File name:

Setup_BrightSlide_1.0.9.exe

Full analysis: https://app.any.run/tasks/597b1ec3-68aa-4691-8830-b8557c061459
Verdict: Malicious activity
Analysis date: January 15, 2025, 15:04:53
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
advancedinstaller
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

65B4FE10012BDE699554A767C31C2416

SHA1:

EEF1E709334083B0A95A64566AA3BEC910827B86

SHA256:

D07CDEEA86A5D640D77D6A99AEFADB541278EE113B3F6D3CF744B490C9BFEBEA

SSDEEP:

98304:M+cD4dnONMFXWX3ocV+GDo/8fk2HmN1zEhQf+q1+C0FZQZs6fhHzeG2l4mTQBLz/:eNIU9k2w+kZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from MS Office

      • POWERPNT.EXE (PID: 836)
    • Reads the value of a key from the registry (SCRIPT)

      • POWERPNT.EXE (PID: 836)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Setup_BrightSlide_1.0.9.tmp (PID: 6692)
      • BrightSlide Assets.exe (PID: 7088)
      • msiexec.exe (PID: 4164)
    • Executable content was dropped or overwritten

      • Setup_BrightSlide_1.0.9.tmp (PID: 6692)
      • Setup_BrightSlide_1.0.9.exe (PID: 6620)
      • BrightSlide Assets.exe (PID: 7088)
    • ADVANCEDINSTALLER mutex has been found

      • BrightSlide Assets.exe (PID: 7088)
    • Reads security settings of Internet Explorer

      • BrightSlide Assets.exe (PID: 7088)
      • Setup_BrightSlide_1.0.9.tmp (PID: 6692)
    • Checks Windows Trust Settings

      • BrightSlide Assets.exe (PID: 7088)
      • msiexec.exe (PID: 4164)
    • Executes as Windows Service

      • VSSVC.exe (PID: 4264)
    • Process drops legitimate windows executable

      • BrightSlide Assets.exe (PID: 7088)
    • Executes WMI query (SCRIPT)

      • POWERPNT.EXE (PID: 836)
    • Accesses WMI object, sets custom ImpersonationLevel (SCRIPT)

      • POWERPNT.EXE (PID: 836)
  • INFO

    • Checks supported languages

      • Setup_BrightSlide_1.0.9.exe (PID: 6620)
      • Setup_BrightSlide_1.0.9.tmp (PID: 6692)
      • BrightSlide Assets.exe (PID: 7088)
      • msiexec.exe (PID: 3820)
      • msiexec.exe (PID: 4164)
    • Create files in a temporary directory

      • Setup_BrightSlide_1.0.9.exe (PID: 6620)
      • Setup_BrightSlide_1.0.9.tmp (PID: 6692)
    • Reads Microsoft Office registry keys

      • Setup_BrightSlide_1.0.9.tmp (PID: 6692)
    • Creates a software uninstall entry

      • Setup_BrightSlide_1.0.9.tmp (PID: 6692)
    • Creates files or folders in the user directory

      • BrightSlide Assets.exe (PID: 7088)
      • Setup_BrightSlide_1.0.9.tmp (PID: 6692)
    • The sample compiled with english language support

      • Setup_BrightSlide_1.0.9.tmp (PID: 6692)
      • BrightSlide Assets.exe (PID: 7088)
      • msiexec.exe (PID: 4164)
    • Reads the computer name

      • Setup_BrightSlide_1.0.9.tmp (PID: 6692)
      • BrightSlide Assets.exe (PID: 7088)
      • msiexec.exe (PID: 4164)
      • msiexec.exe (PID: 3820)
    • Reads Environment values

      • BrightSlide Assets.exe (PID: 7088)
      • msiexec.exe (PID: 1620)
    • Reads the machine GUID from the registry

      • BrightSlide Assets.exe (PID: 7088)
      • msiexec.exe (PID: 4164)
    • Reads the software policy settings

      • BrightSlide Assets.exe (PID: 7088)
      • msiexec.exe (PID: 4816)
      • DWWIN.EXE (PID: 3612)
      • msiexec.exe (PID: 4164)
    • Checks proxy server information

      • BrightSlide Assets.exe (PID: 7088)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 4816)
    • Manages system restore points

