File name:

ZipThis.exe

Full analysis: https://app.any.run/tasks/04ae183e-78fb-4fef-be92-325e25b782cb
Verdict: Malicious activity
Analysis date: January 07, 2025, 19:30:44
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
MD5:

22A6CB7348B496600E7151A8112CBAC9

SHA1:

F0CD50658868A3D347BEFF6977A54520C19AB640

SHA256:

BF2F238D09AC55E7BAF3D73C80C82D3DF935DAA6B94ADF67A299AD3665E879E2

SSDEEP:

98304:gw4Duw4xT2ZyydruTlIseLSzW81j2iXrVfY9cZm4zdFhb4jyH1ZI30KqNJwFs1Du:pqwqz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes powershell execution policy (RemoteSigned)

      • ZipThis.exe (PID: 6236)
  • SUSPICIOUS

    • Starts POWERSHELL.EXE for commands execution

      • ZipThis.exe (PID: 6236)
    • Gets path to any of the special folders (POWERSHELL)

      • powershell.exe (PID: 6836)
    • The process executes Powershell scripts

      • ZipThis.exe (PID: 6236)
    • Executable content was dropped or overwritten

      • ZipThis.exe (PID: 6236)
    • Searches for installed software

      • ZipThis.exe (PID: 6236)
    • The process drops C-runtime libraries

      • ZipThis.exe (PID: 6236)
    • Process drops legitimate windows executable

      • ZipThis.exe (PID: 6236)
    • Creates a software uninstall entry

      • ZipThis.exe (PID: 6236)
    • Reads security settings of Internet Explorer

      • ZipThis.exe (PID: 6236)
      • ZipThisApp.exe (PID: 6604)
      • ZipThisApp.exe (PID: 5240)
    • Reads the date of Windows installation

      • ZipThis.exe (PID: 6236)
  • INFO

    • Creates files or folders in the user directory

      • ZipThis.exe (PID: 6236)
    • Reads the machine GUID from the registry

      • ZipThis.exe (PID: 6236)
      • ZipThisApp.exe (PID: 6604)
      • Updater.exe (PID: 6944)
      • ZipThisApp.exe (PID: 5240)
      • Updater.exe (PID: 6032)
      • Updater.exe (PID: 4392)
    • Checks supported languages

      • ZipThis.exe (PID: 6236)
      • ZipThisApp.exe (PID: 6604)
      • Updater.exe (PID: 6944)
      • ZipThisApp.exe (PID: 5240)
      • Updater.exe (PID: 6032)
      • Updater.exe (PID: 4392)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 6836)
    • The process uses the downloaded file

      • powershell.exe (PID: 6836)
      • ZipThis.exe (PID: 6236)
    • The sample compiled with english language support

      • ZipThis.exe (PID: 6236)
    • Reads the computer name

      • ZipThis.exe (PID: 6236)
      • ZipThisApp.exe (PID: 6604)
      • Updater.exe (PID: 6944)
      • Updater.exe (PID: 6032)
    • Process checks computer location settings

      • ZipThis.exe (PID: 6236)
    • Application launched itself

      • chrome.exe (PID: 7132)
    • Reads the software policy settings

      • ZipThisApp.exe (PID: 6604)
      • Updater.exe (PID: 6944)
      • ZipThisApp.exe (PID: 5240)
      • Updater.exe (PID: 4392)
      • Updater.exe (PID: 6032)
    • Checks proxy server information

      • ZipThisApp.exe (PID: 6604)
      • Updater.exe (PID: 6032)
    • Manual execution by a user

      • Updater.exe (PID: 6944)
      • ZipThisApp.exe (PID: 5240)
      • Updater.exe (PID: 4392)
      • Updater.exe (PID: 6032)
    • Reads Environment values

      • ZipThisApp.exe (PID: 6604)
      • Updater.exe (PID: 6944)
      • ZipThisApp.exe (PID: 5240)
      • Updater.exe (PID: 6032)
    • Disables trace logs

      • ZipThisApp.exe (PID: 5240)
      • Updater.exe (PID: 4392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2071:09:11 02:59:51+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 48
CodeSize: 2688000
InitializedDataSize: 120320
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 10.1.28.102
ProductVersionNumber: 10.1.28.102
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: ZipThis
FileVersion: 10.1.28.102
InternalName: ZipThis.exe
LegalCopyright: Copyright © 2015-2023 Lightner Tok All rights reserved
LegalTrademarks: -
OriginalFileName: ZipThis.exe
ProductName: ZipThis
ProductVersion: 10.1.28.102
AssemblyVersion: 10.1.28.102
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
20
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start zipthis.exe powershell.exe no specs conhost.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs zipthisapp.exe chrome.exe no specs rundll32.exe no specs updater.exe zipthisapp.exe updater.exe updater.exe

