File name:

Setup_UniversalAdBlocker.exe

Full analysis: https://app.any.run/tasks/1213e26b-66f6-4377-86f8-3de9b5ad8aff
Verdict: Malicious activity
Analysis date: May 18, 2025, 03:41:35
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

75A64EE38AC50F49C32C8334827659D6

SHA1:

D2F6F7A29EEB02666AF1BED7203EEA995F5768D8

SHA256:

CBAD60F74D68A74480C63BA06A9CCD1F6A923A49DE6DFB1A75D2869382786B8D

SSDEEP:

98304:v00pLhk8sxtncBrRSvwBa9OURcd0i+muhrNjtTky5XgHG4yF8/K5Tku86u9HbVOZ:RIiHq5C0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup_UniversalAdBlocker.exe (PID: 4892)
    • Reads security settings of Internet Explorer

      • Setup_UniversalAdBlocker.exe (PID: 4892)
    • Creates a software uninstall entry

      • Setup_UniversalAdBlocker.exe (PID: 4892)
  • INFO

    • Checks supported languages

      • Setup_UniversalAdBlocker.exe (PID: 4892)
      • UniversalAdBlocker.exe (PID: 6112)
      • identity_helper.exe (PID: 8164)
    • Creates files or folders in the user directory

      • Setup_UniversalAdBlocker.exe (PID: 4892)
    • Creates files in the program directory

      • Setup_UniversalAdBlocker.exe (PID: 4892)
    • The sample compiled with english language support

      • Setup_UniversalAdBlocker.exe (PID: 4892)
    • Reads the computer name

      • Setup_UniversalAdBlocker.exe (PID: 4892)
      • UniversalAdBlocker.exe (PID: 6112)
      • identity_helper.exe (PID: 8164)
    • Checks proxy server information

      • Setup_UniversalAdBlocker.exe (PID: 4892)
    • Create files in a temporary directory

      • Setup_UniversalAdBlocker.exe (PID: 4892)
    • Reads the software policy settings

      • UniversalAdBlocker.exe (PID: 6112)
    • Reads Environment values

      • identity_helper.exe (PID: 8164)
    • Manual execution by a user

      • msedge.exe (PID: 7764)
      • msedge.exe (PID: 6248)
    • Application launched itself

      • msedge.exe (PID: 6248)
      • msedge.exe (PID: 4120)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 22:50:52+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24064
InitializedDataSize: 164864
UninitializedDataSize: 1024
EntryPoint: 0x30fa
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.0.0.0
ProductVersionNumber: 3.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: -
CompanyName: SecurityXploded
FileDescription: Free Tool to Block or Unblock Ads across all Web Browsers
FileVersion: 3
LegalCopyright: Copyright © 2007-2015 SecurityXploded, All rights reserved
LegalTrademarks: -
ProductName: UniversalAdBlocker
ProductVersion: 3
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
185
Monitored processes
49
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start setup_universaladblocker.exe universaladblocker.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setup_universaladblocker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
924"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3892 --field-trial-handle=2292,i,10718989891683497030,5216138252934389785,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1164"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2412 --field-trial-handle=2416,i,16313544583259847520,14113699555407854207,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1228"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2284 --field-trial-handle=2292,i,10718989891683497030,5216138252934389785,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1512"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6328 --field-trial-handle=2292,i,10718989891683497030,5216138252934389785,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1616"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5960 --field-trial-handle=2292,i,10718989891683497030,5216138252934389785,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2100"C:\Users\admin\AppData\Local\Temp\Setup_UniversalAdBlocker.exe" C:\Users\admin\AppData\Local\Temp\Setup_UniversalAdBlocker.exeexplorer.exe
User:
admin
Company:
SecurityXploded
Integrity Level:
MEDIUM
Description:
Free Tool to Block or Unblock Ads across all Web Browsers
Exit code:
3221226540
Version:
3.0
Modules
Images
c:\users\admin\appdata\local\temp\setup_universaladblocker.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3008"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x290,0x298,0x29c,0x28c,0x2a8,0x7ffc89dd5fd8,0x7ffc89dd5fe4,0x7ffc89dd5ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3676"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2604 --field-trial-handle=2416,i,16313544583259847520,14113699555407854207,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4108"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2568 --field-trial-handle=2292,i,10718989891683497030,5216138252934389785,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4120"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument C:\Program Files (x86)\SecurityXploded\UniversalAdBlocker\Readme.htmlC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeSetup_UniversalAdBlocker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
6 656
Read events
6 541
Write events
115
Delete events
0

