File name:

Kiwi_SyslogGen.exe

Full analysis: https://app.any.run/tasks/0ee94857-d3bf-4d47-95cd-b2bc717136c7
Verdict: Malicious activity
Analysis date: June 19, 2025, 14:09:18
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

A4E687D7DDF1B17DCBACCA7D5D7BD609

SHA1:

B3D5A30D5784579E67B6B732E818613CA23E796A

SHA256:

C2B5017542138F236D7C2CB05DB65C4E9754D276388FAC2BD900796E97354331

SSDEEP:

49152:DRu4jvTgiRNx9LBejMLFqcfK0xV39xmnJbC5frYDZvhpRsUclpzYUt/kvRT3LytH:Dhv0c39BLFH9VaJ+5MJRsUclpzYUyvRa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Kiwi_SyslogGen.exe (PID: 5644)
    • Creates a software uninstall entry

      • Kiwi_SyslogGen.exe (PID: 5644)
    • Process drops legitimate windows executable

      • Kiwi_SyslogGen.exe (PID: 5644)
    • Creates/Modifies COM task schedule object

      • Kiwi_SyslogGen.exe (PID: 5644)
    • Reads security settings of Internet Explorer

      • Kiwi_SyslogGen.exe (PID: 5644)
    • There is functionality for taking screenshot (YARA)

      • Kiwi_SyslogGen.exe (PID: 5644)
  • INFO

    • Creates files in the program directory

      • Kiwi_SyslogGen.exe (PID: 5644)
    • Checks supported languages

      • Kiwi_SyslogGen.exe (PID: 5644)
      • Kiwi_SyslogGen.exe (PID: 6652)
      • identity_helper.exe (PID: 6512)
    • Reads the computer name

      • Kiwi_SyslogGen.exe (PID: 5644)
      • Kiwi_SyslogGen.exe (PID: 6652)
      • identity_helper.exe (PID: 6512)
    • Reads mouse settings

      • Kiwi_SyslogGen.exe (PID: 5644)
      • Kiwi_SyslogGen.exe (PID: 6652)
    • The sample compiled with english language support

      • Kiwi_SyslogGen.exe (PID: 5644)
    • Creates files or folders in the user directory

      • Kiwi_SyslogGen.exe (PID: 5644)
    • Create files in a temporary directory

      • Kiwi_SyslogGen.exe (PID: 5644)
      • Kiwi_SyslogGen.exe (PID: 6652)
    • Reads Environment values

      • identity_helper.exe (PID: 6512)
    • Application launched itself

      • msedge.exe (PID: 4544)
      • msedge.exe (PID: 7000)
      • msedge.exe (PID: 2140)
    • Manual execution by a user

      • msedge.exe (PID: 2140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2005:06:20 21:40:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 22528
InitializedDataSize: 120832
UninitializedDataSize: 1024
EntryPoint: 0x316f
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
25
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start kiwi_sysloggen.exe kiwi_sysloggen.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe no specs kiwi_sysloggen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1100"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3628,i,10430451142996450511,12847717466125259376,262144 --variations-seed-version --mojo-platform-channel-handle=3644 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2140"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --disable-quic --flag-switches-end --do-not-de-elevate --single-argument C:\Program Files (x86)\Kiwi SyslogGen\Readme.htmC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2232"C:\Users\admin\AppData\Local\Temp\Kiwi_SyslogGen.exe" C:\Users\admin\AppData\Local\Temp\Kiwi_SyslogGen.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\kiwi_sysloggen.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2296"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --disable-quic --onnx-enabled-for-ee --string-annotations --always-read-main-dll --field-trial-handle=5348,i,10430451142996450511,12847717466125259376,262144 --variations-seed-version --mojo-platform-channel-handle=4892 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2380"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4288,i,10430451142996450511,12847717466125259376,262144 --variations-seed-version --mojo-platform-channel-handle=2020 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2716"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x290,0x298,0x29c,0x28c,0x2a8,0x7ffc4550f208,0x7ffc4550f214,0x7ffc4550f220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3092"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2300,i,10430451142996450511,12847717466125259376,262144 --variations-seed-version --mojo-platform-channel-handle=2292 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3644"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x284,0x288,0x28c,0x27c,0x294,0x7ffc4550f208,0x7ffc4550f214,0x7ffc4550f220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3964"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5344,i,10430451142996450511,12847717466125259376,262144 --variations-seed-version --mojo-platform-channel-handle=5164 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4080"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2224,i,15920902046250135371,15057617359054786292,262144 --variations-seed-version --mojo-platform-channel-handle=2368 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
5 717
Read events
5 458
Write events
203
Delete events
56

