download:

/wap/liyangyijie/Da5gT758DPa8Ig1BC9/gAL1kfab84k06hwRA,Q9VTTLAwfAC/anyconnect-win-4.0.00057-pre-deploy-k9.msi

Full analysis: https://app.any.run/tasks/e492a16b-27d3-43ea-bfba-a536d2d95808
Verdict: Malicious activity
Analysis date: May 17, 2025, 06:23:55
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Title: Installation Database, Keywords: Installer, MSI, Database, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Dec 11 11:47:44 2009, Number of Pages: 200, Security: 0, Code page: 1252, Revision Number: {72B52D0E-E3C5-4D8E-8DDE-8E7C35273D4B}, Number of Words: 2, Subject: Cisco AnyConnect Secure Mobility Client, Author: Cisco Systems, Inc., Name of Creating Application: Advanced Installer 7.5.2, Template: ;1033, Comments: A SmartNET contract is required for support - Cisco AnyConnect Secure Mobility Client.
MD5:

F5CDAF5EAE18415B1EC53E7447A1542D

SHA1:

EEBF3E4D8B3D453CCD4541F1611E98142CB9F965

SHA256:

C95BB3BD70A89D050364381B0D9B4E180A0A38EA52D2BFC80285D940BE50BC59

SSDEEP:

98304:GYuI7UipJhi8qG3pTqd+Hpje5RzZd/Tz3ayI2ZuscDTkdPYb3u57oO/4xmeKKWnS:iID7Kgt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • InstallHelper.exe (PID: 4488)
      • InstallHelper.exe (PID: 1088)
      • InstallHelper.exe (PID: 6740)
      • InstallHelper.exe (PID: 6972)
      • InstallHelper.exe (PID: 6148)
      • InstallHelper.exe (PID: 4244)
      • InstallHelper.exe (PID: 4112)
      • InstallHelper.exe (PID: 840)
      • InstallHelper.exe (PID: 4112)
      • VACon64.exe (PID: 3100)
      • vpnagent.exe (PID: 2420)
      • VACon64.exe (PID: 2092)
      • InstallHelper.exe (PID: 1628)
      • InstallHelper.exe (PID: 4528)
      • InstallHelper.exe (PID: 2152)
      • ManifestTool.exe (PID: 4696)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 5116)
      • vpnagent.exe (PID: 2420)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 1052)
      • VACon64.exe (PID: 3100)
      • drvinst.exe (PID: 6660)
      • drvinst.exe (PID: 840)
    • Executable content was dropped or overwritten

      • VACon64.exe (PID: 3100)
      • drvinst.exe (PID: 6660)
      • drvinst.exe (PID: 840)
  • INFO

    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 2852)
    • Reads the software policy settings

      • msiexec.exe (PID: 2852)
    • An automatically generated document

      • msiexec.exe (PID: 2852)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 2852)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2852)
      • msiexec.exe (PID: 1052)
    • Checks proxy server information

      • msiexec.exe (PID: 2852)
    • Reads the computer name

      • msiexec.exe (PID: 1052)
    • Manages system restore points

      • SrTasks.exe (PID: 2340)
    • Checks supported languages

      • msiexec.exe (PID: 1052)
    • The sample compiled with english language support

      • msiexec.exe (PID: 1052)
      • VACon64.exe (PID: 3100)
      • drvinst.exe (PID: 6660)
      • drvinst.exe (PID: 840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (88.6)
.mst | Windows SDK Setup Transform Script (10)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Title: Installation Database
Keywords: Installer, MSI, Database
LastPrinted: 2009:12:11 11:47:44
CreateDate: 2009:12:11 11:47:44
ModifyDate: 2009:12:11 11:47:44
Pages: 200
Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {72B52D0E-E3C5-4D8E-8DDE-8E7C35273D4B}
Words: 2
Subject: Cisco AnyConnect Secure Mobility Client
Author: Cisco Systems, Inc.
LastModifiedBy: -
Software: Advanced Installer 7.5.2
Template: ;1033
Comments: A SmartNET contract is required for support - Cisco AnyConnect Secure Mobility Client.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
170
Monitored processes
32
Malicious processes
3
Suspicious processes
14

