File name:

MSPCManagerSetup.exe

Full analysis: https://app.any.run/tasks/fae940a6-40cd-4d17-a8f2-678900cb583d
Verdict: Malicious activity
Analysis date: October 22, 2024, 09:31:24
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

976DA100CE70183EBE529C41BB156E70

SHA1:

A87AB40ECB72B14C0C561B6193F5464D59D8C3EA

SHA256:

CBEB0474B217BDA21E7E11BB2A24F95AF0F6E287C022F1E0ABDD355E0268CB5E

SSDEEP:

98304:uhXx0UnMa0T846a6sdf8KcW8/faO+u3kYsB66khTeLbL0dlh4GPiHP9S6DTRBgZ9:GyLljgn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • MSPCManagerSetup.exe (PID: 6708)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1884)
      • MicrosoftEdgeUpdate.exe (PID: 5172)
      • MSPCManager.exe (PID: 2132)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6248)
      • MicrosoftEdgeUpdate.exe (PID: 6452)
    • Starts a Microsoft application from unusual location

      • MSPCManagerSetup.exe (PID: 6708)
      • MSPCManagerSetup.exe (PID: 6284)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1884)
      • MicrosoftEdgeUpdate.exe (PID: 5172)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6248)
      • MicrosoftEdgeUpdate.exe (PID: 6452)
    • Executable content was dropped or overwritten

      • MSPCManagerSetup.exe (PID: 6708)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1884)
      • MSPCManager.exe (PID: 2132)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6248)
    • Process drops SQLite DLL files

      • MSPCManagerSetup.exe (PID: 6708)
    • The process drops C-runtime libraries

      • MSPCManagerSetup.exe (PID: 6708)
    • Executes as Windows Service

      • MSPCManagerService.exe (PID: 6692)
  • INFO

    • Creates files in the program directory

      • MSPCManagerSetup.exe (PID: 6708)
    • Checks supported languages

      • MSPCManagerSetup.exe (PID: 6708)
    • Reads the software policy settings

      • MSPCManagerSetup.exe (PID: 6708)
    • Process checks computer location settings

      • MSPCManagerSetup.exe (PID: 6708)
    • Reads Environment values

      • MSPCManagerSetup.exe (PID: 6708)
    • Reads the machine GUID from the registry

