File name:

zapret-discord-youtube-1.9.5.zip

Full analysis: https://app.any.run/tasks/45312a5f-fbcf-42ab-a456-7f08ebaa47dd
Verdict: Malicious activity
Analysis date: February 12, 2026, 20:18:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-scr
arch-doc
windivert-sys
mal-driver
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

A787DCD917F03071EB5290D71D52814C

SHA1:

F4E0A79B851D8D3AB9840E73C61AF5F053F8EAFE

SHA256:

CC2688BE2C49C201870CA04E2F433365219BFAF10467296A3E9398B7F21BCA56

SSDEEP:

49152:rvw/Cv8X9eQS0s7eWvRlefNYLw1yD1LE6tVz64qEu1KufrHNW3FzmUS74G6+hefu:U/e8teQzUJRlSNYLeyD1DhdqCirtW3FE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Malicious driver has been detected

      • WinRAR.exe (PID: 412)
    • Detects Cygwin installation

      • WinRAR.exe (PID: 412)
    • Starts NET.EXE for service management

      • cmd.exe (PID: 2912)
      • net.exe (PID: 8852)
  • SUSPICIOUS

    • Starts process via Powershell

      • powershell.exe (PID: 6152)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 412)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 2912)
      • cmd.exe (PID: 2780)
      • cmd.exe (PID: 3920)
      • powershell.exe (PID: 6152)
      • cmd.exe (PID: 8564)
    • Application launched itself

      • cmd.exe (PID: 2780)
      • cmd.exe (PID: 2912)
      • cmd.exe (PID: 3920)
      • cmd.exe (PID: 8564)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 2912)
      • cmd.exe (PID: 6516)
    • Hides command output

      • cmd.exe (PID: 2780)
      • cmd.exe (PID: 8680)
      • cmd.exe (PID: 3920)
      • cmd.exe (PID: 6516)
      • cmd.exe (PID: 8564)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 8780)
      • cmd.exe (PID: 2912)
      • cmd.exe (PID: 2864)
      • cmd.exe (PID: 8284)
    • Executing commands from a ".bat" file

      • cmd.exe (PID: 2912)
      • powershell.exe (PID: 6152)
    • The process bypasses the loading of PowerShell profile settings

      • cmd.exe (PID: 8780)
      • cmd.exe (PID: 2912)
      • cmd.exe (PID: 2864)
      • cmd.exe (PID: 8284)
    • Returns all items found within a container (POWERSHELL)

      • powershell.exe (PID: 3624)
      • powershell.exe (PID: 1792)
    • Probably obfuscated PowerShell command line is found

      • cmd.exe (PID: 8780)
    • Filtering the input of cmdlet (POWERSHELL)

      • powershell.exe (PID: 3624)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 2912)
    • Creates a new Windows service

      • sc.exe (PID: 9076)
    • Windows service management via SC.EXE

      • sc.exe (PID: 8272)
      • sc.exe (PID: 6212)
      • sc.exe (PID: 1000)
      • sc.exe (PID: 4936)
      • sc.exe (PID: 6156)
      • sc.exe (PID: 8040)
      • sc.exe (PID: 5520)
      • sc.exe (PID: 4624)
      • sc.exe (PID: 8824)
      • sc.exe (PID: 8176)
      • sc.exe (PID: 5404)
      • sc.exe (PID: 6416)
      • sc.exe (PID: 8184)
      • sc.exe (PID: 3584)
      • sc.exe (PID: 6468)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 2912)
    • Executes as Windows Service

      • winws.exe (PID: 4852)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 2912)
    • Creates or modifies Windows services

      • reg.exe (PID: 1156)
    • Starts application with an unusual extension

      • cmd.exe (PID: 2912)
    • Get information on the list of running processes

      • cmd.exe (PID: 2912)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 412)
    • Drops script file

      • WinRAR.exe (PID: 412)
      • cmd.exe (PID: 2864)
      • cmd.exe (PID: 2912)
      • powershell.exe (PID: 3624)
      • cmd.exe (PID: 4828)
      • powershell.exe (PID: 224)
      • powershell.exe (PID: 9088)
      • powershell.exe (PID: 1512)
      • powershell.exe (PID: 6152)
      • powershell.exe (PID: 5872)
      • powershell.exe (PID: 8156)
      • powershell.exe (PID: 8512)
      • powershell.exe (PID: 3276)
      • powershell.exe (PID: 8608)
      • powershell.exe (PID: 1792)
      • powershell.exe (PID: 1932)
      • powershell.exe (PID: 8736)
      • powershell.exe (PID: 4312)
      • powershell.exe (PID: 2900)
      • powershell.exe (PID: 8504)
      • powershell.exe (PID: 1424)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 412)
    • Manual execution by a user

