File name:

ManagedSvcAccountsGUIInstaller.zip

Full analysis: https://app.any.run/tasks/a222b0b9-fb3c-498d-b697-5f070ff62277
Verdict: Malicious activity
Analysis date: March 25, 2025, 07:35:12
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
advancedinstaller
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

A91135CC955707EF1F1C46CC9ADDBD49

SHA1:

3B885CEAEC79A7973BF049877D8A3A6E8025C1F2

SHA256:

CCD3893E2192693B21FDEA1E299BAF7CE319C1F361F2CDA87804B4C8A7AF155C

SSDEEP:

24576:ZzDP6nKzZlr5sCU2Uzeci3YKa5uOCq+wmv+bfelD3e5UnRb+z3goAGx2q3rH2:ZzDP6nKzZlr5soUaci3YKa5uOCq+wmvL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 1276)
    • Executing a file with an untrusted certificate

      • MSAGUISetup.exe (PID: 4284)
      • ManagedServiceAccountsGUI.exe (PID: 6132)
      • ManagedServiceAccountsGUI.exe (PID: 1300)
  • SUSPICIOUS

    • ADVANCEDINSTALLER mutex has been found

      • MSAGUISetup.exe (PID: 4284)
    • Executable content was dropped or overwritten

      • MSAGUISetup.exe (PID: 4284)
    • There is functionality for taking screenshot (YARA)

      • MSAGUISetup.exe (PID: 4284)
      • ManagedServiceAccountsGUI.exe (PID: 1300)
    • Detects AdvancedInstaller (YARA)

      • MSAGUISetup.exe (PID: 4284)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3240)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6584)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 4448)
      • ManagedServiceAccountsGUI.exe (PID: 1300)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1276)
      • msiexec.exe (PID: 1088)
      • msiexec.exe (PID: 6584)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 1276)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 3132)
      • BackgroundTransferHost.exe (PID: 6700)
      • BackgroundTransferHost.exe (PID: 5408)
      • BackgroundTransferHost.exe (PID: 208)
      • BackgroundTransferHost.exe (PID: 1040)
      • msiexec.exe (PID: 1088)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 3132)
      • MSAGUISetup.exe (PID: 4284)
      • msiexec.exe (PID: 1088)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 3132)
      • msiexec.exe (PID: 1088)
      • ManagedServiceAccountsGUI.exe (PID: 1300)
      • slui.exe (PID: 3396)
    • Manual execution by a user

      • MSAGUISetup.exe (PID: 4284)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 3132)
      • msiexec.exe (PID: 1088)
      • msiexec.exe (PID: 6584)
    • Checks supported languages

      • MSAGUISetup.exe (PID: 4284)
      • msiexec.exe (PID: 4448)
      • msiexec.exe (PID: 6584)
      • msiexec.exe (PID: 2084)
      • ManagedServiceAccountsGUI.exe (PID: 1300)
      • ShellExperienceHost.exe (PID: 2780)
    • Reads the computer name

      • MSAGUISetup.exe (PID: 4284)
      • msiexec.exe (PID: 6584)
      • msiexec.exe (PID: 4448)
      • msiexec.exe (PID: 2084)
      • ManagedServiceAccountsGUI.exe (PID: 1300)
      • ShellExperienceHost.exe (PID: 2780)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 6584)
      • ManagedServiceAccountsGUI.exe (PID: 1300)
    • Manages system restore points

      • SrTasks.exe (PID: 5328)
    • Reads Environment values

      • ManagedServiceAccountsGUI.exe (PID: 1300)
    • Disables trace logs

      • ManagedServiceAccountsGUI.exe (PID: 1300)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6584)
    • Process checks computer location settings

      • msiexec.exe (PID: 4448)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2016:06:16 15:45:34
ZipCRC: 0x3ef1125d
ZipCompressedSize: 849169
ZipUncompressedSize: 1359544
ZipFileName: MSAGUISetup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
165
Monitored processes
20
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs msaguisetup.exe msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs managedserviceaccountsgui.exe no specs managedserviceaccountsgui.exe slui.exe shellexperiencehost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
208"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
1040"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
1088 /i "C:\Users\admin\AppData\Roaming\Cjwdev\Managed Service Accounts GUI 1.6.0\install\MSAGUISetup.msi" AI_SETUPEXEPATH="C:\Users\admin\Desktop\MSAGUISetup.exe" SETUPEXEDIR="C:\Users\admin\Desktop\" EXE_CMD_LINE="/exenoupdates /exelang 0 /noprereqs "C:\Windows\System32\msiexec.exe
MSAGUISetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1276"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\ManagedSvcAccountsGUIInstaller.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1300"C:\Program Files (x86)\Cjwdev\Managed Service Accounts GUI\ManagedServiceAccountsGUI.exe" C:\Program Files (x86)\Cjwdev\Managed Service Accounts GUI\ManagedServiceAccountsGUI.exe
msiexec.exe
User:
admin
Company:
Cjwdev Ltd
Integrity Level:
HIGH
Description:
Managed Service Accounts GUI
Version:
1.6.0.0
Modules
Images
c:\program files (x86)\cjwdev\managed service accounts gui\managedserviceaccountsgui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2084C:\Windows\syswow64\MsiExec.exe -Embedding 212F1243CA23C130A4423B612785C128C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2780"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\dxgi.dll
3132"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
3240C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3396C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
17 457
Read events
17 133
Write events
307
Delete events
17