      • SrTasks.exe (PID: 6884)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 4164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 131584
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: BrightCarbon
FileDescription: BrightSlide Setup
FileVersion:
LegalCopyright: Copyright (c) 2019-2022 BrightCarbon Ltd. and 2011-2018 YOUpresent Ltd.
OriginalFileName:
ProductName: BrightSlide
ProductVersion: 1.0.9
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
12
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup_brightslide_1.0.9.exe setup_brightslide_1.0.9.tmp brightslide assets.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs powerpnt.exe dwwin.exe

Process information

PID
CMD
Path
Indicators
Parent process
836"C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXE" C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXE
Setup_BrightSlide_1.0.9.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft PowerPoint
Exit code:
0
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\powerpnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1620C:\Windows\syswow64\MsiExec.exe -Embedding DEFD337378E36B6AA985AEB87EE2747AC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3612C:\WINDOWS\system32\dwwin.exe -x -s 6744C:\Windows\System32\DWWIN.EXE
POWERPNT.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Error Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dwwin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
3820C:\Windows\syswow64\MsiExec.exe -Embedding F1802AEDEE42D7EE914763FCAC94AE8F CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4164C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4264C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4816"C:\WINDOWS\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\BrightCarbon\BrightSlide Assets 1.0.1\install\BrightSlide Assets.msi" AI_SETUPEXEPATH="C:\Users\admin\AppData\Local\Temp\is-P7CAV.tmp\BrightSlide Assets.exe" SETUPEXEDIR=C:\Users\admin\AppData\Local\Temp\is-P7CAV.tmp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1736952232 " C:\Windows\SysWOW64\msiexec.exeBrightSlide Assets.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6620"C:\Users\admin\AppData\Local\Temp\Setup_BrightSlide_1.0.9.exe" C:\Users\admin\AppData\Local\Temp\Setup_BrightSlide_1.0.9.exe
explorer.exe
User:
admin
Company:
BrightCarbon
Integrity Level:
MEDIUM
Description:
BrightSlide Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\setup_brightslide_1.0.9.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
6692"C:\Users\admin\AppData\Local\Temp\is-GFRBN.tmp\Setup_BrightSlide_1.0.9.tmp" /SL5="$602A4,7520305,874496,C:\Users\admin\AppData\Local\Temp\Setup_BrightSlide_1.0.9.exe" C:\Users\admin\AppData\Local\Temp\is-GFRBN.tmp\Setup_BrightSlide_1.0.9.tmp
Setup_BrightSlide_1.0.9.exe
User:
admin
Company:
BrightCarbon
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-gfrbn.tmp\setup_brightslide_1.0.9.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
6884C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
28 524
Read events
27 666
Write events
817
Delete events
41

Modification events

(PID) Process:(6692) Setup_BrightSlide_1.0.9.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BrightSlide\Configuration
Operation:writeName:Install Folder
Value:
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide
(PID) Process:(6692) Setup_BrightSlide_1.0.9.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BrightSlide\Configuration
Operation:writeName:Version
Value:
1.0.9
(PID) Process:(6692) Setup_BrightSlide_1.0.9.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BrightSlide\Configuration
Operation:writeName:Build
Value:
2412 311359
(PID) Process:(6692) Setup_BrightSlide_1.0.9.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\PowerPoint\AddIns\BrightSlide
Operation:writeName:AutoLoad
Value:
1
(PID) Process:(6692) Setup_BrightSlide_1.0.9.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\PowerPoint\AddIns\BrightSlide
Operation:writeName:Path
Value:
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide\BrightSlide.ppam
(PID) Process:(6692) Setup_BrightSlide_1.0.9.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BrightSlide\Configuration
Operation:writeName:Ignore MAC OUI
Value:
XX:YY:ZZ
(PID) Process:(6692) Setup_BrightSlide_1.0.9.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BrightSlide\Configuration
Operation:writeName:Installer
Value:
EXE
(PID) Process:(6692) Setup_BrightSlide_1.0.9.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BrightSlide\Configuration
Operation:writeName:Update
Value:
True
(PID) Process:(6692) Setup_BrightSlide_1.0.9.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{29BB97A8-45FC-480D-A789-DF0212601E9F}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.2
(PID) Process:(6692) Setup_BrightSlide_1.0.9.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{29BB97A8-45FC-480D-A789-DF0212601E9F}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide
Executable files
34
Suspicious files
144
Text files
72
Unknown types
2

