File name:

KTL_5.7.3.exe

Full analysis: https://app.any.run/tasks/4f880d6f-2ecf-483b-b400-7bc4af7857e0
Verdict: Malicious activity
Analysis date: June 14, 2025, 02:48:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
mpress
autoit
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections
MD5:

EC86FA9D7462B9CCF45201274645E67D

SHA1:

A654AB9D5487CB84775262B1E34795E70B41FF86

SHA256:

C081004CB7AABA284FEB580DF12F6CA777D1DA07479EACAC39533C182DC3E1F6

SSDEEP:

49152:oAKda+xbKBV6Z0m3aXL227BRzxX2kpFKZNMr9xKtGQC2qk3jROJjAAfgdX3pXaed:j+RK6ZF3e7LxX2khK4Qje4dX3p9vmnOj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • KTL_5.7.3.exe (PID: 6124)
      • KTL_5.7.3.exe (PID: 1604)
  • SUSPICIOUS

    • Adds/modifies Windows certificates

      • KTL_5.7.3.exe (PID: 6124)
    • Reads Microsoft Outlook installation path

      • KTL_5.7.3.exe (PID: 6124)
    • Reads Internet Explorer settings

      • KTL_5.7.3.exe (PID: 6124)
    • There is functionality for taking screenshot (YARA)

      • KTL_5.7.3.exe (PID: 6124)
    • Reads security settings of Internet Explorer

      • KTL_5.7.3.exe (PID: 6124)
  • INFO

    • Create files in a temporary directory

      • KTL_5.7.3.exe (PID: 6124)
    • Reads the computer name

      • KTL_5.7.3.exe (PID: 6124)
    • Application launched itself

      • firefox.exe (PID: 6896)
      • firefox.exe (PID: 5496)
    • The sample compiled with english language support

      • KTL_5.7.3.exe (PID: 6124)
    • Checks supported languages

      • KTL_5.7.3.exe (PID: 6124)
    • Mpress packer has been detected

      • KTL_5.7.3.exe (PID: 6124)
    • The process uses AutoIt

      • KTL_5.7.3.exe (PID: 6124)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 5496)
    • Checks proxy server information

      • KTL_5.7.3.exe (PID: 6124)
    • Manual execution by a user

      • firefox.exe (PID: 6896)
    • Reads mouse settings

      • KTL_5.7.3.exe (PID: 6124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:02:17 16:42:41+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit, No debug
PEType: PE32
LinkerVersion: 14.16
CodeSize: 633856
InitializedDataSize: 1301504
UninitializedDataSize: -
EntryPoint: 0x1df3f8
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 5.7.3.0
ProductVersionNumber: 5.7.3.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileVersion: 5.7.3.0
ProductVersion: 5.7.3.0
ProductName: Kaspersky Tweak Lite
OriginalFileName: KTL
InternalName: KTL
FileDescription: Kaspersky Tweak Lite
CompanyName: TAWAB Soft 2025
LegalTrademarks: TAWAB Soft 2025
LegalCopyright: TAWAB Soft 2025
Comments: please visit : https://sites.google.com/view/samsoft
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
13
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ktl_5.7.3.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs ktl_5.7.3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1296"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 3440 -prefsLen 36996 -prefMapHandle 3444 -prefMapSize 272997 -ipcHandle 1320 -initialChannelId {1daa6afc-48bb-4c76-ab0c-708d07ea06b7} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1380"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 0 -prefsHandle 4956 -prefsLen 44905 -prefMapHandle 4960 -prefMapSize 272997 -ipcHandle 4880 -initialChannelId {447bd238-9b87-4436-9b32-810090d044f1} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 6 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
1604"C:\Users\admin\AppData\Local\Temp\KTL_5.7.3.exe" C:\Users\admin\AppData\Local\Temp\KTL_5.7.3.exeexplorer.exe
User:
admin
Company:
TAWAB Soft 2025
Integrity Level:
MEDIUM
Description:
Kaspersky Tweak Lite
Exit code:
3221226540
Version:
5.7.3.0
Modules
Images
c:\users\admin\appdata\local\temp\ktl_5.7.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2468"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5036 -prefsLen 39068 -prefMapHandle 5040 -prefMapSize 272997 -jsInitHandle 5044 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5048 -initialChannelId {97b8d7fa-e714-4bfb-a60e-33d87ebe6c52} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
2696"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 1980 -prefsLen 36520 -prefMapHandle 1984 -prefMapSize 272997 -ipcHandle 2052 -initialChannelId {9fd7d216-12e1-4ce6-a734-4b1ee7854b76} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
3588"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4176 -prefsLen 44877 -prefMapHandle 4180 -prefMapSize 272997 -jsInitHandle 4184 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4156 -initialChannelId {581cdd74-d73b-4fb7-a2bc-371bbb33107c} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
5496"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
5504"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 2204 -prefsLen 36520 -prefMapHandle 2208 -prefMapSize 272997 -ipcHandle 2216 -initialChannelId {fdf6dfe3-8f81-4609-bc76-dfce69d1b773} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
6124"C:\Users\admin\AppData\Local\Temp\KTL_5.7.3.exe" C:\Users\admin\AppData\Local\Temp\KTL_5.7.3.exe
explorer.exe
User:
admin
Company:
TAWAB Soft 2025
Integrity Level:
HIGH
Description:
Kaspersky Tweak Lite
Version:
5.7.3.0
Modules
Images
c:\users\admin\appdata\local\temp\ktl_5.7.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
6224"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3336 -prefsLen 36996 -prefMapHandle 3340 -prefMapSize 272997 -jsInitHandle 3344 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3348 -initialChannelId {83ab3515-eddc-4656-a968-9ddf92cce006} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
Total events
8 918
Read events
8 913
Write events
5
Delete events
0