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs sppextcomobj.exe no specs slui.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs msiexec.exe no specs vacon64.exe runonce.exe grpconv.exe no specs installhelper.exe no specs vpnagent.exe vacon64.exe no specs drvinst.exe drvinst.exe installhelper.exe no specs installhelper.exe no specs installhelper.exe no specs manifesttool.exe no specs msiexec.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
672C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
840"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -copyFiles "C:\Users\admin\Desktop\Profiles\feedback\\" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\CustomerExperienceFeedback\\" "CustomerExperience_Feedback.xml"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
1
Version:
4, 0, 00057
Modules
Images
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
840DrvInst.exe "2" "211" "ROOT\NET\0000" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:573bd3b1d858e0ac:Cisco.ndi.NTamd64:3.1.6019.0:vpnva," "458dd218b" "0000000000000170"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1052C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1088"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -moveIfExist "C:\Users\admin\AppData\Local\\Cisco\Cisco AnyConnect VPN Client\preferences.xml" "C:\Users\admin\AppData\Local\Cisco\Cisco AnyConnect Secure Mobility Client\\preferences.xml"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
0
Version:
4, 0, 00057
Modules
Images
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1568"C:\Windows\System32\grpconv.exe" -oC:\Windows\System32\grpconv.exerunonce.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Progman Group Converter
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\grpconv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1628"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -acl "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\\" -rC:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
0
Version:
4, 0, 00057
Modules
Images
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2092"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\VACon64.exe" -install "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\\vpnva-6.inf" VPNVAC:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\VACon64.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Virtual Adapter Installer
Exit code:
0
Version:
4, 0, 00057
Modules
Images
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\vacon64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\newdev.dll
c:\windows\system32\rpcrt4.dll
2152"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -createLink "C:\ProgramData\Cisco\Cisco AnyConnect VPN Client\update.txt" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\update.txt"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exemsiexec.exe
User:
admin
Company:
Cisco Systems, Inc.
Integrity Level:
MEDIUM
Description:
AnyConnect Secure Mobility Client Install Helper
Exit code:
0
Version:
4, 0, 00057
Modules
Images
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\installhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2340C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
21 284
Read events
20 763
Write events
496
Delete events
25

Modification events

(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
48000000000000008CA5A653F4C6DB011C040000E8050000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000008CA5A653F4C6DB011C040000E8050000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
48000000000000004DCF1D54F4C6DB011C040000E8050000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000004DCF1D54F4C6DB011C040000E8050000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000D1982254F4C6DB011C040000E8050000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000FBFA2454F4C6DB011C040000E8050000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1052) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000009F0C9554F4C6DB011C04000098020000E8030000010000000000000000000000B0E2BBA600A9F148B2E5667A1746D7AE00000000000000000000000000000000
(PID) Process:(5116) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000DAF1A054F4C6DB01FC130000E8140000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5116) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000DAF1A054F4C6DB01FC130000AC150000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5116) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
Executable files
40
Suspicious files
42
Text files
45
Unknown types
0

Dropped files

PID
Process
Filename
Type
1052msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1052msiexec.exeC:\Windows\Installer\112a49.msi
MD5:
SHA256:
2852msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6binary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
2852msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92Fbinary
MD5:2AB172E9398A3F429D22A89DB10F024D
SHA256:4DFCA5F2F4907EFD537D7DB7D4A8B5D57A14B551EE62A0F4F3EF6B795C438262
1052msiexec.exeC:\Windows\Installer\MSI2DA5.tmpbinary
MD5:3C91DCAD2E068662B884D02A65089784
SHA256:C72EC62786607B2DCCCCAC12D03E9B784D09767042C80E667DA8B850159325F9
2852msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6binary
MD5:B023C6FB851A739982A4CBE2A7C52C41
SHA256:2E5E7AEC327D4353397D4F38CEEF5B77F046BE5E5299482E4082BC25726035C2
1052msiexec.exeC:\Windows\Installer\MSI2CAA.tmpexecutable
MD5:B759A21D153A42060A53A89A26B9931C
SHA256:6ADCC31D2E3746C81F47041E9C6CC576CFE303FC1ED6DADD002C54F98C20CBCD
2852msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6binary
MD5:7294E706964940439142975BB9A9DF77
SHA256:01A4548F8A55A88C31375B971405CEA7DC5E5867B6C4B9F0A8DB7402D70967BD
2852msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_4DB5226280F40111EA841C53C6706FECbinary
MD5:11FBA5C4B99C4F4C57AFFF2F34E24ECC
SHA256:F7E9AEADECE0CA2FB8FD41B7371FDAF9EAF5E804DBB14A432EBB3D16E9EDE5FA
2852msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIB8A3.tmpexecutable
MD5:B759A21D153A42060A53A89A26B9931C
SHA256:6ADCC31D2E3746C81F47041E9C6CC576CFE303FC1ED6DADD002C54F98C20CBCD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
39
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.8:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://crl.verisign.com/pca3-g5.crl
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEGNsdUPdvflp9HMWD0sJm54%3D
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEGNsdUPdvflp9HMWD0sJm54%3D
unknown
whitelisted
2852
msiexec.exe
GET
200
2.17.189.192:80
http://csc3-2010-crl.verisign.com/CSC3-2010.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4988
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6816
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.8:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2852
msiexec.exe
2.17.189.192:80
ocsp.verisign.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.174
whitelisted
crl.microsoft.com
  • 23.216.77.8
  • 23.216.77.6
  • 23.216.77.36
  • 23.216.77.42
  • 23.216.77.28
  • 23.216.77.20
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 23.219.150.101
whitelisted
ocsp.verisign.com
  • 2.17.189.192
whitelisted
crl.verisign.com
  • 2.17.189.192
whitelisted
csc3-2010-crl.verisign.com
  • 2.17.189.192
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.5
  • 40.126.32.134
  • 20.190.160.130
  • 20.190.160.131
  • 40.126.32.133
  • 40.126.32.136
  • 20.190.160.66
  • 40.126.32.76
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

No threats detected
No debug info