Dropped files

PID
Process
Filename
Type
6692Setup_BrightSlide_1.0.9.tmpC:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide\is-NKKRH.tmpexecutable
MD5:EA37C7E16856B1E488C47CA5C6CBB351
SHA256:56D22FBEB6F394587921F7134A8143A26068C99EA9B28EDC49AF09C767E87B6D
6692Setup_BrightSlide_1.0.9.tmpC:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide\is-UIO9H.tmpdocument
MD5:DA834EA699D2FDBA5458348909BDB26E
SHA256:10F44EC95CA4D2A3830753AE9197527ACFA30E31AC3AC6F88B8D270805A79A34
6692Setup_BrightSlide_1.0.9.tmpC:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide\BrightSlide.ppamdocument
MD5:DA834EA699D2FDBA5458348909BDB26E
SHA256:10F44EC95CA4D2A3830753AE9197527ACFA30E31AC3AC6F88B8D270805A79A34
6692Setup_BrightSlide_1.0.9.tmpC:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide\BrightSlide Helper.ppamdocument
MD5:374A50D375B05421A39BC8D8B333F212
SHA256:72571D5AB379F18A0A9F9CAB7535EB6E212F04F6063BB2F35A87F9ECD0100FDF
6692Setup_BrightSlide_1.0.9.tmpC:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide\is-QM0G7.tmpimage
MD5:196659E2912FD5E77331B3D8AC1F2125
SHA256:EDACE35A84228FC6AC89E0EFD3AC813F7E0148786E03D770F5759E63605A031A
6692Setup_BrightSlide_1.0.9.tmpC:\Users\admin\AppData\Roaming\BrightSlide\is-KGR92.tmpdocument
MD5:A2C2EDDFFE9F7AFFD850FAD93778A60C
SHA256:E2E7A5C919BA28D24E156CADF0AAB796144824DC7503F428FF009FDB9403164A
6692Setup_BrightSlide_1.0.9.tmpC:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide\alignToL.pngimage
MD5:3AA880A71196180ED0785ED76711F617
SHA256:3C1955E68F37B2AD057234DB94D61CB3B9F4B8220EAAA9E1F89AA28BB7479DEE
6692Setup_BrightSlide_1.0.9.tmpC:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide\is-A5M89.tmpbinary
MD5:7C2AA873AD45DAFB7489AAB897697E01
SHA256:93C2C200688FC46B12CC33033CBE451064BDB4B8D8D838FA6F7B0492FC1D44AB
6692Setup_BrightSlide_1.0.9.tmpC:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide\is-RD1HH.tmpimage
MD5:3AA880A71196180ED0785ED76711F617
SHA256:3C1955E68F37B2AD057234DB94D61CB3B9F4B8220EAAA9E1F89AA28BB7479DEE
6692Setup_BrightSlide_1.0.9.tmpC:\Users\admin\AppData\Roaming\Microsoft\AddIns\BrightCarbon\BrightSlide\alignToSelectionL.pngimage
MD5:24FF4B975FA15E650A77A69DC2263DDB
SHA256:EA92A5CB8987498DCB79489A6B67EC65290160E77CBAB38D3F064CCF51100DAC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
89
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7088
BrightSlide Assets.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEG3UcusCrgQG492EP1%2FhReE%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7088
BrightSlide Assets.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRXzFDqgcxizGsL1BkUc1gIwekZcAQU34%2FzIAzpyqYE2FtYNyo9q0bcg0kCEQCAA2Pw%2B5cxP%2FtbEcnfxruL
unknown
whitelisted
3840
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3840
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
836
POWERPNT.EXE
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6464
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
836
POWERPNT.EXE
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl
unknown
whitelisted
836
POWERPNT.EXE
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl
unknown
whitelisted
836
POWERPNT.EXE
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7088
BrightSlide Assets.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
whitelisted
640
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.159.75
  • 40.126.31.71
  • 20.190.159.68
  • 40.126.31.69
  • 20.190.159.2
  • 40.126.31.67
  • 20.190.159.23
  • 20.190.159.71
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
arc.msn.com
  • 20.74.47.205
  • 20.223.35.26
  • 20.31.169.57
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info