File name:

omensuperhub-win64-v1.9.18.0.zip

Full analysis: https://app.any.run/tasks/a96435f1-2570-403d-aa7f-894761c070b7
Verdict: Malicious activity
Analysis date: March 06, 2026, 17:17:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

36519998A9F8B75E4D5B83F7186C0076

SHA1:

2F00573D79CF7C2EFEC7168BEE8DE67405EDE639

SHA256:

C2980DD413A85A5F8DC08F4262C7408B4DBA4CDD3E874BB7790257FDE34F393B

SSDEEP:

98304:0mQYIDVTnynjLlt1jO4ShG8HQA6Y2FlEgbILZqSChqziGM9umWudGVmJMfuDGaEq:UQS9R8TIigOxcC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe (PID: 8368)
    • Executable content was dropped or overwritten

      • PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe (PID: 8368)
    • Searches for installed software

      • OmenSuperHub.exe (PID: 9036)
      • OmenSuperHub.exe (PID: 8568)
    • Executes application which crashes

      • OmenSuperHub.exe (PID: 9036)
      • OmenSuperHub.exe (PID: 8568)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 8596)
      • PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe (PID: 8368)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 8596)
    • Manual execution by a user

      • PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe (PID: 8368)
      • PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe (PID: 6020)
      • OmenSuperHub.exe (PID: 8876)
      • OmenSuperHub.exe (PID: 9036)
      • OmenSuperHub.exe (PID: 8568)
      • notepad.exe (PID: 7668)
    • Generic archive extractor

      • WinRAR.exe (PID: 8596)
    • Checks supported languages

      • PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe (PID: 8368)
      • OmenSuperHub.exe (PID: 9036)
      • OmenSuperHub.exe (PID: 8568)
    • Reads the computer name

      • PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe (PID: 8368)
      • OmenSuperHub.exe (PID: 9036)
      • OmenSuperHub.exe (PID: 8568)
    • Creates files in the program directory

      • PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe (PID: 8368)
    • Creates a software uninstall entry

      • PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe (PID: 8368)
    • Reads the machine GUID from the registry

      • OmenSuperHub.exe (PID: 9036)
      • OmenSuperHub.exe (PID: 8568)
    • Checks proxy server information

      • WerFault.exe (PID: 4784)
      • WerFault.exe (PID: 7532)
      • slui.exe (PID: 1948)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 4784)
      • WerFault.exe (PID: 7532)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:09:18 23:41:28
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: OmenSuperHub/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
167
Monitored processes
10
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe pawnio_setup(先安装这个,新的硬件监控所需驱动).exe no specs pawnio_setup(先安装这个,新的硬件监控所需驱动).exe omensuperhub.exe no specs slui.exe omensuperhub.exe werfault.exe notepad.exe no specs omensuperhub.exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
1948C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4784C:\WINDOWS\system32\WerFault.exe -u -p 9036 -s 1700C:\Windows\System32\WerFault.exe
OmenSuperHub.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
6020"C:\Users\admin\Desktop\OmenSuperHub\PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe" C:\Users\admin\Desktop\OmenSuperHub\PawnIO_setup(先安装这个,新的硬件监控所需驱动).exeexplorer.exe
User:
admin
Company:
namazso
Integrity Level:
MEDIUM
Description:
PawnIO Setup
Exit code:
3221226540
Version:
2.0.1.0
Modules
Images
c:\users\admin\desktop\omensuperhub\pawnio_setup(先安装这个,新的硬件监控所需驱动).exe
c:\windows\system32\ntdll.dll
7532C:\WINDOWS\system32\WerFault.exe -u -p 8568 -s 1664C:\Windows\System32\WerFault.exe
OmenSuperHub.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\oleaut32.dll
7668"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\OmenSuperHub\error.logC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
8368"C:\Users\admin\Desktop\OmenSuperHub\PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe" C:\Users\admin\Desktop\OmenSuperHub\PawnIO_setup(先安装这个,新的硬件监控所需驱动).exe
explorer.exe
User:
admin
Company:
namazso
Integrity Level:
HIGH
Description:
PawnIO Setup
Exit code:
0
Version:
2.0.1.0
Modules
Images
c:\users\admin\desktop\omensuperhub\pawnio_setup(先安装这个,新的硬件监控所需驱动).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
8568"C:\Users\admin\Desktop\OmenSuperHub\OmenSuperHub.exe" C:\Users\admin\Desktop\OmenSuperHub\OmenSuperHub.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
OmenSuperHub
Exit code:
3762504530
Version:
1.9.18.0
Modules
Images
c:\users\admin\desktop\omensuperhub\omensuperhub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
8596"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\omensuperhub-win64-v1.9.18.0.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
8876"C:\Users\admin\Desktop\OmenSuperHub\OmenSuperHub.exe" C:\Users\admin\Desktop\OmenSuperHub\OmenSuperHub.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
OmenSuperHub
Exit code:
3221226540
Version:
1.9.18.0
Modules
Images
c:\users\admin\desktop\omensuperhub\omensuperhub.exe
c:\windows\system32\ntdll.dll
9036"C:\Users\admin\Desktop\OmenSuperHub\OmenSuperHub.exe" C:\Users\admin\Desktop\OmenSuperHub\OmenSuperHub.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
OmenSuperHub
Exit code:
3762504530
Version:
1.9.18.0
Modules
Images
c:\users\admin\desktop\omensuperhub\omensuperhub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
14 666
Read events
14 602
Write events
45
Delete events
19

