File name:

ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe

Full analysis: https://app.any.run/tasks/2681e5de-2a05-4df5-bc01-a12232d9523e
Verdict: Malicious activity
Analysis date: April 11, 2024, 13:14:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D63F153BA77F9DEE790D171A5A3D9D4D

SHA1:

C4A2491426A1E4E2ED4D858BD33C053616E3B6D8

SHA256:

C0BFB4B702F81C9C04BA578846C58CA41923824F1729BBD379D53AF6708703CA

SSDEEP:

98304:UgIjhRwfnbTAyAB+Wj+mOpkoFZKssPnqrOpVTJvU6f0hvpfJEUjdVouB8U+j74jU:anAI1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe (PID: 3488)
      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe (PID: 4008)
      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
    • Create files in the Startup directory

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
    • Creates a writable file in the system directory

      • DCA.Edge.Console.exe (PID: 2668)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe (PID: 3488)
      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe (PID: 4008)
      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
    • Uses TASKKILL.EXE to kill process

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
    • Reads the Windows owner or organization settings

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
    • Process drops legitimate windows executable

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
    • Reads the Internet Settings

      • DCA.Edge.Console.exe (PID: 3308)
      • DCA.Edge.Console.exe (PID: 1772)
      • DCA.Edge.TrayIcon.exe (PID: 680)
    • Reads security settings of Internet Explorer

      • DCA.Edge.Console.exe (PID: 3308)
      • DCA.Edge.Console.exe (PID: 1772)
      • DCA.Edge.Console.exe (PID: 2668)
      • DCA.Edge.TrayIcon.exe (PID: 680)
    • Checks Windows Trust Settings

      • DCA.Edge.Console.exe (PID: 3308)
      • DCA.Edge.Console.exe (PID: 1772)
      • DCA.Edge.Console.exe (PID: 2668)
      • DCA.Edge.TrayIcon.exe (PID: 680)
    • Reads settings of System Certificates

      • DCA.Edge.Console.exe (PID: 3308)
      • DCA.Edge.TrayIcon.exe (PID: 680)
      • DCA.Edge.Console.exe (PID: 1772)
    • Starts SC.EXE for service management

      • DCA.Edge.Console.exe (PID: 3308)
    • Executes as Windows Service

      • DCA.Edge.Console.exe (PID: 2668)
    • Searches for installed software

      • DCA.Edge.Console.exe (PID: 2668)
    • Non-standard symbols in registry

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
    • Adds/modifies Windows certificates

      • DCA.Edge.Console.exe (PID: 2668)
  • INFO

    • Checks supported languages

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 1836)
      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe (PID: 4008)
      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe (PID: 3488)
      • DCA.Edge.TrayIcon.exe (PID: 680)
      • DCA.Edge.Console.exe (PID: 1772)
      • DCA.Edge.Console.exe (PID: 2668)
      • DCA.Edge.Console.exe (PID: 3308)
    • Reads the computer name

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 1836)
      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
      • DCA.Edge.Console.exe (PID: 3308)
      • DCA.Edge.TrayIcon.exe (PID: 680)
      • DCA.Edge.Console.exe (PID: 1772)
      • DCA.Edge.Console.exe (PID: 2668)
    • Create files in a temporary directory

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe (PID: 4008)
      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe (PID: 3488)
      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
    • Creates files in the program directory

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
      • DCA.Edge.Console.exe (PID: 3308)
      • DCA.Edge.Console.exe (PID: 2668)
    • Reads the machine GUID from the registry

      • DCA.Edge.Console.exe (PID: 3308)
      • DCA.Edge.Console.exe (PID: 1772)
      • DCA.Edge.TrayIcon.exe (PID: 680)
      • DCA.Edge.Console.exe (PID: 2668)
    • Reads the software policy settings

      • DCA.Edge.Console.exe (PID: 3308)
      • DCA.Edge.Console.exe (PID: 1772)
      • DCA.Edge.Console.exe (PID: 2668)
      • DCA.Edge.TrayIcon.exe (PID: 680)
    • Creates a software uninstall entry

      • ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp (PID: 3180)
    • Reads Environment values

      • DCA.Edge.TrayIcon.exe (PID: 680)
      • DCA.Edge.Console.exe (PID: 2668)
    • Reads product name

      • DCA.Edge.Console.exe (PID: 2668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (57.2)
.exe | Win32 Executable (generic) (18.2)
.exe | Win16/32 Executable Delphi generic (8.3)
.exe | Generic Win/DOS Executable (8)
.exe | DOS Executable Generic (8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:06 14:39:04+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 360448
UninitializedDataSize: -
EntryPoint: 0x117dc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.5.7.9296
ProductVersionNumber: 1.5.7.9296
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: ECI Software Solutions, Inc.
FileDescription: ECI DCA Setup
FileVersion: 1.5.7.9296
LegalCopyright: ©2016-2024 ECI Software Solutions, Inc.
ProductName: ECI DCA
ProductVersion: 1.5.7.9296
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
12
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
start eci dca 1.5.7.9296 [h5xsyp3ru6zh].exe eci dca 1.5.7.9296 [h5xsyp3ru6zh].tmp no specs eci dca 1.5.7.9296 [h5xsyp3ru6zh].exe eci dca 1.5.7.9296 [h5xsyp3ru6zh].tmp taskkill.exe no specs taskkill.exe no specs dca.edge.console.exe no specs sc.exe no specs sc.exe no specs dca.edge.trayicon.exe no specs dca.edge.console.exe no specs dca.edge.console.exe

Process information

PID
CMD
Path
Indicators
Parent process
680"C:\Program Files\ECI DCA\DCA.Edge.TrayIcon.exe"C:\Program Files\ECI DCA\DCA.Edge.TrayIcon.exeECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp
User:
admin
Company:
ECI Software Solutions, Inc
Integrity Level:
MEDIUM
Description:
ECI DCA Service Monitor
Version:
1.5.7.9296
Modules
Images
c:\program files\eci dca\dca.edge.trayicon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
748"taskkill.exe" /f /t /im DCA.Edge.TrayIcon.exeC:\Windows\System32\taskkill.exeECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1308"C:\Windows\system32\sc.exe" create "DCAPulse" start= delayed-auto DisplayName= "ECI DCA" binPath= "\"C:\Program Files\ECI DCA\DCA.Edge.Console.exe\" --config \"C:\ProgramData\ECI DCA\dca.config\"" C:\Windows\System32\sc.exeDCA.Edge.Console.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1772"C:\Program Files\ECI DCA\DCA.Edge.Console.exe" start-service C:\Program Files\ECI DCA\DCA.Edge.Console.exeECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp
User:
admin
Company:
ECI Software Solutions, Inc
Integrity Level:
HIGH
Description:
ECI DCA
Exit code:
0
Version:
1.5.7.9296
Modules
Images
c:\program files\eci dca\dca.edge.console.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1836"C:\Users\admin\AppData\Local\Temp\is-T810P.tmp\ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp" /SL5="$E0170,3478115,428032,C:\Users\admin\AppData\Local\Temp\ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe" C:\Users\admin\AppData\Local\Temp\is-T810P.tmp\ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-t810p.tmp\eci dca 1.5.7.9296 [h5xsyp3ru6zh].tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2256"taskkill.exe" /im DCA.Edge.TrayIcon.exeC:\Windows\System32\taskkill.exeECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2388"C:\Windows\system32\sc.exe" failure "DCAPulse" reset= 180 actions= restart/5000/restart/30000/restart/180000C:\Windows\System32\sc.exeDCA.Edge.Console.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2668"C:\Program Files\ECI DCA\DCA.Edge.Console.exe" --config "C:\ProgramData\ECI DCA\dca.config"C:\Program Files\ECI DCA\DCA.Edge.Console.exe
services.exe
User:
SYSTEM
Company:
ECI Software Solutions, Inc
Integrity Level:
SYSTEM
Description:
ECI DCA
Version:
1.5.7.9296
Modules
Images
c:\program files\eci dca\dca.edge.console.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3180"C:\Users\admin\AppData\Local\Temp\is-PJ9LA.tmp\ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp" /SL5="$100130,3478115,428032,C:\Users\admin\AppData\Local\Temp\ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe" /SPAWNWND=$16013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-PJ9LA.tmp\ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp
ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-pj9la.tmp\eci dca 1.5.7.9296 [h5xsyp3ru6zh].tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3308"C:\Program Files\ECI DCA\DCA.Edge.Console.exe" config --config "C:\ProgramData\ECI DCA\dca.config" --installer "C:\Users\admin\AppData\Local\Temp\ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exe" --install-service C:\Program Files\ECI DCA\DCA.Edge.Console.exeECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmp
User:
admin
Company:
ECI Software Solutions, Inc
Integrity Level:
HIGH
Description:
ECI DCA
Exit code:
0
Version:
1.5.7.9296
Modules
Images
c:\program files\eci dca\dca.edge.console.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
25 814
Read events
25 661
Write events
134
Delete events
19