      • MSPCManagerSetup.exe (PID: 6708)
    • Reads the computer name

      • MSPCManagerSetup.exe (PID: 6708)
    • Sends debugging messages

      • MSPCManagerSetup.exe (PID: 6708)
    • Create files in a temporary directory

      • MSPCManagerSetup.exe (PID: 6708)
    • Manual execution by a user

      • Taskmgr.exe (PID: 6156)
      • Taskmgr.exe (PID: 2980)
      • MSPCManager.exe (PID: 2132)
      • MSPCManager.exe (PID: 3568)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (18)
.exe | Win32 Executable (generic) (2.9)
.exe | Generic Win/DOS Executable (1.3)
.exe | DOS Executable Generic (1.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:10:12 04:54:21+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.35
CodeSize: 1033728
InitializedDataSize: 2519552
UninitializedDataSize: -
EntryPoint: 0xa3150
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.1.3.0
ProductVersionNumber: 3.1.3.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Microsoft PC Manager Setup
FileVersion: 3.1.3.0
InternalName: Setup.exe
LegalCopyright: Copyright Microsoft Corporation
OriginalFileName: Setup.exe
ProductName: Microsoft PC Manager Setup
ProductVersion: 3.1.3.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
165
Monitored processes
17
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mspcmanagersetup.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe mspcmanagerservice.exe wermgr.exe taskmgr.exe no specs taskmgr.exe checksum.exe conhost.exe no specs mspcmanager.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe wermgr.exe mspcmanager.exe ucpdmgr.exe no specs conhost.exe no specs mspcmanagersetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1524"C:\Program Files\Microsoft PC Manager\checksum.exe"C:\Program Files\Microsoft PC Manager\checksum.exe
MSPCManagerSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\microsoft pc manager\checksum.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1884C:\Users\admin\AppData\Local\Temp\\MicrosoftEdgeWebview2Setup.exe /silent /installC:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe
MSPCManagerSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Exit code:
2147747592
Version:
1.3.161.35
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2132"C:\Program Files\Microsoft PC Manager\MSPCManager.exe" --Source=InstallerC:\Program Files\Microsoft PC Manager\MSPCManager.exe
explorer.exe
User:
admin
Company:
MSPCManager
Integrity Level:
MEDIUM
Description:
MSPCManager
Exit code:
0
Version:
3.1.3.0
Modules
Images
c:\program files\microsoft pc manager\mspcmanager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2380"C:\WINDOWS\system32\UCPDMgr.exe"C:\Windows\System32\UCPDMgr.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
User Choice Protection Manager
Exit code:
0
Version:
1.0.0.414301
2980"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Manager
Exit code:
3221226540
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
3156\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exechecksum.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3568"C:\Program Files\Microsoft PC Manager\MSPCManager.exe" --Source=DesktopLinkC:\Program Files\Microsoft PC Manager\MSPCManager.exe
explorer.exe
User:
admin
Company:
MSPCManager
Integrity Level:
MEDIUM
Description:
MSPCManager
Exit code:
1073807364
Version:
3.1.3.0
Modules
Images
c:\program files\microsoft pc manager\mspcmanager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4236\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeUCPDMgr.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
5172"C:\Program Files (x86)\Microsoft\Temp\EUF95D.tmp\MicrosoftEdgeUpdate.exe" /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Program Files (x86)\Microsoft\Temp\EUF95D.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
2147747592
Version:
1.3.161.35
Modules
Images
c:\program files (x86)\microsoft\temp\euf95d.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6156"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Exit code:
1073807364
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\combase.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\rpcrt4.dll
Total events
34 164
Read events
34 030
Write events
124
Delete events
10

Modification events

(PID) Process:(6708) MSPCManagerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\MSPCManager
Operation:writeName:InstallRegionCode
Value:
US
(PID) Process:(6708) MSPCManagerSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\AppInsights\066b3572-6927-4afd-86e4-008726fb9f24
Operation:delete valueName:DisableTracking
Value:
(PID) Process:(6708) MSPCManagerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:WindowsMasterSetup
Value:
(PID) Process:(5172) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(5172) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{DB831345-26D8-4CC0-AD59-20A13D3A4E3A}
Operation:writeName:PersistedPingString
Value:
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.161.35" shell_version="1.3.147.37" ismachine="1" sessionid="{438CBE70-D5E9-425A-AEC5-7CA95759F68A}" userid="{FD984739-A122-4DB0-BE5B-46E3E09D84E4}" installsource="otherinstallcmd" requestid="{DB831345-26D8-4CC0-AD59-20A13D3A4E3A}" dedup="cr" domainjoined="0"><hw logical_cpus="4" physmemory="4" disk_type="2" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="10.0.19045.4046" sp="" arch="x64"/><oem product_manufacturer="DELL" product_name="DELL"/><exp etag="&quot;r452t1+k2Tgq/HXzjvFNBRhopBWR9sbjXxqeUDH9uX0=&quot;"/><app appid="{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}" version="1.3.185.17" nextversion="1.3.161.35" lang="" brand="" client=""><event eventtype="2" eventresult="1" errorcode="0" extracode1="0" install_time_ms="531"/></app></request>
(PID) Process:(5172) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{DB831345-26D8-4CC0-AD59-20A13D3A4E3A}
Operation:writeName:PersistedPingTime
Value:
133740631093668222
(PID) Process:(5172) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\proxy
Operation:writeName:source
Value:
auto
(PID) Process:(5172) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{DB831345-26D8-4CC0-AD59-20A13D3A4E3A}
Operation:delete keyName:(default)
Value:
(PID) Process:(6692) MSPCManagerService.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\Microsoft PC Manager Service
Operation:writeName:EventMessageFile
Value:
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\EventLogMessages.dll
(PID) Process:(5172) MicrosoftEdgeUpdate.exeKey:\REGISTRY\A\{2097654e-d2c7-be13-d89a-2dbffc1d8420}\Root\InventoryApplicationFile
Operation:writeName:WritePermissionsCheck
Value:
1
Executable files
542
Suspicious files
59
Text files
128
Unknown types
3

