File name:

d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe

Full analysis: https://app.any.run/tasks/856a2038-269a-428c-a549-db916760d62f
Verdict: Malicious activity
Analysis date: March 06, 2024, 09:28:34
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

26BC45B7EDADC11281B6ACB58D1E1D03

SHA1:

F184F4C70928BDC55AB3D5FAF42C359D6232D9AE

SHA256:

D10F367E9F06ADE8A710E20B00D1B4EECB456E1923369725A276EEE871841417

SSDEEP:

196608:Jtq9owWFa2lVHhXsILm+XXZjU8YBg5reMyujDlnTu4XNY:JEqe4V1LLm+XJjHYq5Hb9nTuwNY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe (PID: 6552)
      • BvWinFspMgr.exe (PID: 6192)
      • msiexec.exe (PID: 2944)
    • Drops the executable file immediately after the start

      • BvWinFspMgr.exe (PID: 6192)
      • d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe (PID: 6552)
      • msiexec.exe (PID: 2944)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe (PID: 6552)
      • BvWinFspMgr.exe (PID: 6192)
    • Creates files in the driver directory

      • BvWinFspMgr.exe (PID: 6192)
    • Executable content was dropped or overwritten

      • BvWinFspMgr.exe (PID: 6192)
      • d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe (PID: 6552)
    • Creates or modifies Windows services

      • BvWinFspMgr.exe (PID: 6192)
    • Creates a software uninstall entry

      • d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe (PID: 6552)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 2944)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 2944)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 2944)
    • Creates/Modifies COM task schedule object

      • d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe (PID: 6552)
    • Searches for installed software

      • BvSsh.exe (PID: 5296)
    • Reads security settings of Internet Explorer

      • BvSsh.exe (PID: 5296)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 2944)
      • BvSsh.exe (PID: 5296)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 2944)
  • INFO

    • Reads the computer name

      • d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe (PID: 6552)
      • BvWinFspMgr.exe (PID: 6192)
      • msiexec.exe (PID: 2944)
      • BvSsh.exe (PID: 5296)
    • Creates files in the program directory

      • d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe (PID: 6552)
    • Checks supported languages

      • d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe (PID: 6552)
      • BvEventSource.exe (PID: 2368)
      • BvWinFspMgr.exe (PID: 6192)
      • msiexec.exe (PID: 2944)
      • BvSsh.exe (PID: 5296)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 2944)
      • BvSsh.exe (PID: 5296)
    • Reads the software policy settings

      • msiexec.exe (PID: 2944)
      • BvSsh.exe (PID: 5296)
      • slui.exe (PID: 3752)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2944)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 2944)
      • BvSsh.exe (PID: 5296)
    • Manual execution by a user