      • cmd.exe (PID: 2864)
    • Checks supported languages

      • chcp.com (PID: 3132)
      • chcp.com (PID: 3696)
      • chcp.com (PID: 1456)
      • chcp.com (PID: 2752)
      • winws.exe (PID: 4852)
      • chcp.com (PID: 8544)
      • chcp.com (PID: 6072)
      • chcp.com (PID: 6396)
      • chcp.com (PID: 4468)
      • chcp.com (PID: 7428)
      • chcp.com (PID: 848)
      • chcp.com (PID: 8696)
    • Changes the display of characters in the console

      • cmd.exe (PID: 2912)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 3624)
    • Disables trace logs

      • netsh.exe (PID: 7508)
      • netsh.exe (PID: 4604)
      • netsh.exe (PID: 2748)
    • Reads the computer name

      • winws.exe (PID: 4852)
    • Search a value from a registry key

      • cmd.exe (PID: 6516)
      • reg.exe (PID: 8700)
    • Checks proxy server information

      • reg.exe (PID: 8700)
    • Returns all items recursively from all subfolders (POWERSHELL)

      • cmd.exe (PID: 8284)
      • powershell.exe (PID: 1792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2026:02:05 14:32:40
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: bin/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
320
Monitored processes
176
Malicious processes
4
Suspicious processes
3

Behavior graph

Click at the process to see the details
start THREAT winrar.exe cmd.exe no specs conhost.exe no specs where.exe no specs powershell.exe no specs cmd.exe conhost.exe no specs where.exe no specs where.exe no specs where.exe no specs where.exe no specs chcp.com no specs cmd.exe no specs cmd.exe no specs find.exe no specs findstr.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs cmd.exe no specs powershell.exe no specs cmd.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs netsh.exe no specs findstr.exe no specs findstr.exe no specs netsh.exe no specs net.exe no specs net1.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs winws.exe no specs reg.exe no specs chcp.com no specs cmd.exe no specs cmd.exe no specs find.exe no specs findstr.exe no specs chcp.com no specs chcp.com no specs chcp.com no specs sc.exe no specs findstr.exe no specs powershell.exe no specs cmd.exe no specs reg.exe no specs findstr.exe no specs powershell.exe no specs netsh.exe no specs findstr.exe no specs findstr.exe no specs powershell.exe no specs tasklist.exe no specs find.exe no specs powershell.exe no specs sc.exe no specs findstr.exe no specs powershell.exe no specs sc.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs powershell.exe no specs sc.exe no specs findstr.exe no specs sc.exe no specs findstr.exe no specs powershell.exe no specs sc.exe no specs findstr.exe no specs powershell.exe no specs sc.exe no specs findstr.exe no specs powershell.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs tasklist.exe no specs find.exe no specs sc.exe no specs findstr.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs slui.exe no specs tasklist.exe no specs findstr.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs chcp.com no specs cmd.exe no specs cmd.exe no specs find.exe no specs findstr.exe no specs chcp.com no specs chcp.com no specs

Process information

PID
CMD
Path
Indicators
Parent process
224powershell -NoProfile -Command "Write-Host \"Base Filtering Engine check passed\" -ForegroundColor Green"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
c:\windows\system32\combase.dll
412"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\zapret-discord-youtube-1.9.5.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
508findstr ":" C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
684C:\WINDOWS\system32\cmd.exe /S /D /c" echo %LISTS%list-general.txt "C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
848chcp 437 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Change CodePage Utility
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1000sc start zapretC:\Windows\System32\sc.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1036findstr /I "Connectivity" C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1068findstr /i "winws.exe" C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1156reg add "HKLM\System\CurrentControlSet\Services\zapret" /v zapret-discord-youtube /t REG_SZ /d "general (ALT3)" /fC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
1212C:\WINDOWS\system32\cmd.exe /S /D /c" echo start "zapret: %~n0" /min "%BIN%winws.exe" --wf-tcp=80,443,2053,2083,2087,2096,8443,%GameFilter% --wf-udp=443,19294-19344,50000-50100,%GameFilter% ^ "C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
Total events
82 122
Read events
82 098
Write events
24
Delete events
0

