File name:

KTL_5.7.3.exe

Full analysis: https://app.any.run/tasks/4f880d6f-2ecf-483b-b400-7bc4af7857e0
Verdict: Malicious activity
Analysis date: June 14, 2025, 02:48:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
mpress
autoit
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections
MD5:

EC86FA9D7462B9CCF45201274645E67D

SHA1:

A654AB9D5487CB84775262B1E34795E70B41FF86

SHA256:

C081004CB7AABA284FEB580DF12F6CA777D1DA07479EACAC39533C182DC3E1F6

SSDEEP:

49152:oAKda+xbKBV6Z0m3aXL227BRzxX2kpFKZNMr9xKtGQC2qk3jROJjAAfgdX3pXaed:j+RK6ZF3e7LxX2khK4Qje4dX3p9vmnOj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • KTL_5.7.3.exe (PID: 1604)
      • KTL_5.7.3.exe (PID: 6124)
  • SUSPICIOUS

    • Adds/modifies Windows certificates

      • KTL_5.7.3.exe (PID: 6124)
    • Reads security settings of Internet Explorer

      • KTL_5.7.3.exe (PID: 6124)
    • Reads Microsoft Outlook installation path

      • KTL_5.7.3.exe (PID: 6124)
    • Reads Internet Explorer settings

      • KTL_5.7.3.exe (PID: 6124)
    • There is functionality for taking screenshot (YARA)

      • KTL_5.7.3.exe (PID: 6124)
  • INFO

    • The sample compiled with english language support

      • KTL_5.7.3.exe (PID: 6124)
    • Reads mouse settings

      • KTL_5.7.3.exe (PID: 6124)
    • Checks supported languages

      • KTL_5.7.3.exe (PID: 6124)
    • Create files in a temporary directory

      • KTL_5.7.3.exe (PID: 6124)
    • Reads the computer name

      • KTL_5.7.3.exe (PID: 6124)
    • Checks proxy server information

      • KTL_5.7.3.exe (PID: 6124)
    • Manual execution by a user

      • firefox.exe (PID: 6896)
    • Application launched itself

      • firefox.exe (PID: 6896)
      • firefox.exe (PID: 5496)
    • The process uses AutoIt

      • KTL_5.7.3.exe (PID: 6124)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 5496)
    • Mpress packer has been detected

      • KTL_5.7.3.exe (PID: 6124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:02:17 16:42:41+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit, No debug
PEType: PE32
LinkerVersion: 14.16
CodeSize: 633856
InitializedDataSize: 1301504
UninitializedDataSize: -
EntryPoint: 0x1df3f8
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 5.7.3.0
ProductVersionNumber: 5.7.3.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileVersion: 5.7.3.0
ProductVersion: 5.7.3.0
ProductName: Kaspersky Tweak Lite
OriginalFileName: KTL
InternalName: KTL
FileDescription: Kaspersky Tweak Lite
CompanyName: TAWAB Soft 2025
LegalTrademarks: TAWAB Soft 2025
LegalCopyright: TAWAB Soft 2025
Comments: please visit : https://sites.google.com/view/samsoft
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
13
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ktl_5.7.3.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs ktl_5.7.3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1296"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 3440 -prefsLen 36996 -prefMapHandle 3444 -prefMapSize 272997 -ipcHandle 1320 -initialChannelId {1daa6afc-48bb-4c76-ab0c-708d07ea06b7} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1380"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 0 -prefsHandle 4956 -prefsLen 44905 -prefMapHandle 4960 -prefMapSize 272997 -ipcHandle 4880 -initialChannelId {447bd238-9b87-4436-9b32-810090d044f1} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 6 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
1604"C:\Users\admin\AppData\Local\Temp\KTL_5.7.3.exe" C:\Users\admin\AppData\Local\Temp\KTL_5.7.3.exeexplorer.exe
User:
admin
Company:
TAWAB Soft 2025
Integrity Level:
MEDIUM
Description:
Kaspersky Tweak Lite
Exit code:
3221226540
Version:
5.7.3.0
Modules
Images
c:\users\admin\appdata\local\temp\ktl_5.7.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2468"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5036 -prefsLen 39068 -prefMapHandle 5040 -prefMapSize 272997 -jsInitHandle 5044 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5048 -initialChannelId {97b8d7fa-e714-4bfb-a60e-33d87ebe6c52} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
2696"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 1980 -prefsLen 36520 -prefMapHandle 1984 -prefMapSize 272997 -ipcHandle 2052 -initialChannelId {9fd7d216-12e1-4ce6-a734-4b1ee7854b76} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
3588"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4176 -prefsLen 44877 -prefMapHandle 4180 -prefMapSize 272997 -jsInitHandle 4184 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4156 -initialChannelId {581cdd74-d73b-4fb7-a2bc-371bbb33107c} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
5496"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
5504"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 2204 -prefsLen 36520 -prefMapHandle 2208 -prefMapSize 272997 -ipcHandle 2216 -initialChannelId {fdf6dfe3-8f81-4609-bc76-dfce69d1b773} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
6124"C:\Users\admin\AppData\Local\Temp\KTL_5.7.3.exe" C:\Users\admin\AppData\Local\Temp\KTL_5.7.3.exe
explorer.exe
User:
admin
Company:
TAWAB Soft 2025
Integrity Level:
HIGH
Description:
Kaspersky Tweak Lite
Version:
5.7.3.0
Modules
Images
c:\users\admin\appdata\local\temp\ktl_5.7.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
6224"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3336 -prefsLen 36996 -prefMapHandle 3340 -prefMapSize 272997 -jsInitHandle 3344 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3348 -initialChannelId {83ab3515-eddc-4656-a968-9ddf92cce006} -parentPid 5496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5496" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
Total events
8 918
Read events
8 913
Write events
5
Delete events
0

