File name:

digipass-nativebridge-installer-2.8.8 (1).exe

Full analysis: https://app.any.run/tasks/7412935b-d4f1-4e65-a9e8-99eba719eaa2
Verdict: Malicious activity
Analysis date: June 06, 2025, 09:19:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

D4C99E3A9CEC565ABDC7F2EAFFC32374

SHA1:

6D5A70BB096D85C1FF2711202B9F7D617CB6BDA3

SHA256:

B98211C7E91EA7A0D3346291F841B96E6B8CE2A16148E0B177BB7EF70B83FCC7

SSDEEP:

98304:oLbkHLWqniKHqvGgDLu5AfD1t15Z8TqhRklI9EvLxymk4i4f4eJJ36csIEXeCv6Y:NPrGmTr/e+ayRN6I

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 6048)
      • msiexec.exe (PID: 2040)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 5956)
      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 6048)
    • Searches for installed software

      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 6048)
    • Creates a software uninstall entry

      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 6048)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 2040)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 2040)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 2040)
  • INFO

    • The sample compiled with english language support

      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 5956)
      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 6048)
      • msiexec.exe (PID: 2040)
    • Create files in a temporary directory

      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 5956)
      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 6048)
    • Checks supported languages

      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 5956)
      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 6048)
      • msiexec.exe (PID: 2040)
      • msiexec.exe (PID: 6392)
      • digipass-nativebridge-monitor.exe (PID: 6136)
      • digipass-nativebridge.exe (PID: 644)
    • Reads the computer name

      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 6048)
      • msiexec.exe (PID: 2040)
      • msiexec.exe (PID: 6392)
    • Creates files or folders in the user directory

      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 6048)
      • msiexec.exe (PID: 2040)
      • digipass-nativebridge.exe (PID: 644)
    • Launching a file from a Registry key

      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 6048)
      • msiexec.exe (PID: 2040)
    • Reads the machine GUID from the registry

      • digipass-nativebridge-installer-2.8.8 (1).exe (PID: 6048)
      • msiexec.exe (PID: 2040)
    • Reads the software policy settings

      • msiexec.exe (PID: 2040)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2040)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2040)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:09:17 05:33:38+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.16
CodeSize: 299008
InitializedDataSize: 163328
UninitializedDataSize: -
EntryPoint: 0x2df71
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.8.8.0
ProductVersionNumber: 2.8.8.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: OneSpan Inc.
FileDescription: DIGIPASS Native Bridge 2.8.8
FileVersion: 2.8.8
InternalName: setup
LegalCopyright: Copyright (c) OneSpan Inc.. All rights reserved.
OriginalFileName: digipass-nativebridge-installer.exe
ProductName: DIGIPASS Native Bridge 2.8.8
ProductVersion: 2.8.8
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start digipass-nativebridge-installer-2.8.8 (1).exe digipass-nativebridge-installer-2.8.8 (1).exe msiexec.exe msiexec.exe no specs digipass-nativebridge-monitor.exe no specs digipass-nativebridge.exe no specs conhost.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
644trueC:\Users\admin\AppData\Local\OneSpan\NativeBridge\digipass-nativebridge.exedigipass-nativebridge-monitor.exe
User:
admin
Company:
VASCO Data Security
Integrity Level:
MEDIUM
Description:
DIGIPASS Native Bridge
Version:
2.8.8.0
Modules
Images
c:\users\admin\appdata\local\onespan\nativebridge\digipass-nativebridge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2040C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3140\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exedigipass-nativebridge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5548C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5956"C:\Users\admin\AppData\Local\Temp\digipass-nativebridge-installer-2.8.8 (1).exe" C:\Users\admin\AppData\Local\Temp\digipass-nativebridge-installer-2.8.8 (1).exe
explorer.exe
User:
admin
Company:
OneSpan Inc.
Integrity Level:
MEDIUM
Description:
DIGIPASS Native Bridge 2.8.8
Exit code:
0
Version:
2.8.8
Modules
Images
c:\users\admin\appdata\local\temp\digipass-nativebridge-installer-2.8.8 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6048"C:\Users\admin\AppData\Local\Temp\{3CB14F6E-3A97-4FDC-B9A2-FA21BCE68A1A}\.cr\digipass-nativebridge-installer-2.8.8 (1).exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\digipass-nativebridge-installer-2.8.8 (1).exe" -burn.filehandle.attached=752 -burn.filehandle.self=588 C:\Users\admin\AppData\Local\Temp\{3CB14F6E-3A97-4FDC-B9A2-FA21BCE68A1A}\.cr\digipass-nativebridge-installer-2.8.8 (1).exe
digipass-nativebridge-installer-2.8.8 (1).exe
User:
admin
Company:
OneSpan Inc.
Integrity Level:
MEDIUM
Description:
DIGIPASS Native Bridge 2.8.8
Exit code:
0
Version:
2.8.8
Modules
Images
c:\users\admin\appdata\local\temp\{3cb14f6e-3a97-4fdc-b9a2-fa21bce68a1a}\.cr\digipass-nativebridge-installer-2.8.8 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6136C:\Users\admin\AppData\Local\OneSpan\NativeBridge\digipass-nativebridge-monitor.exeC:\Users\admin\AppData\Local\OneSpan\NativeBridge\digipass-nativebridge-monitor.exemsiexec.exe
User:
admin
Company:
VASCO Data Security
Integrity Level:
MEDIUM
Description:
DIGIPASS Native Bridge Monitor
Version:
2.8.8.0
Modules
Images
c:\users\admin\appdata\local\onespan\nativebridge\digipass-nativebridge-monitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6392C:\Windows\syswow64\MsiExec.exe -Embedding 7848C52642159163DB6B0EA067FED503C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
5 574
Read events
5 423
Write events
136
Delete events
15