Modification events

(PID) Process:(6124) KTL_5.7.3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\1573B2F840D61F0B0B16AEDE5A35726F9E93117B
Operation:writeName:Blob
Value:
1900000001000000100000000482B43DE35322C3316263CAA047B71E0F00000001000000140000003321029F5D2AA18F786D64B9E0F6974ED14430AF0200000001000000C40000001C0000006C00000001000000000000000000000000000000010000007B00380042004600320036004300440046002D0046003100430046002D0034003800420031002D0041004500380038002D003200370033003400300036004400300045004500320045007D00000000004D006900630072006F0073006F0066007400200042006100730065002000430072007900700074006F0067007200610070006800690063002000500072006F00760069006400650072002000760031002E003000000000000B000000010000000200000000000300000001000000140000001573B2F840D61F0B0B16AEDE5A35726F9E93117B140000000100000014000000C249345BDD960BACF1A4722906D8E08F8253957820000000010000007802000030820274308201DDA00302010202110084A4E6838DC066869EC2E8B759251B40300D06092A864886F70D0101050500305431133011060355040C0C0A544157414220496E632E31133011060355040B0C0A544157414220496E632E31133011060355040A0C0A544157414220496E632E3113301106035504030C0A544157414220496E632E301E170D3230303130313036343830395A170D3435303130313036343830395A305431133011060355040C0C0A544157414220496E632E31133011060355040B0C0A544157414220496E632E31133011060355040A0C0A544157414220496E632E3113301106035504030C0A544157414220496E632E30819F300D06092A864886F70D010101050003818D003081890281810085A57ABF7363A26064014FE26DEB8E8870DEDED94E04A591821F72509524C6611AB43A36ECEE63E558989C6BC21A46006039F0F26F45B660A17252FD511ADB5435624573A893ACB95E40E4FE887D9E610F93DA3F8EAE6610180BCE1601947B165C9BBB622FF9CF7CBBCA8DCD653DD21A7A4688B04597A761C97DB8D73ADB8AEF0203010001A3463044300E0603551D0F0101FF04040302078030130603551D25040C300A06082B06010505070303301D0603551D0E04160414C249345BDD960BACF1A4722906D8E08F82539578300D06092A864886F70D0101050500038181003F9676C4420AF79A4EC4F8805077D7B106B84F0855366716486B1D531FBC3BE661B244158D7EBA6DD20A9A9DD87FF427C93595AA0A6238B6F1CAF341C5686CF9AA031AC66B6C0C1D31F58DFAC1284550EA510B99FE73C4EE7F4FD121EC21FB9DBF7E13E0689235F2B8655C50D3838CC2684196B995CD57DFE0109D506CF83F60
(PID) Process:(6124) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6124) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6124) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5496) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
Executable files
0
Suspicious files
161
Text files
15
Unknown types
1

Dropped files

PID
Process
Filename
Type
6124KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\Nolicense.jpgimage
MD5:3BDC5C25DE0F1A8C29C44049AB77CB8C
SHA256:53F5FEE17915B07125DFA2E2101C41960D18DCC0C3AFCFBDFF740E8B746F9635
6124KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\licReset.icoimage
MD5:65E328AC8667E56B91F34411635E4F5A
SHA256:134F2698140BA21472646DBED559956BD06EB40C3363813B8696182E6F3ADEDA
6124KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\licExpo.icoimage
MD5:ACB74483BF38B4497FCFD0B275FFE743
SHA256:E09A4C4062797E06CE8DD03960A43067EEA2BEAABF70C7FFE370F6434F56D698
6124KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\flag_usa.jpgimage
MD5:37CC8C7241C52CF03BA78EAA368975C0
SHA256:016C98C51F7326E5DCA1EF44DF06F71B21B51E49442CA1F5E751EC8ED75E7AA8
5496firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
5496firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
6124KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\DelTraces.icoimage
MD5:5F63D7837ACDE31C13C8D3C905BC4D6D
SHA256:7D9DC98DADA1E641ABD39459A5B735164486CA0FE93A705E5A8EBFC5E57926BF
5496firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
5496firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
5496firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
35
DNS requests
64
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
5496
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
5496
firefox.exe
POST
200
2.16.206.148:80
http://r10.o.lencr.org/
unknown
whitelisted
5496
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
5496
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/we2
unknown
whitelisted
5496
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
5496
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
5496
firefox.exe
POST
200
2.16.206.143:80
http://r11.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5552
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
whitelisted
5496
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted
content-signature-chains.prod.autograph.services.mozaws.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.36.137.203
whitelisted
spocs.getpocket.com
  • 34.36.137.203
whitelisted

Threats

No threats detected
No debug info