      • BvSsh.exe (PID: 5296)
    • Checks proxy server information

      • BvSsh.exe (PID: 5296)
      • slui.exe (PID: 3752)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:20 22:33:07+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 756736
InitializedDataSize: 26369024
UninitializedDataSize: -
EntryPoint: 0x85ab0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows command line
FileVersionNumber: 9.33.0.0
ProductVersionNumber: 9.33.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: -
CompanyName: Bitvise Limited
FileDescription: Bitvise SSH Client Installer
FileVersion: 9.33.0.0
InternalName: BvSshClient-Inst
LegalCopyright: Copyright (C) 2000-2023 by Bitvise Limited.
LegalTrademarks: -
OriginalFileName: BvSshClient-Inst.exe
PrivateBuild: -
ProductName: Bitvise SSH Client
ProductVersion: 9.33
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
10
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe conhost.exe no specs bveventsource.exe no specs bvwinfspmgr.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs slui.exe bvssh.exe d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1020msiexec.exe /i "C:\Program Files (x86)\Bitvise SSH Client\FlowSshNet64.msi" INSTALLDIR="C:\Program Files (x86)\Bitvise SSH Client" /quiet /norestart MSIRESTARTMANAGERCONTROL="Disable"C:\Windows\SysWOW64\msiexec.exed10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1460msiexec.exe /i "C:\Program Files (x86)\Bitvise SSH Client\FlowSshNet32.msi" INSTALLDIR="C:\Program Files (x86)\Bitvise SSH Client" /quiet /norestart MSIRESTARTMANAGERCONTROL="Disable"C:\Windows\SysWOW64\msiexec.exed10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2368"C:\WINDOWS\system32\BvEventSource.exe" registerC:\Windows\System32\BvEventSource.exed10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe
User:
admin
Company:
Bitvise Limited
Integrity Level:
HIGH
Description:
Bitvise Log Event Source Utility
Exit code:
0
Version:
1.02
Modules
Images
c:\windows\system32\bveventsource.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
2460\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exed10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2944C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3752C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
5296"C:\Program Files (x86)\Bitvise SSH Client\BvSsh.exe" C:\Program Files (x86)\Bitvise SSH Client\BvSsh.exe
explorer.exe
User:
admin
Company:
Bitvise Limited
Integrity Level:
MEDIUM
Description:
Bitvise SSH Client
Exit code:
0
Version:
9.33.0.0
Modules
Images
c:\program files (x86)\bitvise ssh client\bvssh.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
6192"C:\WINDOWS\BvWinFspMgr.exe" InstallC:\Windows\BvWinFspMgr.exe
d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe
User:
admin
Company:
Bitvise Limited
Integrity Level:
HIGH
Description:
Bitvise WinFsp Driver Management Utility
Exit code:
0
Version:
1.01
Modules
Images
c:\windows\bvwinfspmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6552"C:\Users\admin\AppData\Local\Temp\d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe" C:\Users\admin\AppData\Local\Temp\d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe
explorer.exe
User:
admin
Company:
Bitvise Limited
Integrity Level:
HIGH
Description:
Bitvise SSH Client Installer
Exit code:
0
Version:
9.33.0.0
Modules
Images
c:\users\admin\appdata\local\temp\d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6912"C:\Users\admin\AppData\Local\Temp\d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe" C:\Users\admin\AppData\Local\Temp\d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeexplorer.exe
User:
admin
Company:
Bitvise Limited
Integrity Level:
MEDIUM
Description:
Bitvise SSH Client Installer
Exit code:
3221226540
Version:
9.33.0.0
Modules
Images
c:\users\admin\appdata\local\temp\d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
12 727
Read events
12 331
Write events
366
Delete events
30

Modification events

(PID) Process:(2368) BvEventSource.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\Bitvise Installer
Operation:writeName:EventMessageFile
Value:
C:\WINDOWS\system32\BvEventSource.exe
(PID) Process:(2368) BvEventSource.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\Bitvise Installer
Operation:writeName:TypesSupported
Value:
7
(PID) Process:(6552) d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitvise\Installers
Operation:writeName:Bitvise SSH Client Installer
Value:
"C:\Users\admin\AppData\Local\Temp\d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exe" -acceptEULA -installDir="C:\Program Files (x86)\Bitvise SSH Client" -interactive -runWhenDone
(PID) Process:(6552) d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Bitvise SSH Client Installer
Value:
(PID) Process:(6552) d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Tunnelier Installer
Value:
(PID) Process:(6552) d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:Bitvise-WWLib-CRegSafeModify-Guard-45150DC24C566C9D69E778BD71FF42F8585C46D2
Value:
0
(PID) Process:(6192) BvWinFspMgr.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinFsp.Np\NetworkProvider
Operation:writeName:Name
Value:
Windows File System Proxy
(PID) Process:(6192) BvWinFspMgr.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinFsp.Np\NetworkProvider
Operation:writeName:DeviceName
Value:
\Device\WinFsp.Mup
(PID) Process:(6192) BvWinFspMgr.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinFsp.Np\NetworkProvider
Operation:writeName:ProviderPath
Value:
C:\WINDOWS\system32\BvWinFsp.dll
(PID) Process:(6192) BvWinFspMgr.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinFsp.Np
Operation:writeName:Group
Value:
NetworkProvider
Executable files
79
Suspicious files
26
Text files
6
Unknown types
26