Modification events

(PID) Process:(8596) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(8596) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(8596) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(8596) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(8596) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(8596) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\omensuperhub-win64-v1.9.18.0.zip
(PID) Process:(8596) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(8596) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(8596) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(8596) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
6
Suspicious files
6
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
4784WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_OmenSuperHub.exe_142a5f124b269d81386880ab35e7e291f7b54f_7f5c0092_d7008c10-67e6-43bf-b50d-e187e2dedb1d\Report.wer
MD5:
SHA256:
4784WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\OmenSuperHub.exe.9036.dmp
MD5:
SHA256:
7532WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_OmenSuperHub.exe_142a5f124b269d81386880ab35e7e291f7b54f_7f5c0092_c87e51f5-8be6-43fb-acc6-c0fc313e3914\Report.wer
MD5:
SHA256:
7532WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\OmenSuperHub.exe.8568.dmp
MD5:
SHA256:
8596WinRAR.exeC:\Users\admin\Desktop\OmenSuperHub\OmenSuperHub.exeexecutable
MD5:C31FDB39C4052E553DBD46BB4286DF5C
SHA256:C3386E0DFA1DEC861011C4653ADF5836534171937449417038807E59B728F3F2
4784WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER28BE.tmp.dmpbinary
MD5:59BA28FA574C8743BB5861A77E1D6D45
SHA256:AC678E6B9D9DA5840D5534BB76AEF1A7C84A9F9C08D2D5A8AB62798DD3260672
8368PawnIO_setup(先安装这个,新的硬件监控所需驱动).exeC:\Program Files\PawnIO\PawnIOLib.dllexecutable
MD5:2CA484C07ABCF8AC21E61E202FBBD90A
SHA256:320416E8549FDC1730C4DB6B37E30FA6255CF99603444DF6A02B3CD8A39E20D1
8596WinRAR.exeC:\Users\admin\Desktop\OmenSuperHub\PawnIO_setup(先安装这个,新的硬件监控所需驱动).exeexecutable
MD5:B44F4B412AF6075E9BCC4F87F4C07674
SHA256:3A34B5DF231F10F252C4B50D3C777534B2A2CEC5E1DF9466AB2DCA401C068C44
8368PawnIO_setup(先安装这个,新的硬件监控所需驱动).exeC:\Program Files\PawnIO\PawnIOLib.htext
MD5:1D285F6DFD9B2C5C31496F84A8C799C3
SHA256:79E50E2921761A7306548909E8AE7A59915BDA1F9E97F3549BC5645911E24891
8368PawnIO_setup(先安装这个,新的硬件监控所需驱动).exeC:\Program Files\PawnIO\PawnIO.sysexecutable
MD5:1EF8FBE40198892CDA4A57811068221B
SHA256:E19F274B9F3C917445BFF19A80BBE2EE34A54995E62BE50073122B20D86AF900
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
42
TCP/UDP connections
32
DNS requests
28
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3004
svchost.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
132
SIHClient.exe
GET
304
74.179.77.204:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
132
SIHClient.exe
GET
200
74.178.240.51:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
132
SIHClient.exe
GET
200
74.179.77.204:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
132
SIHClient.exe
GET
304
74.179.77.204:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
3004
svchost.exe
GET
200
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=1&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.70 Kb
whitelisted
356
svchost.exe
POST
400
40.126.32.74:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
356
svchost.exe
POST
400
40.126.32.74:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
4784
WerFault.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3004
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
8736
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3004
svchost.exe
2.16.164.49:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
3004
svchost.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
3412
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
356
svchost.exe
40.126.32.74:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
356
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 142.251.36.110
whitelisted
self.events.data.microsoft.com
  • 52.182.143.208
  • 20.42.65.90
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.32.74
  • 20.190.160.17
  • 20.190.160.3
  • 40.126.32.136
  • 20.190.160.67
  • 40.126.32.140
  • 20.190.160.20
  • 20.190.160.132
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 162.159.142.9
  • 172.66.2.5
whitelisted
slscr.update.microsoft.com
  • 74.179.77.204
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 74.178.240.51
whitelisted

Threats

PID
Process
Class
Message
3004
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info