File name:

RevoUninProSetup.exe

Full analysis: https://app.any.run/tasks/fdd4b19d-6680-46c4-aac8-0ffea1c6d7b7
Verdict: Malicious activity
Analysis date: November 20, 2024, 13:00:12
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
possible-phishing
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

A056EEBBF2759849DCC784F2A38AD1BA

SHA1:

8AD1C868F5C89422617A18CF0F171F81EC9010D9

SHA256:

D094E8CD974F13D6FD7CE7733B7FAACCB8663095ED861BC7A541657DA57E298C

SSDEEP:

98304:102iNzKbCD2nYu06DkPQYZtJzewJKU61Ics5bwDtgzvW2wO+VyF9E1Ht5S09Cm0K:+DuTR9Rs6Uxx3mkcREuN2dmqnpfG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • RevoUninProSetup.exe (PID: 5340)
      • RevoUninProSetup.exe (PID: 6028)
      • RevoUninPro.exe (PID: 7108)
      • RevoUninPro.exe (PID: 6984)
    • Registers / Runs the DLL via REGSVR32.EXE

      • RevoUninProSetup.tmp (PID: 3796)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • RevoUninProSetup.exe (PID: 5340)
      • RevoUninProSetup.exe (PID: 6028)
      • RevoUninProSetup.tmp (PID: 3796)
      • rundll32.exe (PID: 6808)
    • Reads security settings of Internet Explorer

      • RevoUninProSetup.tmp (PID: 5444)
    • Uses TASKKILL.EXE to kill process

      • RevoUninProSetup.tmp (PID: 3796)
    • Drops a system driver (possible attempt to evade defenses)

      • RevoUninProSetup.tmp (PID: 3796)
      • rundll32.exe (PID: 6808)
    • Uses RUNDLL32.EXE to load library

      • RevoUninProSetup.tmp (PID: 3796)
  • INFO

    • Create files in a temporary directory

      • RevoUninProSetup.exe (PID: 5340)
      • RevoUninProSetup.exe (PID: 6028)
    • Checks supported languages

      • RevoUninProSetup.exe (PID: 5340)
      • RevoUninProSetup.tmp (PID: 5444)
      • RevoUninProSetup.exe (PID: 6028)
      • RevoUninProSetup.tmp (PID: 3796)
    • Reads the computer name

      • RevoUninProSetup.tmp (PID: 5444)
      • RevoUninProSetup.tmp (PID: 3796)
    • Process checks computer location settings

      • RevoUninProSetup.tmp (PID: 5444)
    • Application launched itself

      • msedge.exe (PID: 3772)
      • msedge.exe (PID: 6524)
    • Manual execution by a user

      • msedge.exe (PID: 6524)
      • Taskmgr.exe (PID: 8148)
      • Taskmgr.exe (PID: 7220)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (57.2)
.exe | Win32 Executable (generic) (18.2)
.exe | Win16/32 Executable Delphi generic (8.3)
.exe | Generic Win/DOS Executable (8)
.exe | DOS Executable Generic (8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:06:14 13:27:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 121344
UninitializedDataSize: -
EntryPoint: 0x1181c
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 4.5.0.0
ProductVersionNumber: 4.5.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: VS Revo Group
FileDescription: Revo Uninstaller Pro
FileVersion: 4.5.0.0
LegalCopyright: VS Revo Group, Ltd.
ProductName: Revo Uninstaller Pro
ProductVersion: 4.5.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
178
Monitored processes
52
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start revouninprosetup.exe revouninprosetup.tmp no specs revouninprosetup.exe revouninprosetup.tmp taskkill.exe no specs conhost.exe no specs regsvr32.exe no specs rundll32.exe runonce.exe no specs grpconv.exe no specs ruplp.exe no specs revouninpro.exe no specs revouninpro.exe no specs ruplp.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs taskmgr.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
556"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=16 --mojo-platform-channel-handle=5572 --field-trial-handle=2324,i,13285410225488301951,17812967819542887405,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
968"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4256 --field-trial-handle=2324,i,13285410225488301951,17812967819542887405,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3040"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2264 --field-trial-handle=2284,i,18241554585824593051,15730435157118759013,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3760"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5144 --field-trial-handle=2324,i,13285410225488301951,17812967819542887405,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3772"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.revouninstaller.com/pro-install-thankyou/C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeRevoUninProSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3796"C:\Users\admin\AppData\Local\Temp\is-PRL1F.tmp\RevoUninProSetup.tmp" /SL5="$301F6,16126922,188928,C:\Users\admin\AppData\Local\Temp\RevoUninProSetup.exe" /SPAWNWND=$301EC /NOTIFYWND=$701D8 C:\Users\admin\AppData\Local\Temp\is-PRL1F.tmp\RevoUninProSetup.tmp
RevoUninProSetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-prl1f.tmp\revouninprosetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
4024"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=4356 --field-trial-handle=2324,i,13285410225488301951,17812967819542887405,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
5124"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=4344 --field-trial-handle=2324,i,13285410225488301951,17812967819542887405,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
5340"C:\Users\admin\AppData\Local\Temp\RevoUninProSetup.exe" C:\Users\admin\AppData\Local\Temp\RevoUninProSetup.exe
explorer.exe
User:
admin
Company:
VS Revo Group
Integrity Level:
MEDIUM
Description:
Revo Uninstaller Pro
Exit code:
0
Version:
4.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\revouninprosetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
5444"C:\Users\admin\AppData\Local\Temp\is-PRSTD.tmp\RevoUninProSetup.tmp" /SL5="$701D8,16126922,188928,C:\Users\admin\AppData\Local\Temp\RevoUninProSetup.exe" C:\Users\admin\AppData\Local\Temp\is-PRSTD.tmp\RevoUninProSetup.tmpRevoUninProSetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-prstd.tmp\revouninprosetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
6 765
Read events
6 551
Write events
205
Delete events
9