Modification events

(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\zapret-discord-youtube-1.9.5.zip
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
4
Suspicious files
5
Text files
63
Unknown types
0

Dropped files

PID
Process
Filename
Type
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.13182\bin\tls_clienthello_www_google_com.binbinary
MD5:41E47557F16690DF1781F67C8712714E
SHA256:F966351AE376963DFFBCB5B94256872649B9CDAAB8C5175025936FA50E07DC19
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.13182\bin\quic_initial_www_google_com.binbinary
MD5:312526D39958D89B1F8AB67789AB985F
SHA256:F4589C57749F956BB30538197A521D7005F8B0A8723B4707E72405E51DDAC50A
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.13182\bin\cygwin1.dllexecutable
MD5:A1C82ED072DC079DD7851F82D9AA7678
SHA256:103104A52E5293CE418944725DF19E2BF81AD9269B9A120D71D39028E821499B
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.13182\bin\tls_clienthello_4pda_to.binbinary
MD5:E6D649DE132C3C10CB62531EF74F5B73
SHA256:EEFEAF09DDE8D69B1F176212541F63C68B314A33A335ECED99A8A29F17254DA8
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.13182\bin\tls_clienthello_max_ru.binbinary
MD5:B2B3E684CE449B60F0BC5A9028221A08
SHA256:4EE0870ABE0A0128600B0095189987BA1D210DAE8BF963BC725AFF49CF922624
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.13182\bin\winws.exeexecutable
MD5:D498E19BC7A79DD1EFCB6B928CBE9909
SHA256:AFFB4F69D2EA302A7ABCCD5325D81826E140DDAE014F1E070BC4A6C0DD555188
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.13182\bin\WinDivert64.sysexecutable
MD5:89ED5BE7EA83C01D0DE33D3519944AA5
SHA256:8DA085332782708D8767BCACE5327A6EC7283C17CFB85E40B03CD2323A90DDC2
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.13182\bin\WinDivert.dllexecutable
MD5:B2014D33EE645112D5DC16FE9D9FCBFF
SHA256:C1E060EE19444A259B2162F8AF0F3FE8C4428A1C6F694DCE20DE194AC8D7D9A2
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.13182\general (ALT11).battext
MD5:4FF67A0368D08639424326621A8976B6
SHA256:E71E97066CE97FCFF1B257864CF9E88B6BC3AAED447140181D92A34E96806472
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.13182\general (ALT5).battext
MD5:BCD9A37C8EF0E03FD5B516D781E36A3D
SHA256:61B7C5AF0359492D6CD5252956C17104F17DF66A1E01982EE7AB55C4B490E3CD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
29
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
unknown
whitelisted
2600
svchost.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
unknown
whitelisted
4920
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
whitelisted
4920
SIHClient.exe
GET
200
135.233.95.135:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
unknown
whitelisted
4920
SIHClient.exe
GET
200
135.233.95.144:443
https://slscr.update.microsoft.com/sls/ping
unknown
whitelisted
4920
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
unknown
whitelisted
356
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
356
svchost.exe
POST
200
20.190.160.130:443
https://login.live.com/RST2.srf
unknown
xml
11.1 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2600
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
8628
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.204.138:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
5568
SearchApp.exe
2.16.204.138:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
2.16.204.148:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 51.104.136.2
whitelisted
www.bing.com
  • 2.16.204.148
  • 2.16.204.157
  • 2.16.204.149
  • 2.16.204.159
  • 2.16.204.154
  • 2.16.204.158
  • 2.16.204.138
  • 2.16.204.142
  • 2.16.204.139
whitelisted
th.bing.com
  • 2.16.204.138
  • 2.16.204.157
  • 2.16.204.158
  • 2.16.204.135
  • 2.16.204.139
  • 2.16.204.142
  • 2.16.204.149
  • 2.16.204.154
  • 2.16.204.148
whitelisted
google.com
  • 142.250.201.78
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
self.events.data.microsoft.com
  • 13.89.179.9
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.130
  • 20.190.160.17
  • 20.190.160.128
  • 20.190.160.3
  • 20.190.160.131
  • 40.126.32.136
  • 20.190.160.132
  • 40.126.32.138
whitelisted
crl.microsoft.com
  • 2.16.164.32
  • 2.16.164.81
  • 2.16.164.49
  • 2.16.164.99
  • 2.16.164.18
  • 2.16.164.114
  • 2.16.164.120
  • 2.16.164.9
  • 2.16.164.72
whitelisted

Threats

No threats detected
No debug info