Dropped files

PID
Process
Filename
Type
6708MSPCManagerSetup.exeC:\Users\admin\AppData\Local\Temp\skin\b_c1_pushed.pngimage
MD5:18734414F3FF768AE93A7A7FF1EDD90A
SHA256:56C8C7F3964D9BE68D51B6EDC84372EE8890A7D8A6B1CDF1555C2905BCBAB410
6708MSPCManagerSetup.exeC:\Users\admin\AppData\Local\Temp\skin\images\button2_hover.pngimage
MD5:176BF7CC7491EEE802931F33463F6382
SHA256:98AFCC7A09A826AC330B470FF7368DEB7E4E8AB8A8E67B539897B383E9234200
6708MSPCManagerSetup.exeC:\Users\admin\AppData\Local\Temp\skin\images\button1_normal.pngimage
MD5:3D2082700694857076F47F5F5E7054FB
SHA256:422649F51EF57C97F1DCC7B61E51A3F81AD47049086E218EAD2AF01026ECB998
6708MSPCManagerSetup.exeC:\Users\admin\AppData\Local\Temp\skin\images\button1_disable.pngimage
MD5:EE9BDC84D9FF17C1D7EA8D7CD7FD22BD
SHA256:3D40D5602BA9F4B4253E82F72D70BFAB12686248BFA7C715EB405C86AB90DE33
6708MSPCManagerSetup.exeC:\Users\admin\AppData\Local\Temp\skin\images\button1_hover.pngimage
MD5:79A97D0CA6C51643ACDAF638D91C1E74
SHA256:10F2A90B3788FC74867F82CCDFE5DE511D0941618331EBCBDBD34F841B4C6C92
6708MSPCManagerSetup.exeC:\Users\admin\AppData\Local\Temp\skin\images\button1_pushed.pngimage
MD5:18734414F3FF768AE93A7A7FF1EDD90A
SHA256:56C8C7F3964D9BE68D51B6EDC84372EE8890A7D8A6B1CDF1555C2905BCBAB410
6708MSPCManagerSetup.exeC:\Users\admin\AppData\Local\Temp\skin.zipcompressed
MD5:14CC14C0253ED697C022D4080E593F5F
SHA256:CC56ACD9B1725FB909221151EE897950B3FB260496EBCAF56A89B2DFB96B86F3
6708MSPCManagerSetup.exeC:\Users\admin\AppData\Local\Temp\skin\bottom.pngimage
MD5:47E6DD4693AF1A166F177DF10CE744B6
SHA256:7812DCB062A85D288C98EF1F53D2C38CE073D1C4E035F4843D09992F9E807548
6708MSPCManagerSetup.exeC:\Users\admin\AppData\Local\Temp\skin\b_c1_disable.pngimage
MD5:EE9BDC84D9FF17C1D7EA8D7CD7FD22BD
SHA256:3D40D5602BA9F4B4253E82F72D70BFAB12686248BFA7C715EB405C86AB90DE33
6708MSPCManagerSetup.exeC:\Users\admin\AppData\Local\Temp\skin\b_c1_hover.pngimage
MD5:79A97D0CA6C51643ACDAF638D91C1E74
SHA256:10F2A90B3788FC74867F82CCDFE5DE511D0941618331EBCBDBD34F841B4C6C92
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
111
DNS requests
43
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4904
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6692
MSPCManagerService.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6692
MSPCManagerService.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSzT%2FzqwcqNvhP9i4c4sCPz2JbzrAQU%2FglxQFUFEETYpIF1uJ4a6UoGiMgCEzMAibmBFJ%2FEWBY%2FO5UAAACJuYE%3D
unknown
whitelisted
6692
MSPCManagerService.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
6692
MSPCManagerService.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBR2JNtr0JxEvYySpbyBWaqBmealCgQUzhUWO%2BoCo6Zr2tkr%2FeWMUr56UKgCEzMAb%2Fhn%2Bs2y2UaksPYAAABv%2BGc%3D
unknown
whitelisted
6880
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7160
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4080
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4360
SearchApp.exe
104.126.37.155:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6708
MSPCManagerSetup.exe
20.50.88.245:443
dc.applicationinsights.azure.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4904
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4904
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4360
SearchApp.exe
104.126.37.146:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 40.127.240.158
whitelisted
www.bing.com
  • 104.126.37.155
  • 104.126.37.146
  • 104.126.37.161
  • 104.126.37.153
  • 104.126.37.137
  • 104.126.37.139
  • 104.126.37.131
  • 104.126.37.152
  • 104.126.37.160
  • 92.123.104.38
  • 92.123.104.41
  • 92.123.104.45
  • 92.123.104.47
  • 92.123.104.51
  • 92.123.104.53
  • 92.123.104.56
  • 92.123.104.37
  • 92.123.104.42
whitelisted
google.com
  • 142.250.185.238
whitelisted
dc.applicationinsights.azure.com
  • 20.50.88.245
  • 20.50.88.238
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.75
  • 40.126.31.73
  • 20.190.159.73
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.71
  • 20.190.159.4
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
th.bing.com
  • 104.126.37.155
  • 104.126.37.131
  • 104.126.37.160
  • 104.126.37.153
  • 104.126.37.161
  • 104.126.37.152
  • 104.126.37.137
  • 104.126.37.146
  • 104.126.37.139
whitelisted
go.microsoft.com
  • 23.213.166.81
  • 184.28.89.167
whitelisted
aka.ms
  • 184.30.22.2
whitelisted
pcmdistributestorage.blob.core.windows.net
  • 20.60.220.36
whitelisted