Modification events

(PID) Process:(6124) KTL_5.7.3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\1573B2F840D61F0B0B16AEDE5A35726F9E93117B
Operation:writeName:Blob
Value:
1900000001000000100000000482B43DE35322C3316263CAA047B71E0F00000001000000140000003321029F5D2AA18F786D64B9E0F6974ED14430AF0200000001000000C40000001C0000006C00000001000000000000000000000000000000010000007B00380042004600320036004300440046002D0046003100430046002D0034003800420031002D0041004500380038002D003200370033003400300036004400300045004500320045007D00000000004D006900630072006F0073006F0066007400200042006100730065002000430072007900700074006F0067007200610070006800690063002000500072006F00760069006400650072002000760031002E003000000000000B000000010000000200000000000300000001000000140000001573B2F840D61F0B0B16AEDE5A35726F9E93117B140000000100000014000000C249345BDD960BACF1A4722906D8E08F8253957820000000010000007802000030820274308201DDA00302010202110084A4E6838DC066869EC2E8B759251B40300D06092A864886F70D0101050500305431133011060355040C0C0A544157414220496E632E31133011060355040B0C0A544157414220496E632E31133011060355040A0C0A544157414220496E632E3113301106035504030C0A544157414220496E632E301E170D3230303130313036343830395A170D3435303130313036343830395A305431133011060355040C0C0A544157414220496E632E31133011060355040B0C0A544157414220496E632E31133011060355040A0C0A544157414220496E632E3113301106035504030C0A544157414220496E632E30819F300D06092A864886F70D010101050003818D003081890281810085A57ABF7363A26064014FE26DEB8E8870DEDED94E04A591821F72509524C6611AB43A36ECEE63E558989C6BC21A46006039F0F26F45B660A17252FD511ADB5435624573A893ACB95E40E4FE887D9E610F93DA3F8EAE6610180BCE1601947B165C9BBB622FF9CF7CBBCA8DCD653DD21A7A4688B04597A761C97DB8D73ADB8AEF0203010001A3463044300E0603551D0F0101FF04040302078030130603551D25040C300A06082B06010505070303301D0603551D0E04160414C249345BDD960BACF1A4722906D8E08F82539578300D06092A864886F70D0101050500038181003F9676C4420AF79A4EC4F8805077D7B106B84F0855366716486B1D531FBC3BE661B244158D7EBA6DD20A9A9DD87FF427C93595AA0A6238B6F1CAF341C5686CF9AA031AC66B6C0C1D31F58DFAC1284550EA510B99FE73C4EE7F4FD121EC21FB9DBF7E13E0689235F2B8655C50D3838CC2684196B995CD57DFE0109D506CF83F60
(PID) Process:(6124) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6124) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6124) KTL_5.7.3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5496) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
Executable files
0
Suspicious files
161
Text files
15
Unknown types
1

Dropped files

PID
Process
Filename
Type
6124KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\KAV.icoimage
MD5:07285205035CC97BB897BC9858439FD0
SHA256:58E5CFF5B042904D6AD8AEC159B5F46EE327FC2584EFB4082C211ACE2532089B
5496firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbinary
MD5:F091C5C3EC5D6496F4E048C8AC421A97
SHA256:CDDBC54FBA7987DEB7EEC077643E42B422F58B5F52FE2A4C41E6F8E25362B97B
6124KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\DelTraces.icoimage
MD5:5F63D7837ACDE31C13C8D3C905BC4D6D
SHA256:7D9DC98DADA1E641ABD39459A5B735164486CA0FE93A705E5A8EBFC5E57926BF
6124KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\~DF0113D0E8DEA3EB9F.TMPbinary
MD5:0F3D363BF8C6B8A187E58D2B2F8D878C
SHA256:DEBF0C02E854565D931E7E913E3EA3E98A9243013FC809E3E870EEEA26512AB1
6124KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\licExpo.icoimage
MD5:ACB74483BF38B4497FCFD0B275FFE743
SHA256:E09A4C4062797E06CE8DD03960A43067EEA2BEAABF70C7FFE370F6434F56D698
5496firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
6124KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\licImpo.icoimage
MD5:C383ED33ECEB598BC8CA280D6BD1479D
SHA256:1356D857499985BC5C25BB55FFF616DB83D0EDAE22E52F937C6C1E1E3A1CF395
6124KTL_5.7.3.exeC:\Users\admin\AppData\Local\Temp\flag_usa.jpgimage
MD5:37CC8C7241C52CF03BA78EAA368975C0
SHA256:016C98C51F7326E5DCA1EF44DF06F71B21B51E49442CA1F5E751EC8ED75E7AA8
5496firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
5496firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:2FD670934FEF0C60E2119BD874AAF470
SHA256:771A7C83CA015BDBC6AB86A7BD9B1D54E40062E28942D311A9178A0FE6433CF2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
35
DNS requests
64
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
5496
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
5496
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
5496
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
5496
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/we2
unknown
whitelisted
5496
firefox.exe
POST
200
2.16.206.148:80
http://r10.o.lencr.org/
unknown
whitelisted
5496
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
5496
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5552
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
whitelisted
5496
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted
content-signature-chains.prod.autograph.services.mozaws.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.36.137.203
whitelisted
spocs.getpocket.com
  • 34.36.137.203
whitelisted

Threats

No threats detected
No debug info