Modification events

(PID) Process:(3796) RevoUninProSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB562550-BBE6-4298-861A-5C0A6562C272}
Operation:writeName:InfoTip
Value:
Uninstall, Remove Programs, Clear Web Browsers Tracks, Control Automatically Started Applications
(PID) Process:(3796) RevoUninProSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB562550-BBE6-4298-861A-5C0A6562C272}
Operation:writeName:{305CA226-D286-468e-B848-2B2E8E697B74} 2
Value:
8
(PID) Process:(3796) RevoUninProSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB562550-BBE6-4298-861A-5C0A6562C272}\ShellFolder
Operation:writeName:Attributes
Value:
48
(PID) Process:(3796) RevoUninProSetup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VS Revo Group\Revo Uninstaller Pro\General
Operation:writeName:Aff
Value:
https://www.revouninstaller.com/buy-now-btn/
(PID) Process:(3796) RevoUninProSetup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VS Revo Group\Revo Uninstaller Pro\General
Operation:writeName:USRenewLink
Value:
https://www.revouninstaller.com/buy-update-subscription-btn/
(PID) Process:(3796) RevoUninProSetup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VS Revo Group\Revo Uninstaller Pro\General
Operation:writeName:Anchor
Value:
www.revouninstaller.com
(PID) Process:(3796) RevoUninProSetup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VS Revo Group\Revo Uninstaller Pro\General
Operation:writeName:AffHome
Value:
https://www.revouninstaller.com
(PID) Process:(3796) RevoUninProSetup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VS Revo Group\Revo Uninstaller Pro\General
Operation:writeName:LDBURL
Value:
https://www.revouninstallerpro.com/db/ilogs/
(PID) Process:(3796) RevoUninProSetup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VS Revo Group\Revo Uninstaller Pro\General
Operation:writeName:WebLang
Value:
ENG
(PID) Process:(3796) RevoUninProSetup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\VS Revo Group\Revo Uninstaller Pro\General
Operation:writeName:Language file
Value:
english.ini
Executable files
23
Suspicious files
117
Text files
132
Unknown types
0

