download:

/wap/liyangyijie/Da5gT758DPa8Ig1BC9/gAL1kfab84k06hwRA,Q9VTTLAwfAC/anyconnect-win-4.0.00057-pre-deploy-k9.msi

Full analysis: https://app.any.run/tasks/e492a16b-27d3-43ea-bfba-a536d2d95808
Verdict: Malicious activity
Analysis date: May 17, 2025, 06:23:55
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Title: Installation Database, Keywords: Installer, MSI, Database, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Dec 11 11:47:44 2009, Number of Pages: 200, Security: 0, Code page: 1252, Revision Number: {72B52D0E-E3C5-4D8E-8DDE-8E7C35273D4B}, Number of Words: 2, Subject: Cisco AnyConnect Secure Mobility Client, Author: Cisco Systems, Inc., Name of Creating Application: Advanced Installer 7.5.2, Template: ;1033, Comments: A SmartNET contract is required for support - Cisco AnyConnect Secure Mobility Client.
MD5:

F5CDAF5EAE18415B1EC53E7447A1542D

SHA1:

EEBF3E4D8B3D453CCD4541F1611E98142CB9F965

SHA256:

C95BB3BD70A89D050364381B0D9B4E180A0A38EA52D2BFC80285D940BE50BC59

SSDEEP:

98304:GYuI7UipJhi8qG3pTqd+Hpje5RzZd/Tz3ayI2ZuscDTkdPYb3u57oO/4xmeKKWnS:iID7Kgt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • InstallHelper.exe (PID: 4488)
      • InstallHelper.exe (PID: 1088)
      • InstallHelper.exe (PID: 6740)
      • InstallHelper.exe (PID: 6972)
      • InstallHelper.exe (PID: 6148)
      • InstallHelper.exe (PID: 4244)
      • InstallHelper.exe (PID: 4112)
      • InstallHelper.exe (PID: 840)
      • VACon64.exe (PID: 3100)
      • InstallHelper.exe (PID: 4112)
      • vpnagent.exe (PID: 2420)
      • VACon64.exe (PID: 2092)
      • InstallHelper.exe (PID: 1628)
      • ManifestTool.exe (PID: 4696)
      • InstallHelper.exe (PID: 4528)
      • InstallHelper.exe (PID: 2152)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 5116)
      • vpnagent.exe (PID: 2420)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 1052)
      • VACon64.exe (PID: 3100)
      • drvinst.exe (PID: 6660)
      • drvinst.exe (PID: 840)
    • Executable content was dropped or overwritten

      • drvinst.exe (PID: 6660)
      • drvinst.exe (PID: 840)
      • VACon64.exe (PID: 3100)
  • INFO

    • Creates files or folders in the user directory

      • msiexec.exe (PID: 2852)
    • Reads the software policy settings

      • msiexec.exe (PID: 2852)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 2852)
    • An automatically generated document

      • msiexec.exe (PID: 2852)
    • Checks proxy server information

      • msiexec.exe (PID: 2852)
    • Reads the computer name

      • msiexec.exe (PID: 1052)
    • Checks supported languages

      • msiexec.exe (PID: 1052)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2852)
      • msiexec.exe (PID: 1052)
    • Manages system restore points

      • SrTasks.exe (PID: 2340)
    • The sample compiled with english language support

      • msiexec.exe (PID: 1052)
      • VACon64.exe (PID: 3100)
      • drvinst.exe (PID: 6660)
      • drvinst.exe (PID: 840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (88.6)
.mst | Windows SDK Setup Transform Script (10)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Title: Installation Database
Keywords: Installer, MSI, Database
LastPrinted: 2009:12:11 11:47:44
CreateDate: 2009:12:11 11:47:44
ModifyDate: 2009:12:11 11:47:44
Pages: 200
Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {72B52D0E-E3C5-4D8E-8DDE-8E7C35273D4B}
Words: 2
Subject: Cisco AnyConnect Secure Mobility Client
Author: Cisco Systems, Inc.
LastModifiedBy: -
Software: Advanced Installer 7.5.2
Template: ;1033
Comments: A SmartNET contract is required for support - Cisco AnyConnect Secure Mobility Client.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
170
Monitored processes
32
Malicious processes
3
Suspicious processes
14