Modification events

(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ManagedSvcAccountsGUIInstaller.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6700) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6700) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
17
Suspicious files
36
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3132BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\4a56661e-2ac4-4643-a85b-ccd77e6bb22d.down_data
MD5:
SHA256:
1088msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EB35376744F392396307460D546222D_29D70281C885CDDD5399E56DF7D4B8B7binary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
3132BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\4a56661e-2ac4-4643-a85b-ccd77e6bb22d.e2f8d1fe-57f6-4fc1-a8af-9430e2057031.down_metabinary
MD5:80201CAD35CAE3E53F7E2548D328261E
SHA256:8986CA92255335261586144EF50BA71FF3BE70800C81344CCD124A48A967D7AE
6584msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3132BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:4872BABAF39AA62B8D32695EBB7E9173
SHA256:2EE85DF86EE29BBEB3DCA81AA29B6DE204F605A2769B84C728A329178A2D0999
3132BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:CFA1CA55CC5C618866E7F5F998A0649D
SHA256:65BE6EFA42140E558EDA2C86137677B7858691E2D319D2DF44E2BDEC3D8FA09F
1088msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\378B079587A9184B2E2AB859CB263F40_524AD1B9B08D3C6450727265AE77B7D2binary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
1088msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\378B079587A9184B2E2AB859CB263F40_524AD1B9B08D3C6450727265AE77B7D2binary
MD5:8533967B169A1D4C3A47FC5360EBE79E
SHA256:D868030AE8A93F3BC40012E62AE3B8054874CBFD72FF05A7EC7F68CE7866200A
4284MSAGUISetup.exeC:\Users\admin\AppData\Roaming\Cjwdev\Managed Service Accounts GUI 1.6.0\install\MSAGUISetup.msibinary
MD5:7D8F1367A0A69BA481BD32EFA25E2534
SHA256:F1FE9D9E9FC123C2CC3D2595324CDA2C38A565A2BC5DD9F2E3FB934EBC806223
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.43189\MSAGUISetup.exeexecutable
MD5:95D49FC97CEAD82D1190511D61F411EF
SHA256:5E46BE9A7D33CC96920C6C26618356A7B87823B91B740B9F47FF74935B015D6E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
40
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
5496
MoUsoCoreWorker.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
6988
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
unknown
1088
msiexec.exe
GET
200
184.30.131.114:80
http://t2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEHGgtzaV3bGvwjsrmhjuVMs%3D
unknown
unknown
1088
msiexec.exe
GET
200
184.30.131.114:80
http://tl.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSFBjxN%2BWY73bfUnSOp7HDKJ%2Fbx0wQUV4abVLi%2BpimK5PbC4hMYiYXN3LcCEAcT6MZ9mFiNPaFjs%2BZq79Y%3D
unknown
unknown
1088
msiexec.exe
GET
200
184.30.131.114:80
http://t2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEHGgtzaV3bGvwjsrmhjuVMs%3D
unknown
unknown
1088
msiexec.exe
GET
200
184.30.131.114:80
http://t1.symcb.com/ThawtePCA.crl
unknown
unknown
1088
msiexec.exe
GET
200
184.30.131.114:80
http://tl.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSFBjxN%2BWY73bfUnSOp7HDKJ%2Fbx0wQUV4abVLi%2BpimK5PbC4hMYiYXN3LcCEAcT6MZ9mFiNPaFjs%2BZq79Y%3D
unknown
unknown
1088
msiexec.exe
GET
200
184.30.131.114:80
http://tl.symcb.com/tl.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
5496
MoUsoCoreWorker.exe
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:138
unknown
3216
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
6544
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
unknown
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
6988
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.174
unknown
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
unknown
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
unknown
client.wns.windows.com
  • 40.113.110.67
  • 40.115.3.253
unknown
login.live.com
  • 20.190.159.71
  • 40.126.31.2
  • 40.126.31.3
  • 40.126.31.67
  • 20.190.159.4
  • 20.190.159.64
  • 40.126.31.129
  • 20.190.159.0
unknown
ocsp.digicert.com
  • 184.30.131.245
unknown
arc.msn.com
  • 20.223.35.26
unknown
www.bing.com
  • 92.123.104.29
  • 92.123.104.35
  • 92.123.104.33
  • 92.123.104.30
  • 92.123.104.28
  • 92.123.104.32
  • 92.123.104.38
  • 92.123.104.31
  • 92.123.104.26
unknown
t2.symcb.com
  • 184.30.131.114
unknown
t1.symcb.com
  • 184.30.131.114
unknown

Threats

No threats detected
No debug info