Modification events

(PID) Process:(6048) digipass-nativebridge-installer-2.8.8 (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}
Operation:writeName:BundleCachePath
Value:
C:\Users\admin\AppData\Local\Package Cache\{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}\digipass-nativebridge-installer.exe
(PID) Process:(6048) digipass-nativebridge-installer-2.8.8 (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}
Operation:writeName:BundleUpgradeCode
Value:
{1A0B6F06-E133-494F-8F9A-1392ABAF675D}
(PID) Process:(6048) digipass-nativebridge-installer-2.8.8 (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}
Operation:writeName:BundleAddonCode
Value:
(PID) Process:(6048) digipass-nativebridge-installer-2.8.8 (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}
Operation:writeName:BundleDetectCode
Value:
(PID) Process:(6048) digipass-nativebridge-installer-2.8.8 (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}
Operation:writeName:BundlePatchCode
Value:
(PID) Process:(6048) digipass-nativebridge-installer-2.8.8 (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}
Operation:writeName:BundleVersion
Value:
2.8.8.0
(PID) Process:(6048) digipass-nativebridge-installer-2.8.8 (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}
Operation:writeName:VersionMajor
Value:
2
(PID) Process:(6048) digipass-nativebridge-installer-2.8.8 (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}
Operation:writeName:VersionMinor
Value:
8
(PID) Process:(6048) digipass-nativebridge-installer-2.8.8 (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}
Operation:writeName:BundleProviderKey
Value:
{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}
(PID) Process:(6048) digipass-nativebridge-installer-2.8.8 (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{be46a568-0503-4ce8-b4f8-a98fe4fbf75c}
Operation:writeName:BundleTag
Value:
Executable files
16
Suspicious files
11
Text files
21
Unknown types
10