Modification events

(PID) Process:(4892) Setup_UniversalAdBlocker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\UniversalAdBlocker
Operation:writeName:DisplayName
Value:
UniversalAdBlocker v3.0
(PID) Process:(4892) Setup_UniversalAdBlocker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\UniversalAdBlocker
Operation:writeName:Publisher
Value:
SecurityXploded
(PID) Process:(4892) Setup_UniversalAdBlocker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\UniversalAdBlocker
Operation:writeName:DisplayVersion
Value:
3.0
(PID) Process:(4892) Setup_UniversalAdBlocker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\UniversalAdBlocker
Operation:writeName:DisplayIcon
Value:
"C:\Program Files (x86)\SecurityXploded\UniversalAdBlocker\UniversalAdBlocker.exe"
(PID) Process:(4892) Setup_UniversalAdBlocker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\UniversalAdBlocker
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\SecurityXploded\UniversalAdBlocker\Uninstall.exe"
(PID) Process:(4892) Setup_UniversalAdBlocker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\UniversalAdBlocker
Operation:writeName:URLInfoAbout
Value:
http://www.securityxploded.com
(PID) Process:(4892) Setup_UniversalAdBlocker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4892) Setup_UniversalAdBlocker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4892) Setup_UniversalAdBlocker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4892) Setup_UniversalAdBlocker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithProgids
Operation:writeName:htmlfile
Value:
Executable files
10
Suspicious files
166
Text files
61
Unknown types
1