Threats

No threats detected
Process
Message
MSPCManagerSetup.exe
[2024-10-22 09:31:31.117][TID: 6364][ INFO][BaseManager][BaseManager::Init:23] [[Setup]], Main Process Id:6708, Main Thread Id:6364
MSPCManagerSetup.exe
[2024-10-22 09:31:31.117][TID: 6364][ INFO][BaseManager][BaseManager::Init:25] Init common options
MSPCManagerSetup.exe
[2024-10-22 09:31:31.132][TID: 6364][ INFO][CommonOptions][CommonOptions::Init:15] installerVersion:3.1.3.0, installerChannel:500000
MSPCManagerSetup.exe
[2024-10-22 09:31:31.148][TID: 6364][ INFO][CommonOptions][CommonOptions::Init:28] upgradeMode:false
MSPCManagerSetup.exe
[2024-10-22 09:31:31.148][TID: 6364][ INFO][CommonOptions][CommonOptions::Init:41] SystemLangId:1033
MSPCManagerSetup.exe
[2024-10-22 09:31:31.148][TID: 6364][ INFO][CommonOptions][CommonOptions::Init:44] Current process is running as local system:false
MSPCManagerSetup.exe
[2024-10-22 09:31:31.148][TID: 6364][ INFO][CommonOptions][CommonOptions::Init:47] System user has login:true
MSPCManagerSetup.exe
[2024-10-22 09:31:31.148][TID: 6364][ INFO][CommonOptions][CommonOptions::Init:93] LanguageId:1033, LanguageFile:languages\en_us.xml
MSPCManagerSetup.exe
[2024-10-22 09:31:31.148][TID: 6364][ INFO][CommonOptions][CommonOptions::Init:125] SystemRegionCode:US, UsingRegionCode:US
MSPCManagerSetup.exe
[2024-10-22 09:31:31.148][TID: 6364][ INFO][CommonOptions][CommonOptions::Init:129] includeDriver:false, includeADBlock:true