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs sppextcomobj.exe no specs slui.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs msiexec.exe no specs vacon64.exe runonce.exe grpconv.exe no specs installhelper.exe no specs vpnagent.exe vacon64.exe no specs drvinst.exe drvinst.exe installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs manifesttool.exe no specs msiexec.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
672C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
840"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -copyFiles "C:\Users\admin\Desktop\Profiles\feedback\\" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\CustomerExperienceFeedback\\" "CustomerExperience_Feedback.xml"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
1
Version:
4, 0, 00057
Modules
Images
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
840DrvInst.exe "2" "211" "ROOT\NET\0000" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:573bd3b1d858e0ac:Cisco.ndi.NTamd64:3.1.6019.0:vpnva," "458dd218b" "0000000000000170"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1052C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1088"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -moveIfExist "C:\Users\admin\AppData\Local\\Cisco\Cisco AnyConnect VPN Client\preferences.xml" "C:\Users\admin\AppData\Local\Cisco\Cisco AnyConnect Secure Mobility Client\\preferences.xml"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
0
Version:
4, 0, 00057
Modules
Images
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1568"C:\Windows\System32\grpconv.exe" -oC:\Windows\System32\grpconv.exerunonce.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Progman Group Converter
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\grpconv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1628"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -acl "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\\" -rC:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
0
Version:
4, 0, 00057
Modules
Images
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2092"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\VACon64.exe" -install "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\\vpnva-6.inf" VPNVAC:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\VACon64.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Virtual Adapter Installer
Exit code:
0
Version:
4, 0, 00057
Modules
Images
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\vacon64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\newdev.dll
c:\windows\system32\rpcrt4.dll
2152"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -createLink "C:\ProgramData\Cisco\Cisco AnyConnect VPN Client\update.txt" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\update.txt"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
0
Version:
4, 0, 00057
Modules
Images
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2340C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
21 284
Read events
20 763
Write events
496
Delete events
25

Modification events

(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
48000000000000008CA5A653F4C6DB011C040000E8050000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000008CA5A653F4C6DB011C040000E8050000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
48000000000000004DCF1D54F4C6DB011C040000E8050000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000004DCF1D54F4C6DB011C040000E8050000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000D1982254F4C6DB011C040000E8050000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000FBFA2454F4C6DB011C040000E8050000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000009F0C9554F4C6DB011C04000098020000E8030000010000000000000000000000B0E2BBA600A9F148B2E5667A1746D7AE00000000000000000000000000000000
(PID) Process:(5116) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000DAF1A054F4C6DB01FC130000E8140000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5116) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000DAF1A054F4C6DB01FC130000AC150000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5116) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
Executable files
40
Suspicious files
42
Text files
45
Unknown types
0

Dropped files

PID
Process
Filename
Type
1052msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1052msiexec.exeC:\Windows\Installer\112a49.msi
MD5:
SHA256:
2852msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92Fbinary
MD5:2AB172E9398A3F429D22A89DB10F024D
SHA256:4DFCA5F2F4907EFD537D7DB7D4A8B5D57A14B551EE62A0F4F3EF6B795C438262
2852msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_4DB5226280F40111EA841C53C6706FECbinary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
2852msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92Fbinary
MD5:59B3470E19AD51E9E3B52B5ACBBABAD9
SHA256:DDAB8F04E39496CF3EF78A537ACED02CD566C28F8C5DAE9CE5DAA715B0C15C1C
2852msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIBA1B.tmpexecutable
MD5:B759A21D153A42060A53A89A26B9931C
SHA256:6ADCC31D2E3746C81F47041E9C6CC576CFE303FC1ED6DADD002C54F98C20CBCD
2852msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIB8A3.tmpexecutable
MD5:B759A21D153A42060A53A89A26B9931C
SHA256:6ADCC31D2E3746C81F47041E9C6CC576CFE303FC1ED6DADD002C54F98C20CBCD
1052msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:6182B6252F29F8F805CCD1BF5BA75B48
SHA256:525D95AFE53C7EEC7E5C9D7BD7D64A9A189D8108C668548DC19D38F96BF360D7
1052msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{a6bbe2b0-a900-48f1-b2e5-667a1746d7ae}_OnDiskSnapshotPropbinary
MD5:6182B6252F29F8F805CCD1BF5BA75B48
SHA256:525D95AFE53C7EEC7E5C9D7BD7D64A9A189D8108C668548DC19D38F96BF360D7
2852msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6binary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
39
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4988
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.8:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://crl.verisign.com/pca3-g5.crl
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEGNsdUPdvflp9HMWD0sJm54%3D
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEGNsdUPdvflp9HMWD0sJm54%3D
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://csc3-2010-crl.verisign.com/CSC3-2010.crl
unknown
whitelisted
4988
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6816
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.8:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2852
msiexec.exe
2.17.189.192:80
ocsp.verisign.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.174
whitelisted
crl.microsoft.com
  • 23.216.77.8
  • 23.216.77.6
  • 23.216.77.36
  • 23.216.77.42
  • 23.216.77.28
  • 23.216.77.20
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 23.219.150.101
whitelisted
ocsp.verisign.com
  • 2.17.189.192
whitelisted
crl.verisign.com
  • 2.17.189.192
whitelisted
csc3-2010-crl.verisign.com
  • 2.17.189.192
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.5
  • 40.126.32.134
  • 20.190.160.130
  • 20.190.160.131
  • 40.126.32.133
  • 40.126.32.136
  • 20.190.160.66
  • 40.126.32.76
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

No threats detected
No debug info