Dropped files

PID
Process
Filename
Type
6048digipass-nativebridge-installer-2.8.8 (1).exeC:\Users\admin\AppData\Local\Temp\{F6C3A6E4-5597-43D3-9982-3E88E14F2C08}\.ba\1033\thm.wxlxml
MD5:E7606CC0D380A9EDFE74F101A3E4B17E
SHA256:6C940487318CA7D65C676C39C236F773EBC09DE34455B98619ED09DA919581FD
6048digipass-nativebridge-installer-2.8.8 (1).exeC:\Users\admin\AppData\Local\Temp\{F6C3A6E4-5597-43D3-9982-3E88E14F2C08}\Setup
MD5:
SHA256:
6048digipass-nativebridge-installer-2.8.8 (1).exeC:\Users\admin\AppData\Local\Package Cache\.unverified\Setup
MD5:
SHA256:
6048digipass-nativebridge-installer-2.8.8 (1).exeC:\Users\admin\AppData\Local\Package Cache\{D333A5B4-AED8-416D-A67F-429910C163FC}v2.8.8\digipass-nativebridge.msi
MD5:
SHA256:
2040msiexec.exeC:\Windows\Installer\121d06.msi
MD5:
SHA256:
6048digipass-nativebridge-installer-2.8.8 (1).exeC:\Users\admin\AppData\Local\Temp\{F6C3A6E4-5597-43D3-9982-3E88E14F2C08}\.ba\1031\thm.wxlxml
MD5:DE28714728966AF42D82D9946C121606
SHA256:A865E534047D67B85EE241468D89201119029A5E23CAE2539083312C4683910A
6048digipass-nativebridge-installer-2.8.8 (1).exeC:\Users\admin\AppData\Local\Temp\{F6C3A6E4-5597-43D3-9982-3E88E14F2C08}\.ba\1036\thm.wxlxml
MD5:BB86342BF3E435FE22E39601D0D68E07
SHA256:6136B04D2506B49186B1D2D7DC29A64FF00CD667B998D94B2FFCF7F707C695D2
6048digipass-nativebridge-installer-2.8.8 (1).exeC:\Users\admin\AppData\Local\Temp\{F6C3A6E4-5597-43D3-9982-3E88E14F2C08}\.ba\license.rtftext
MD5:8155C6F047D2C91DD91BE940A8387B02
SHA256:CFA1CE5AEC648B1DE6523146B96622E2D044C5F0D6AC1AF5C7C9D09EAF6FFA7D
6048digipass-nativebridge-installer-2.8.8 (1).exeC:\Users\admin\AppData\Local\Temp\{F6C3A6E4-5597-43D3-9982-3E88E14F2C08}\.ba\1043\thm.wxlxml
MD5:39A479BBD5FB4CCA6513A6F8A6C87B55
SHA256:18E771640ED392C4379F979739A33F656FDD8363BB9B8C841D26C1D467F74748
6048digipass-nativebridge-installer-2.8.8 (1).exeC:\Users\admin\AppData\Local\Temp\{F6C3A6E4-5597-43D3-9982-3E88E14F2C08}\.ba\1031\license.rtftext
MD5:18D6B1D1C665251382F845EBAA75B157
SHA256:AB95992FBCAC0D7F35AFA8E4BE999D6F14A8E958864A93C3D6634E608A6EF71E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
36
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2040
msiexec.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
2040
msiexec.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAvgmNFFZyIznWrT%2FiecVZ0%3D
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7552
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7552
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
7548
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
7348
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2040
msiexec.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
7548
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
40.126.31.128:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.181.238
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
localhost.vdsnb.com
  • 127.0.0.1
unknown
login.live.com
  • 40.126.31.128
  • 20.190.159.68
  • 20.190.159.23
  • 40.126.31.67
  • 20.190.159.130
  • 40.126.31.2
  • 40.126.31.1
  • 40.126.31.129
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
www.bing.com
  • 92.123.104.42
  • 92.123.104.38
  • 92.123.104.52
  • 92.123.104.35
  • 92.123.104.34
  • 92.123.104.58
  • 92.123.104.37
  • 92.123.104.36
  • 92.123.104.49
whitelisted
th.bing.com
  • 92.123.104.67
  • 92.123.104.59
  • 92.123.104.63
  • 92.123.104.62
  • 92.123.104.65
  • 92.123.104.4
  • 92.123.104.66
  • 92.123.104.58
  • 92.123.104.61
whitelisted

Threats

No threats detected
No debug info