Dropped files

PID
Process
Filename
Type
6552d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeC:\Program Files (x86)\Bitvise SSH Client\log.exeexecutable
MD5:0B29570A2B9475955AE11D264BC9C110
SHA256:4D173E481E96205EA1F222C730BA37543C344194283F15B49D1F89CD4B8D2F9E
6552d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeC:\Program Files (x86)\Bitvise SSH Client\CiCpFips32.dllexecutable
MD5:7444B33ED49B788089E2EB4C29A64F72
SHA256:4EF057D09CDB4D7B7037EB45080928BCD01CD75AF23D278A1ABF1C316FD57670
6552d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeC:\Program Files (x86)\Bitvise SSH Client\CiCpFips64.dllexecutable
MD5:D5515B8F6DFC68069431748ADAAF1F88
SHA256:91DC41249C6894382C09AFB34910A6ED374A86ADC1F6E493B5E94239678F6003
6552d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeC:\Program Files (x86)\Bitvise SSH Client\uninst.exeexecutable
MD5:E437D1F3AEEF071168F04CF6C55935EA
SHA256:369CBA2C96A34B4989112A189CD2D38E198DEC3BA2B3C65CB704F51540490B03
6552d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeC:\WINDOWS\system32\BvEventSource.exeexecutable
MD5:65DA6CF5313B8EFF5858935853CE63C4
SHA256:D18FC2BA355122BF0383B62C0A6F6BC52B764FAACD62836F07AB997F5428E142
6552d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeC:\Program Files (x86)\Bitvise SSH Client\Countries.binbs
MD5:338EC61E822FDF00B7A9C195013FA491
SHA256:986146928A9938573F7B088BB0F3175F67EB7151C650D5ABC4CB99B406E5DF9E
6552d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeC:\Program Files (x86)\Bitvise SSH Client\BscInstalledResources.htmhtml
MD5:F7CD682253A9FFFFE3D6C811F5195352
SHA256:527284A653383EA5B929F7687085882860974DE62E51AAD3E46F9DEF70B298A4
6552d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeC:\Program Files (x86)\Bitvise SSH Client\BvSshCtrl.exeexecutable
MD5:157F80FF21E4044D9E3CEBC969D33ED0
SHA256:E4406C26C9ADBEC14ABEAC919D6389B2850E514C62D3722A35BA384960972F6A
6552d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeC:\Program Files (x86)\Bitvise SSH Client\BvSshUpdate.exeexecutable
MD5:2FFFCBFD4FD008808DBF0B2368DABB67
SHA256:0308BFC6C2B1A48A316120712E3FB3B1CBA211453C2B05C6F5E38EC4C1712F32
6552d10f367e9f06ade8a710e20b00d1b4eecb456e1923369725a276eee871841417.exeC:\Program Files (x86)\Bitvise SSH Client\BscActCode.exeexecutable
MD5:46726A7A2D9B7234E97161A3BBD86AEB
SHA256:20F13CA46D9ECC2A026C239D928B27DFC8CE020CAED526DE7920A49709F4AAE4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
33
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5928
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
5928
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
5928
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
unknown
binary
471 b
unknown
2944
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D
unknown
binary
765 b
unknown
2944
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D
unknown
binary
1.42 Kb
unknown
872
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
313 b
unknown
2944
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVD%2BnGf79Hpedv3mhy6uKMVZkPCQQUDyrLIIcouOxvSK4rVKYpqhekzQwCEGL3Tmi4GXrLF6oYQjkos38%3D
unknown
binary
637 b
unknown
5296
BvSsh.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEChOOcFLOG2InHKZ5YzQWlc%3D
unknown
binary
2.18 Kb
unknown
2464
svchost.exe
GET
200
2.19.105.18:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
3848
svchost.exe
239.255.255.250:1900
unknown
5928
svchost.exe
20.190.159.4:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:138
unknown
20.190.159.4:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5928
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
20.103.156.88:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5928
svchost.exe
20.190.159.23:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
www.bing.com
  • 23.213.161.200
  • 23.213.161.217
  • 23.213.161.214
  • 23.213.161.224
  • 23.213.161.225
  • 23.213.161.198
  • 23.213.161.222
  • 23.213.161.223
  • 23.213.161.219
  • 23.213.161.204
  • 23.213.161.196
  • 23.213.161.205
  • 23.213.161.202
  • 23.213.161.206
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
bitvise.com
  • 18.188.178.2
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted

Threats

No threats detected
No debug info