Process information

PID
CMD
Path
Indicators
Parent process
244"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1936 --field-trial-handle=1940,i,14050589623492954840,11442928746944680388,262144 --variations-seed-version /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
624"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --extension-process --no-appcompat-clear --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=3724 --field-trial-handle=1940,i,14050589623492954840,11442928746944680388,262144 --variations-seed-version /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2324"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2300 --field-trial-handle=1940,i,14050589623492954840,11442928746944680388,262144 --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2676"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3192 --field-trial-handle=1940,i,14050589623492954840,11442928746944680388,262144 --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2928C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
4392"C:\Users\admin\AppData\Local\ZipThis\Updater.exe" C:\Users\admin\AppData\Local\ZipThis\Updater.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Updater
Exit code:
0
Version:
5.345.34.36
Modules
Images
c:\users\admin\appdata\local\zipthis\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4716"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3156 --field-trial-handle=1940,i,14050589623492954840,11442928746944680388,262144 --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5240"C:\Users\admin\AppData\Local\ZipThis\ZipThisApp.exe" C:\Users\admin\AppData\Local\ZipThis\ZipThisApp.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ZipThisApp
Exit code:
0
Version:
9.10.100.101
Modules
Images
c:\users\admin\appdata\local\zipthis\zipthisapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
5392"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2260 --field-trial-handle=1940,i,14050589623492954840,11442928746944680388,262144 --variations-seed-version /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6032"C:\Users\admin\AppData\Local\ZipThis\Updater.exe" C:\Users\admin\AppData\Local\ZipThis\Updater.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Updater
Exit code:
0
Version:
5.345.34.36
Modules
Images
c:\users\admin\appdata\local\zipthis\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
18 694
Read events
18 626
Write events
66
Delete events
2

Modification events

(PID) Process:(6236) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6236) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6236) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6236) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6236) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6236) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6236) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6236) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6236) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6236) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
24
Suspicious files
78
Text files
32
Unknown types
1

Dropped files

PID
Process
Filename
Type
6236ZipThis.exeC:\Users\admin\AppData\Local\ZipThis\zipthisUserId.txttext
MD5:FA16EAE54E69DE01CB2D6995997C1427
SHA256:90134D8AB0CBEF4AD3C0A8841778D8CC5E84EA0F7D30A6C69753984B0E92474D
6236ZipThis.exeC:\Users\admin\AppData\Roaming\SMCR\userId.txttext
MD5:FA16EAE54E69DE01CB2D6995997C1427
SHA256:90134D8AB0CBEF4AD3C0A8841778D8CC5E84EA0F7D30A6C69753984B0E92474D
6236ZipThis.exeC:\Users\admin\AppData\Local\ZipThis\Updates.zipcompressed
MD5:674D4C37B0C2888A2768CBE7D368C4DB
SHA256:777BCEC19FCEF78FC6E3451139456269FD9FDF10F68FBD8DE5B82AAABF21502E
6836powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:24021BC8F4770139094326A4E654CD8F
SHA256:2C421C2C3310DA38FD31A5C7F71B8B729821ACC8CEA606C87A98A868D70A57E7
6236ZipThis.exeC:\Users\admin\AppData\Local\ZipThis\Updater.dllexecutable
MD5:C355B5CA9F7B07667F96C1E30B9A0894
SHA256:27A7BA032F7D6CF787454C2FD036C95D13BE9FB489B26FD9050659AA23498DD6
6236ZipThis.exeC:\Users\admin\AppData\Local\ZipThis\concrt140.dllexecutable
MD5:9485D003573E0EAF7952AB23CC82EF7B
SHA256:5E0E8EAC57B86E2DE7CA7D6E8D34DDDEA602CE3660208FB53947A027635D59A1
6236ZipThis.exeC:\Users\admin\AppData\Local\ZipThis\msvcp140.dllexecutable
MD5:C3D497B0AFEF4BD7E09C7559E1C75B05
SHA256:1E57A6DF9E3742E31A1C6D9BFF81EBEEAE8A7DE3B45A26E5079D5E1CCE54CD98
6236ZipThis.exeC:\Users\admin\AppData\Local\ZipThis\vcamp140.dllexecutable
MD5:8441A618D2CEF67BDEDCA224FD61AFA2
SHA256:6CD300E597C477260809C5CA036993D923CD8BE304AE323C9C4D7776115FE62D
6236ZipThis.exeC:\Users\admin\AppData\Local\ZipThis\Updater.exeexecutable
MD5:8F3972F98564FC9D1E3E5A3840A0DA85
SHA256:CBDFE04B8F754E5E6150936EE604F0A478B79C6D0466EE155775EAD575ADEA90
6236ZipThis.exeC:\Users\admin\AppData\Local\ZipThis\msvcp140_codecvt_ids.dllexecutable
MD5:165308EE66D0B8F11CA20F3BCD410EA9
SHA256:08DF3AB1B59D1F7D63F0811838E4FCCC107087FCBC469D94975C0E44477058E7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
80
DNS requests
80
Threats
14

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5892
svchost.exe
GET
200
184.24.77.37:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5892
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.24.77.37:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7100
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6160
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7100
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
184.24.77.37:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
5892
svchost.exe
184.24.77.37:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown
5892
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
104.126.37.147:443
www.bing.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1076
svchost.exe
23.56.254.14:443
go.microsoft.com
Mobile Telecommunications Company
KW
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 184.24.77.37
  • 184.24.77.12
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
google.com
  • 142.250.186.142
whitelisted
www.bing.com
  • 104.126.37.147
  • 104.126.37.139
  • 104.126.37.145
  • 104.126.37.144
  • 104.126.37.128
  • 104.126.37.153
  • 104.126.37.146
  • 104.126.37.129
  • 104.126.37.137
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.56.254.14
whitelisted
apb.thisilient.com
  • 45.33.84.9
unknown
login.live.com
  • 40.126.32.68
  • 20.190.160.14
  • 20.190.160.17
  • 40.126.32.138
  • 40.126.32.140
  • 40.126.32.72
  • 20.190.160.22
  • 20.190.160.20
whitelisted
sts.thisilient.com
  • 45.33.84.9
unknown

Threats

PID
Process
Class
Message
5392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
5392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] BootstrapCDN (stackpath .bootstrapcdn .com)
5392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
5392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] BootstrapCDN (stackpath .bootstrapcdn .com)
5392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
5392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
5392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
5392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
5392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] BootstrapCDN (stackpath .bootstrapcdn .com)
5392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
No debug info