File name:

uwu.bat

Full analysis: https://app.any.run/tasks/471f3c2a-f6e0-4a1d-8ff6-a831e678be44
Verdict: Malicious activity
Analysis date: February 06, 2025, 22:47:07
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
python
arch-doc
Indicators:
MIME: text/x-msdos-batch
File info: DOS batch file, ASCII text, with CRLF line terminators
MD5:

7A7F49957B26D222821360B9DBAD0775

SHA1:

4D44B03B3587811BB43416F0C4BBB44C2730CB11

SHA256:

C5C8C3B60E70E2E6A44D3CA67A868062E97CD23F7DDC9F6EACE8FD8B70616F12

SSDEEP:

24:wsXyvghKGHBHAhv+yncCcnIHgXINqrQK4a84qzKm:OghKGHpk+6hyQUI8cK4nh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Script downloads file (POWERSHELL)

      • powershell.exe (PID: 6300)
    • Changes the autorun value in the registry

      • python-3.11.7-amd64.exe (PID: 7064)
  • SUSPICIOUS

    • Probably download files using WebClient

      • cmd.exe (PID: 6160)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 6160)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 6300)
      • python-3.11.7-amd64.exe (PID: 7040)
      • python-3.11.7-amd64.exe (PID: 7064)
      • python-3.11.7-amd64.exe (PID: 7156)
      • python.exe (PID: 6960)
    • Loads Python modules

      • python-3.11.7-amd64.exe (PID: 7064)
      • python.exe (PID: 7144)
      • python.exe (PID: 6960)
    • Searches for installed software

      • python-3.11.7-amd64.exe (PID: 7064)
      • dllhost.exe (PID: 6436)
    • Reads security settings of Internet Explorer

      • python-3.11.7-amd64.exe (PID: 7064)
    • Starts itself from another location

      • python-3.11.7-amd64.exe (PID: 7064)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6076)
    • Creates a software uninstall entry

      • python-3.11.7-amd64.exe (PID: 7064)
    • The process drops C-runtime libraries

      • python-3.11.7-amd64.exe (PID: 7064)
      • python-3.11.7-amd64.exe (PID: 7156)
      • msiexec.exe (PID: 6944)
    • Process drops legitimate windows executable

      • python-3.11.7-amd64.exe (PID: 7064)
      • python-3.11.7-amd64.exe (PID: 7156)
      • msiexec.exe (PID: 6944)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6944)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6944)
    • There is functionality for taking screenshot (YARA)

      • python-3.11.7-amd64.exe (PID: 7064)
    • Process drops python dynamic module

      • msiexec.exe (PID: 6944)
    • Application launched itself

      • python.exe (PID: 7144)
    • Starts CMD.EXE for commands execution

      • python.exe (PID: 6960)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 6944)
  • INFO

    • Disables trace logs

      • powershell.exe (PID: 6300)
    • Checks proxy server information

      • powershell.exe (PID: 6300)
    • Checks supported languages

      • python-3.11.7-amd64.exe (PID: 7040)
      • python-3.11.7-amd64.exe (PID: 7064)
      • python-3.11.7-amd64.exe (PID: 7156)
      • msiexec.exe (PID: 6944)
      • msiexec.exe (PID: 7084)
      • python.exe (PID: 7144)
      • python.exe (PID: 6960)
    • Create files in a temporary directory

      • python-3.11.7-amd64.exe (PID: 7040)
      • python-3.11.7-amd64.exe (PID: 7064)
      • python-3.11.7-amd64.exe (PID: 7156)
      • python.exe (PID: 7144)
      • python.exe (PID: 6960)
    • The sample compiled with english language support

      • powershell.exe (PID: 6300)
      • python-3.11.7-amd64.exe (PID: 7040)
      • python-3.11.7-amd64.exe (PID: 7064)
      • python-3.11.7-amd64.exe (PID: 7156)
      • msiexec.exe (PID: 6944)
      • python.exe (PID: 6960)
    • Reads the computer name

      • python-3.11.7-amd64.exe (PID: 7064)
      • python-3.11.7-amd64.exe (PID: 7156)
      • msiexec.exe (PID: 6944)
      • msiexec.exe (PID: 7084)
    • Process checks computer location settings

      • python-3.11.7-amd64.exe (PID: 7064)
    • Creates files or folders in the user directory

      • python-3.11.7-amd64.exe (PID: 7064)
      • msiexec.exe (PID: 6944)
    • Manages system restore points

      • SrTasks.exe (PID: 6704)
    • Creates files in the program directory

      • python-3.11.7-amd64.exe (PID: 7156)
    • Mutex for Python MSI log

      • msiexec.exe (PID: 6944)
      • python-3.11.7-amd64.exe (PID: 7156)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6944)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 6944)
      • python-3.11.7-amd64.exe (PID: 7156)
    • Reads the software policy settings

      • msiexec.exe (PID: 6944)
    • Python executable

      • python.exe (PID: 7144)
      • python.exe (PID: 6960)
    • Checks operating system version