Dropped files

PID
Process
Filename
Type
3796RevoUninProSetup.tmpC:\Program Files\VS Revo Group\Revo Uninstaller Pro\is-VUFRE.tmpexecutable
MD5:2B26C6DBFC73F303CE85E1183EB93240
SHA256:8CFE8AE1ED05C2154A9875B3C08CC8071E82A67E01356456DC4B35556A6F44FE
3796RevoUninProSetup.tmpC:\Users\admin\AppData\Local\Temp\is-T4HR3.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
5340RevoUninProSetup.exeC:\Users\admin\AppData\Local\Temp\is-PRSTD.tmp\RevoUninProSetup.tmpexecutable
MD5:D0BF64E27284709966A4E2EFEF3233EF
SHA256:2019350B1451F4653D27C33B1C034155CE81534F318CD2E3591DD2EE73C77F09
3796RevoUninProSetup.tmpC:\Program Files\VS Revo Group\Revo Uninstaller Pro\lang\arabic.initext
MD5:F16B36E63303619EE98621BBF623968B
SHA256:68E4ECDD6CFD97DCADF55CF90531BD8A09142DB8CF8E62DFE20DD133759B9127
3796RevoUninProSetup.tmpC:\Program Files\VS Revo Group\Revo Uninstaller Pro\lang\is-1PEG1.tmptext
MD5:F16B36E63303619EE98621BBF623968B
SHA256:68E4ECDD6CFD97DCADF55CF90531BD8A09142DB8CF8E62DFE20DD133759B9127
3796RevoUninProSetup.tmpC:\Program Files\VS Revo Group\Revo Uninstaller Pro\lang\is-UMNU2.tmptext
MD5:5D7940A52B9653AB25C4FD2F15D0CC7C
SHA256:2D773FBC4D2C194A260964E76D2ECF28C89C29C6BD30632BF774F7DDBEB57FEC
3796RevoUninProSetup.tmpC:\Program Files\VS Revo Group\Revo Uninstaller Pro\lang\armenian.initext
MD5:22C302D515747DF778989919124FBDA2
SHA256:A74A42D62FD6E52E082E318548597E4F05F448C80BA49B91B5166C80F75B6D49
3796RevoUninProSetup.tmpC:\Program Files\VS Revo Group\Revo Uninstaller Pro\unins000.exeexecutable
MD5:2B26C6DBFC73F303CE85E1183EB93240
SHA256:8CFE8AE1ED05C2154A9875B3C08CC8071E82A67E01356456DC4B35556A6F44FE
3796RevoUninProSetup.tmpC:\Program Files\VS Revo Group\Revo Uninstaller Pro\lang\is-MLGJQ.tmptext
MD5:22C302D515747DF778989919124FBDA2
SHA256:A74A42D62FD6E52E082E318548597E4F05F448C80BA49B91B5166C80F75B6D49
6028RevoUninProSetup.exeC:\Users\admin\AppData\Local\Temp\is-PRL1F.tmp\RevoUninProSetup.tmpexecutable
MD5:D0BF64E27284709966A4E2EFEF3233EF
SHA256:2019350B1451F4653D27C33B1C034155CE81534F318CD2E3591DD2EE73C77F09
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
109
DNS requests
137
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6676
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6676
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5376
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4932
svchost.exe
GET
200
2.16.164.107:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4932
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4932
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5572
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.23.209.185:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4932
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4932
svchost.exe
2.16.164.107:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4932
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.23.209.185
  • 2.23.209.177
  • 2.23.209.130
  • 2.23.209.193
  • 2.23.209.179
  • 2.23.209.182
  • 2.23.209.181
  • 2.23.209.189
  • 2.23.209.183
  • 92.123.104.20
  • 92.123.104.33
  • 92.123.104.34
  • 92.123.104.35
  • 92.123.104.26
  • 92.123.104.31
  • 92.123.104.19
  • 92.123.104.28
  • 92.123.104.30
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 172.217.23.110
whitelisted
crl.microsoft.com
  • 2.16.164.107
  • 2.16.164.34
  • 2.16.164.24
  • 2.16.164.97
  • 2.16.164.89
  • 2.16.164.99
  • 2.16.164.98
  • 2.16.164.9
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
login.live.com
  • 20.190.159.75
  • 20.190.159.0
  • 40.126.31.73
  • 40.126.31.71
  • 20.190.159.2
  • 20.190.159.68
  • 20.190.159.64
  • 20.190.159.4
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

PID
Process
Class
Message
6772
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6772
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
6772
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
6772
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
Misc activity
ET INFO MailJet URL Shortening Service Domain in DNS Lookup (mjt .lu)
Possible Social Engineering Attempted
SUSPICIOUS [ANY.RUN] Domain is used for link redirection and static content hosting ( .mjt .lu)
Misc activity
ET INFO MailJet URL Shortening Service Domain in DNS Lookup (mjt .lu)
Possible Social Engineering Attempted
SUSPICIOUS [ANY.RUN] Domain is used for link redirection and static content hosting ( .mjt .lu)
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
No debug info