Modification events

(PID) Process:(3180) ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
6C0C000082CEAE26128CDA01
(PID) Process:(3180) ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
13AE3C4FF83AB4A8B80FA37D0D8E3F9CDCBD51A0CC71D3A6E13AB7D8FBD097C0
(PID) Process:(3180) ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3180) ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\ECI DCA\Abot.dll
(PID) Process:(3180) ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
E6E65CA379265E66921B86E11123F3A4D5DEC1DB0BEEFE924C3711C119A1596B
(PID) Process:(3308) DCA.Edge.Console.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3308) DCA.Edge.Console.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3308) DCA.Edge.Console.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3308) DCA.Edge.Console.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3308) DCA.Edge.Console.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
97
Suspicious files
6
Text files
6
Unknown types
4

Dropped files

PID
Process
Filename
Type
4008ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exeC:\Users\admin\AppData\Local\Temp\is-T810P.tmp\ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpexecutable
MD5:
SHA256:
3488ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].exeC:\Users\admin\AppData\Local\Temp\is-PJ9LA.tmp\ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpexecutable
MD5:
SHA256:
3180ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpC:\Users\admin\AppData\Local\Temp\is-F3SCE.tmp\idp.dllexecutable
MD5:
SHA256:
3180ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpC:\Program Files\ECI DCA\is-3ALO6.tmpexecutable
MD5:
SHA256:
3180ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpC:\Program Files\ECI DCA\unins000.exeexecutable
MD5:
SHA256:
3180ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpC:\Program Files\ECI DCA\is-A3O32.tmpexecutable
MD5:
SHA256:
3180ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpC:\Program Files\ECI DCA\Abot.dllexecutable
MD5:
SHA256:
3180ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpC:\Program Files\ECI DCA\is-CCTAN.tmpexecutable
MD5:
SHA256:
3180ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpC:\Program Files\ECI DCA\AngleSharp.dllexecutable
MD5:
SHA256:
3180ECI DCA 1.5.7.9296 [H5XSYP3RU6ZH].tmpC:\Program Files\ECI DCA\is-OEV7B.tmpexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
7
DNS requests
8
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2668
DCA.Edge.Console.exe
GET
304
88.221.110.91:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6f620e2de5fecb97
unknown
unknown
2668
DCA.Edge.Console.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
unknown
2668
DCA.Edge.Console.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA98u5eOYdBR7R%2Fa5LSCbuo%3D
unknown
unknown
2668
DCA.Edge.Console.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2668
DCA.Edge.Console.exe
88.221.110.91:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2668
DCA.Edge.Console.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2668
DCA.Edge.Console.exe
18.194.186.127:443
updates.printfleetcdn.com
AMAZON-02
DE
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 88.221.110.91
  • 2.16.100.168
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
updates.printfleetcdn.com
  • 18.194.186.127
unknown
1712841273.5DZOMQ1RC4J12HUT2ZNI4RZH97NOYZH6T9JC4J2VENV67Z7W00.H5XSYP3RU6ZH.ECI-DCA-1-5-7-9296.Microsoft-Windows-NT-6-1-7601-Service-Pack-1.ping.reg.pf-d.ca
unknown

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info