      • python.exe (PID: 6960)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • python.exe (PID: 6960)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
16
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
start cmd.exe no specs conhost.exe no specs powershell.exe python-3.11.7-amd64.exe python-3.11.7-amd64.exe python-3.11.7-amd64.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe msiexec.exe no specs python.exe no specs conhost.exe no specs python.exe cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6032C:\WINDOWS\system32\cmd.exe /c "ver"C:\Windows\System32\cmd.exepython.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
6076C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6160C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\uwu.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
6168\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6300powershell -Command "(New-Object Net.WebClient).DownloadFile('https://www.python.org/ftp/python/3.11.7/python-3.11.7-amd64.exe', 'C:\Tools\python-3.11.7-amd64.exe')"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6436C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
6500\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6704C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exedllhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6944C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6960C:\Tools\Python311\python.exe -W ignore::DeprecationWarning -c " import runpy import sys sys.path = ['C:\\Users\\admin\\AppData\\Local\\Temp\\tmpwi0z12qd\\setuptools-65.5.0-py3-none-any.whl', 'C:\\Users\\admin\\AppData\\Local\\Temp\\tmpwi0z12qd\\pip-23.2.1-py3-none-any.whl'] + sys.path sys.argv[1:] = ['install', '--no-cache-dir', '--no-index', '--find-links', 'C:\\Users\\admin\\AppData\\Local\\Temp\\tmpwi0z12qd', '--upgrade', 'setuptools', 'pip'] runpy.run_module(\"pip\", run_name=\"__main__\", alter_sys=True) "C:\Tools\Python311\python.exe
python.exe
User:
admin
Company:
Python Software Foundation
Integrity Level:
HIGH
Description:
Python
Version:
3.11.7
Modules
Images
c:\tools\python311\python.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\tools\python311\vcruntime140.dll
c:\tools\python311\python311.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
Total events
29 952
Read events
25 514
Write events
4 352
Delete events
86

Modification events

(PID) Process:(7156) python-3.11.7-amd64.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000009BA91117E978DB01F41B0000F81B0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6436) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
480000000000000025444D17E978DB012419000028100000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6436) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000DF705417E978DB012419000028100000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6436) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6076) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(6076) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
(PID) Process:(6076) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000002
Operation:delete keyName:(default)
Value:
(PID) Process:(6076) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000002
Operation:writeName:Element
Value:
\EFI\Microsoft\Boot\bootmgfw.efi
(PID) Process:(6076) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{5b970157-8568-11eb-b45c-806e6f6e6963}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(6076) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{5b970157-8568-11eb-b45c-806e6f6e6963}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
Executable files
100
Suspicious files
1 037
Text files
3 588
Unknown types
0

Dropped files

PID
Process
Filename
Type
6436dllhost.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
7064python-3.11.7-amd64.exeC:\Users\admin\AppData\Local\Temp\{CF6E6F2E-63E1-49CC-B2CE-466196205DE3}\lib_AllUsers
MD5:
SHA256:
7064python-3.11.7-amd64.exeC:\Users\admin\AppData\Local\Temp\{CF6E6F2E-63E1-49CC-B2CE-466196205DE3}\doc_AllUsers
MD5:
SHA256:
7064python-3.11.7-amd64.exeC:\Users\admin\AppData\Local\Temp\{CF6E6F2E-63E1-49CC-B2CE-466196205DE3}\.ba\PythonBA.dllexecutable
MD5:763D0F2D4F1C5DBA5C61203BE2CD9DC4
SHA256:0ABDEECABCC5A0A7253CDF53C691314601E9EE3B6AC5477A534BE6B3A6A78DC3
6300powershell.exeC:\Tools\python-3.11.7-amd64.exeexecutable
MD5:6EBD889155AC3261308202B29D39C5A4
SHA256:C117C6444494BBE4CC937E8A5A61899D53F7F5C5BC573C5D130304E457D54024
6300powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_kctxbcph.ud0.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6436dllhost.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:7C93FB36E7BB25B7ACBF90B64F7AA31A
SHA256:A95CEEF6E93D2696048D273C57DF445DD8E040A2AA9D5CF6D3318D9B40F1E44C
7064python-3.11.7-amd64.exeC:\Users\admin\AppData\Local\Temp\{CF6E6F2E-63E1-49CC-B2CE-466196205DE3}\.ba\Default.wxlxml
MD5:E2E4ED5DD48AF4EEBE15726C7053749F
SHA256:0111A0F259F5F498055B4C1218B30C21D4A8B7D893BCA04ED4E18FE01D3563D2
6436dllhost.exeC:\System Volume Information\SPP\OnlineMetadataCache\{baab311c-dc83-41e9-accf-0237b4d412d3}_OnDiskSnapshotPropbinary
MD5:7C93FB36E7BB25B7ACBF90B64F7AA31A
SHA256:A95CEEF6E93D2696048D273C57DF445DD8E040A2AA9D5CF6D3318D9B40F1E44C
7064python-3.11.7-amd64.exeC:\Users\admin\AppData\Local\Package Cache\{f1ae9112-e709-45d0-9767-bf7b3f56c6f4}\state.rsmbinary
MD5:EE30FD81D3A1893CFAEF318E17C25994
SHA256:99A9EE061B8C113571858D50FA580A18F10BD2C2B5A5E5F309CE57AA7EA148F2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
31
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6264
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
DE
binary
471 b
whitelisted
1176
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
2756
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
2756
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
408 b
whitelisted
6944
msiexec.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
DE
binary
471 b
whitelisted
6944
msiexec.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAcfFBuLMA0l8xTrIwzQ0d0%3D
DE
binary
727 b
whitelisted
6944
msiexec.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
DE
binary
727 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1488
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1864
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
184.30.131.245:80
AKAMAI-AS
US
unknown
5064
SearchApp.exe
92.123.104.62:443
Akamai International B.V.
DE
unknown
6300
powershell.exe
151.101.0.223:443
www.python.org
FASTLY
US
whitelisted
3976
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 23.35.238.131
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.130
  • 20.190.159.71
  • 40.126.31.1
  • 40.126.31.130
  • 20.190.159.131
  • 20.190.159.2
  • 20.190.159.23
whitelisted
www.python.org
  • 151.101.0.223
  • 151.101.64.223
  • 151.101.192.223
  • 151.101.128.223
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 40.127.240.158
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info