Modification events

(PID) Process:(5644) Kiwi_SyslogGen.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(5644) Kiwi_SyslogGen.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A4C466B8-499F-101B-BB78-00AA00383CBB}\TypeLib
Operation:writeName:Version
Value:
6.0
(PID) Process:(5644) Kiwi_SyslogGen.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A4C46780-499F-101B-BB78-00AA00383CBB}\TypeLib
Operation:writeName:Version
Value:
6.0
(PID) Process:(5644) Kiwi_SyslogGen.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{45046D60-08CA-11CF-A90F-00AA0062BB4C}\TypeLib
Operation:writeName:Version
Value:
6.0
(PID) Process:(5644) Kiwi_SyslogGen.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4495AD01-C993-11D1-A3E4-00A0C90AEA82}\TypeLib
Operation:writeName:Version
Value:
6.0
(PID) Process:(5644) Kiwi_SyslogGen.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{41A7D761-6018-11CF-9016-00AA0068841E}\TypeLib
Operation:writeName:Version
Value:
6.0
(PID) Process:(5644) Kiwi_SyslogGen.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{41A7D760-6018-11CF-9016-00AA0068841E}\TypeLib
Operation:writeName:Version
Value:
6.0
(PID) Process:(5644) Kiwi_SyslogGen.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B28FA150-0FF0-11CF-A911-00AA0062BB4C}\TypeLib
Operation:writeName:Version
Value:
6.0
(PID) Process:(5644) Kiwi_SyslogGen.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2CE46480-1A08-11CF-AD63-00AA00614F3E}\TypeLib
Operation:writeName:Version
Value:
6.0
(PID) Process:(5644) Kiwi_SyslogGen.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BE8F9800-2AAA-11CF-AD67-00AA00614F3E}\TypeLib
Operation:writeName:Version
Value:
6.0
Executable files
6
Suspicious files
33
Text files
41
Unknown types
19

Dropped files

PID
Process
Filename
Type
5644Kiwi_SyslogGen.exeC:\Users\admin\AppData\Local\Temp\nsz59F8.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
5644Kiwi_SyslogGen.exeC:\Users\admin\AppData\Local\Temp\nsz59F8.tmp\ioSpecial.iniini
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
5644Kiwi_SyslogGen.exeC:\Users\admin\AppData\Local\Temp\nsz59F8.tmp\Splash.dllexecutable
MD5:00D07DCF7A412AA1D89B688E333C1DC3
SHA256:702F7486FE412917CD8510B49343970CD2E1E4841815B428E1B4B5CA92D15254
5644Kiwi_SyslogGen.exeC:\Program Files (x86)\Kiwi SyslogGen\Readme.htmxml
MD5:19A783AE929D9AC75CC6AC88A08DB785
SHA256:280A2084D3019B30AAD38827A432F5EDE9FE617086C120F84230A14A72BA9984
5644Kiwi_SyslogGen.exeC:\Users\admin\AppData\Local\Temp\nsz59F8.tmp\modern-header.bmpimage
MD5:940C56737BF9BB69CE7A31C623D4E87A
SHA256:766A893FE962AEFD27C574CB05F25CF895D3FC70A00DB5A6FA73D573F571AEFC
5644Kiwi_SyslogGen.exeC:\Program Files (x86)\Kiwi SyslogGen\Kiwi_logo.gifimage
MD5:4356A455ECEFC233DBC21EA8C6DFF233
SHA256:FE015CB5AAA4BE478DA048AB64DD8CD5637A4BFCDCEEBD8584551CA316643683
5644Kiwi_SyslogGen.exeC:\Program Files (x86)\Kiwi SyslogGen\Kiwi_SyslogGen.exeexecutable
MD5:B76D2F5E3C9323654F78CC9A8E25F940
SHA256:402AFB8982A822F180EBAB37D5C8F5E2094D5663C45E4B7C51D0892746DDAC85
5644Kiwi_SyslogGen.exeC:\Program Files (x86)\Kiwi SyslogGen\Kiwi_bp.gifimage
MD5:6B476279D96576E9F7768ACDE399A3FD
SHA256:AEADCE0826CE8C4F24FC2580751A975B4A9D5B4CF6CA45D2A85023D78D1F2C5B
5644Kiwi_SyslogGen.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kiwi Enterprises\Kiwi SyslogGen\Kiwi SyslogGen.lnklnk
MD5:644D47F788FB4FE7D821472D396C84B1
SHA256:5D28BFA0D1D52C1A450D7A46DCB6A1E3A330CB04DD398BD2AB7AF9B0A83277BD
5644Kiwi_SyslogGen.exeC:\Program Files (x86)\Kiwi SyslogGen\Kiwi_SyslogGen.chmchm
MD5:823369B38C802E9B44996923DDD13D08
SHA256:337A7A50034E7A6C1D92A94585F05C6B16A6B69DE65D482290111A14FA19A495
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
46
DNS requests
33
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2596
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
23.55.104.172:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5712
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:DgMcQLL2fTmxsSZGcWug41L9VE1KgUIKa98RCkjiWs8&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
7348
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7348
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2276
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2336
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
2596
svchost.exe
40.126.31.128:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2596
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.55.104.172:80
crl.microsoft.com
Akamai International B.V.
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.238
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.31.128
  • 40.126.31.129
  • 40.126.31.71
  • 20.190.159.2
  • 40.126.31.69
  • 40.126.31.3
  • 40.126.31.0
  • 40.126.31.1
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.55.104.172
  • 23.55.104.190
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.19
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted

Threats

No threats detected
No debug info