Dropped files

PID
Process
Filename
Type
4892Setup_UniversalAdBlocker.exeC:\Users\admin\AppData\Local\Temp\Installmanager.exebinary
MD5:6E7F1514369EDDB4E5021B70C36DF366
SHA256:FAC7A5B81367AD1F812E2E09F318635C4C2984FCC51B42E4C45CBE59CCEACF39
4892Setup_UniversalAdBlocker.exeC:\Users\admin\AppData\Local\Temp\nsmBB25.tmp\isWelcome.inibinary
MD5:9D2BD569029F8C546EBF966AF44C54D2
SHA256:DA42F25D2438686218F67EAA50325FC6FD4384D32A34A81E348F07BC10CD2542
4892Setup_UniversalAdBlocker.exeC:\Users\admin\AppData\Local\Temp\nsmBB25.tmp\leftimg.bmpimage
MD5:800A6DC38364A42D1FD2F1C73D0C9759
SHA256:AD0BC1C700CDC260B55A560C37FA3AF1628FBF197229FE2D62593732FCA0DC3C
4892Setup_UniversalAdBlocker.exeC:\Program Files (x86)\SecurityXploded\UniversalAdBlocker\Uninstall.exeexecutable
MD5:C90DFA77F391A834347D65C5F3BD69EF
SHA256:72761DFD108F5FD7E0441C916DCC9141D3D3856CB3802CFB34F73818407AA98C
4892Setup_UniversalAdBlocker.exeC:\Users\admin\AppData\Local\Temp\nsmBB25.tmp\UserInfo.dllexecutable
MD5:7579ADE7AE1747A31960A228CE02E666
SHA256:564C80DEC62D76C53497C40094DB360FF8A36E0DC1BDA8383D0F9583138997F5
4892Setup_UniversalAdBlocker.exeC:\Users\admin\AppData\Local\Temp\nsmBB25.tmp\Finish.inibinary
MD5:DA8F3DA5429FED132DF4ACA3D8E28714
SHA256:BBCD9F8029258F06571985A665106CFC6BCB146840D676E577F8289373B1ADC7
4892Setup_UniversalAdBlocker.exeC:\Users\admin\AppData\Local\Temp\nsmBB25.tmp\InstallOptions.dllexecutable
MD5:325B008AEC81E5AAA57096F05D4212B5
SHA256:C9CD5C9609E70005926AE5171726A4142FFBCCCC771D307EFCD195DAFC1E6B4B
4892Setup_UniversalAdBlocker.exeC:\Users\admin\AppData\Local\Temp\nsmBB25.tmp\Confirm.inibinary
MD5:1E610E27961C153733775E2376DCEDDC
SHA256:669B1E53B446C0839AD29C9C7D4AC06F749755602A8AB5C6E848888A642C7BF6
4892Setup_UniversalAdBlocker.exeC:\Program Files (x86)\SecurityXploded\UniversalAdBlocker\SecurityXploded_License.rtftext
MD5:316CC59FE8FAD0FF382DE96ACDAB2894
SHA256:4CC7B7DC863DA1DFAF197BF4198518C9FBDB088D6DE7790793F7715772A8A890
4892Setup_UniversalAdBlocker.exeC:\Users\admin\AppData\Local\Temp\nsmBB25.tmp\inetc.dllexecutable
MD5:7569B23F19A0F5CB4C1D3B30A296C4BB
SHA256:615BF32E15AAA8D58832DF2298F75DD2B29EA5F25BF152C99630315CB618A31A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
66
DNS requests
63
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.20.245.137:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4892
Setup_UniversalAdBlocker.exe
GET
200
160.202.73.231:80
http://securityxploded.net/installer_im.php?id=2575
unknown
unknown
6112
UniversalAdBlocker.exe
GET
301
104.26.15.162:80
http://www.securityxploded.com/product_versions.xml
unknown
whitelisted
6940
svchost.exe
HEAD
200
2.22.242.122:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3aeadfbf-fadd-43ac-a5d9-c143db5f63d8?P1=1747705131&P2=404&P3=2&P4=ep8zdQnvu0alJQz0QY0SHXnYaoRwv0LjyBdl80piPRQOXzugqjlq60%2fGeVpCMVJima1a%2fyxVIneuA4foB9xTzg%3d%3d
unknown
whitelisted
7760
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7760
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6940
svchost.exe
GET
206
2.22.242.122:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3aeadfbf-fadd-43ac-a5d9-c143db5f63d8?P1=1747705131&P2=404&P3=2&P4=ep8zdQnvu0alJQz0QY0SHXnYaoRwv0LjyBdl80piPRQOXzugqjlq60%2fGeVpCMVJima1a%2fyxVIneuA4foB9xTzg%3d%3d
unknown
whitelisted
6940
svchost.exe
GET
206
2.22.242.122:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3aeadfbf-fadd-43ac-a5d9-c143db5f63d8?P1=1747705131&P2=404&P3=2&P4=ep8zdQnvu0alJQz0QY0SHXnYaoRwv0LjyBdl80piPRQOXzugqjlq60%2fGeVpCMVJima1a%2fyxVIneuA4foB9xTzg%3d%3d
unknown
whitelisted
6940
svchost.exe
GET
206
2.22.242.122:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3aeadfbf-fadd-43ac-a5d9-c143db5f63d8?P1=1747705131&P2=404&P3=2&P4=ep8zdQnvu0alJQz0QY0SHXnYaoRwv0LjyBdl80piPRQOXzugqjlq60%2fGeVpCMVJima1a%2fyxVIneuA4foB9xTzg%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.20.245.137:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
4892
Setup_UniversalAdBlocker.exe
160.202.73.231:80
securityxploded.net
QUICKPACKET
US
suspicious
6112
UniversalAdBlocker.exe
104.26.15.162:80
www.securityxploded.com
CLOUDFLARENET
US
whitelisted
6112
UniversalAdBlocker.exe
104.26.15.162:443
www.securityxploded.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.20.245.137
  • 2.20.245.139
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
google.com
  • 142.250.185.206
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
securityxploded.net
  • 160.202.73.231
unknown
www.securityxploded.com
  • 104.26.15.162
  • 104.26.14.162
  • 172.67.68.59
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted

Threats

PID
Process
Class
Message
4892
Setup_UniversalAdBlocker.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
No debug info