:(3812) nchsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Pedable
Operation:writeName:DisplayName
Value:
Pedable
(PID) Process:(3812) nchsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Pedable
Operation:writeName:Publisher
Value:
NCH Software
(PID) Process:(3812) nchsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Pedable
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\NCH Swift Sound\Pedable\uninst.exe
(PID) Process:(3812) nchsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Pedable
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\NCH Swift Sound\Pedable\uninst.exe
(PID) Process:(3812) nchsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Pedable
Value:
"C:\Program Files (x86)\NCH Swift Sound\Pedable\pedable.exe" -logon
Executable files
10
Suspicious files
123
Text files
82
Unknown types
7

Dropped files

PID
Process
Filename
Type
4276pedablesetup.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exeexecutable
MD5:0BAD95343C66B2510B5F8291649D00F8
SHA256:F9685D1FEE6C0FFCBFECDD6421527367686195162AAC023BBECB91C86351E210
3812nchsetup.exeC:\Program Files (x86)\NCH Swift Sound\Pedable\uninst.exeexecutable
MD5:65BD3BA9434664FF093F42F24B46323C
SHA256:FE4DC83BA2DC75F89F84285E6AEA317D854D7E350B871A9376FB6BF13FAC2248
3812nchsetup.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Utilities\Backup Software.lnklnk
MD5:663F761B82382040995D5A25215EAD54
SHA256:5C44653C988CE347E67DA13F0F47967098C01B3DED5153879607C9F90E74F32F
3812nchsetup.exeC:\Program Files (x86)\NCH Swift Sound\Pedable\Help\overview.htmlhtml
MD5:2FFED7F76ECBA414EDC760710068FBD1
SHA256:23427D955CF1A674E90BF68F366FEE1C9F025F3ACA8496A53938A354B976F46C
3812nchsetup.exeC:\Program Files (x86)\NCH Swift Sound\Pedable\Help\usage.htmlhtml
MD5:54FD2FBDFD5BBF1FEEFEAE6350F8450E
SHA256:1F96D6C0D13FC65DA04C22894DF21F7686036576300D6FCD5BD12423FD7B3951
3812nchsetup.exeC:\Program Files (x86)\NCH Swift Sound\Pedable\Help\shortcut.htmlhtml
MD5:BB76F623475D0ED135E1A2E64BC96DE1
SHA256:E7C9A9B438D6080D4EE2CF5D9109EB92A28327C9E9472E5963E5C0D92CB54BCC
3812nchsetup.exeC:\Program Files (x86)\NCH Swift Sound\Pedable\Help\index.htmlhtml
MD5:361E66F29A5A22CBA7CFAA46DD751E6B
SHA256:1B7F3E94159C6B0C12840A75D351039108BF0AFA89031BEEAAEBDDF70202FFE1
3812nchsetup.exeC:\Program Files (x86)\NCH Swift Sound\Pedable\Help\hlp.csstext
MD5:1CB4FF819D5D4BC8FF8F3EB5FB647C47
SHA256:EAC606A2FE614538BA39AC74F75FA9258BFF251D21A719F09AA76A2BE8368C5D
3812nchsetup.exeC:\Program Files (x86)\NCH Swift Sound\Pedable\Help\arrowlist.gifimage
MD5:C2D463614F71780745E76AD71BEF0D3D
SHA256:1FD4764E084E7E78D6EBBFC060F79C4B778B407EE7BB4B2E9736794257816573
3812nchsetup.exeC:\Program Files (x86)\NCH Swift Sound\Pedable\Help\licenceterms.htmlhtml
MD5:954CD90A7B072086F23B6BB6AF29F332
SHA256:637A637BCE951B359031C5911214AA0D4842BAADE4113B56F92C18CB1F136906
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
43
TCP/UDP connections
131
DNS requests
89
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1988
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
512
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3812
nchsetup.exe
GET
200
66.39.83.117:80
http://www.audiochannel.net/versions/pedable.txt
unknown
whitelisted
2120
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
488
n1s.exe
GET
200
66.39.83.117:80
http://www.audiochannel.net/versions/toolbox.txt
unknown
whitelisted
1492
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6328
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/d6787caf-caa9-4d56-acdb-2bd467c0ff21?P1=1728283616&P2=404&P3=2&P4=Ir4y2tSUX1dAs49ghBSvRkkhjD%2bkp%2f7KzP9A07abETvpn7f6G6oueHrbZx9Wefn6l8kqz8dURwr%2bOY6xjfQiRw%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5244
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5128
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
512
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
512
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
google.com
  • 142.250.186.174
whitelisted
go.microsoft.com
  • 184.28.89.167
  • 23.35.238.131
whitelisted
login.live.com
  • 20.190.159.4
  • 40.126.31.71
  • 20.190.159.71
  • 20.190.159.0
  • 40.126.31.67
  • 20.190.159.68
  • 20.190.159.75
  • 20.190.159.73
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
www.audiochannel.net
  • 66.39.83.117
  • 173.247.250.125
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

PID
Process
Class
Message
5032
pedable.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
5032
pedable.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
No debug info