File name:

WeMod Manor Lords Setup.exe

Full analysis: https://app.any.run/tasks/62bb28c6-cc73-4fb1-b0d3-08d6ab2dcc0b
Verdict: Malicious activity
Analysis date: March 19, 2025, 22:59:20
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

82097273963EA15B183283522C99CCEF

SHA1:

BDAF41A36A246099A57D95DD425AACB31E11A365

SHA256:

D732C7BB0C539DFC5B81F0173EA76FC80FFDAD87240E47A089492D63EEF5335E

SSDEEP:

1536:Q668Dtf9nk7RBog5KG6JkOiVPL+09ME5LBtJD64uQgCYO6+YFyHA7OqCkNRBog5m:w8DvE57miVj+J6pHdHg7OA57N/u

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • Update.exe (PID: 7052)
      • ShellExperienceHost.exe (PID: 4452)
      • Update.exe (PID: 4560)
      • WeModAuxiliaryService.exe (PID: 7228)
    • Reads Microsoft Outlook installation path

      • WeMod Manor Lords Setup.exe (PID: 1328)
    • Reads Internet Explorer settings

      • WeMod Manor Lords Setup.exe (PID: 1328)
    • Executable content was dropped or overwritten

      • WeMod-Setup-638780219722716362.exe (PID: 2664)
      • Update.exe (PID: 7052)
    • Process drops legitimate windows executable

      • Update.exe (PID: 7052)
    • Reads the date of Windows installation

      • Update.exe (PID: 4560)
    • Application launched itself

      • WeMod.exe (PID: 4812)
  • INFO

    • Reads the computer name

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • squirrel.exe (PID: 1764)
      • Update.exe (PID: 4560)
      • Update.exe (PID: 6944)
      • WeMod.exe (PID: 2332)
    • Checks supported languages

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • WeMod-Setup-638780219722716362.exe (PID: 2664)
      • Update.exe (PID: 7052)
      • squirrel.exe (PID: 1764)
      • ShellExperienceHost.exe (PID: 4452)
      • Update.exe (PID: 4560)
      • WeMod.exe (PID: 4812)
      • WeMod.exe (PID: 5680)
      • Update.exe (PID: 6944)
      • WeMod.exe (PID: 2332)
      • Update.exe (PID: 6652)
      • WeModAuxiliaryService.exe (PID: 7228)
    • Reads the machine GUID from the registry

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • Update.exe (PID: 7052)
      • squirrel.exe (PID: 1764)
      • Update.exe (PID: 6944)
      • Update.exe (PID: 4560)
      • WeModAuxiliaryService.exe (PID: 7228)
    • Checks proxy server information

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • BackgroundTransferHost.exe (PID: 6068)
      • Update.exe (PID: 6652)
    • Reads the software policy settings

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • BackgroundTransferHost.exe (PID: 6068)
      • Update.exe (PID: 7052)
      • Update.exe (PID: 6652)
    • Creates files or folders in the user directory

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • BackgroundTransferHost.exe (PID: 6068)
      • WeMod-Setup-638780219722716362.exe (PID: 2664)
      • Update.exe (PID: 7052)
      • squirrel.exe (PID: 1764)
      • Update.exe (PID: 6944)
      • Update.exe (PID: 4560)
      • WeMod.exe (PID: 4812)
      • Update.exe (PID: 6652)
      • WeMod.exe (PID: 2332)
    • Reads Environment values

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • Update.exe (PID: 7052)
      • WeMod.exe (PID: 5680)
      • WeMod.exe (PID: 4812)
      • Update.exe (PID: 6652)
    • Disables trace logs

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • Update.exe (PID: 7052)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 4428)
      • BackgroundTransferHost.exe (PID: 6068)
      • BackgroundTransferHost.exe (PID: 4932)
      • BackgroundTransferHost.exe (PID: 2516)
      • BackgroundTransferHost.exe (PID: 7012)
    • Create files in a temporary directory

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • Update.exe (PID: 7052)
      • WeMod.exe (PID: 4812)
    • The sample compiled with english language support

      • Update.exe (PID: 7052)
    • Process checks computer location settings

      • Update.exe (PID: 4560)
    • Reads product name

      • WeMod.exe (PID: 5680)
      • WeMod.exe (PID: 4812)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2076:12:06 19:29:50+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 105984
InitializedDataSize: 28160
UninitializedDataSize: -
EntryPoint: 0x1bcfe
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 8.0.0.0
ProductVersionNumber: 8.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: WeMod Setup
CompanyName: WeMod LLC
FileDescription: WeMod Setup
FileVersion: 8.0.0.0
InternalName: WeMod-Setup.exe
LegalCopyright: Copyright © WeMod LLC 2022
LegalTrademarks: -
OriginalFileName: WeMod-Setup.exe
ProductName: WeMod
ProductVersion: 8.0.0.0
AssemblyVersion: 8.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
21
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start wemod manor lords setup.exe sppextcomobj.exe no specs slui.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs wemod-setup-638780219722716362.exe update.exe squirrel.exe no specs wemod.exe no specs update.exe no specs shellexperiencehost.exe no specs update.exe no specs wemod.exe no specs wemod.exe no specs wemod.exe no specs wemod.exe no specs update.exe wemodauxiliaryservice.exe

Process information

PID
CMD
Path
Indicators
Parent process
1128"C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\WeMod" --app-user-model-id=com.squirrel.WeMod.WeMod --app-path="C:\Users\admin\AppData\Local\WeMod\app-10.8.1\resources\app.asar" --no-sandbox --no-zygote --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --field-trial-handle=2580,i,5547426010144408216,11447557989369380618,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --variations-seed-version --mojo-platform-channel-handle=2584 /prefetch:1C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exeWeMod.exe
User:
admin
Company:
WeMod
Integrity Level:
MEDIUM
Description:
WeMod - The Ultimate Game Companion
Version:
10.8.1
Modules
Images
c:\users\admin\appdata\local\wemod\app-10.8.1\wemod.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\users\admin\appdata\local\wemod\app-10.8.1\ffmpeg.dll
1164"C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\WeMod" --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=1872,i,5547426010144408216,11447557989369380618,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --variations-seed-version --mojo-platform-channel-handle=1856 /prefetch:2C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exeWeMod.exe
User:
admin
Company:
WeMod
Integrity Level:
LOW
Description:
WeMod - The Ultimate Game Companion
Version:
10.8.1
Modules
Images
c:\users\admin\appdata\local\wemod\app-10.8.1\wemod.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1328"C:\Users\admin\AppData\Local\Temp\WeMod Manor Lords Setup.exe" C:\Users\admin\AppData\Local\Temp\WeMod Manor Lords Setup.exe
explorer.exe
User:
admin
Company:
WeMod LLC
Integrity Level:
MEDIUM
Description:
WeMod Setup
Exit code:
0
Version:
8.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\wemod manor lords setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1764"C:\Users\admin\AppData\Local\WeMod\app-10.8.1\Squirrel.exe" --updateSelf=C:\Users\admin\AppData\Local\SquirrelTemp\Update.exeC:\Users\admin\AppData\Local\WeMod\app-10.8.1\squirrel.exeUpdate.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\wemod\app-10.8.1\squirrel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2332"C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --force-ui-direction=ltr --user-data-dir="C:\Users\admin\AppData\Roaming\WeMod" --field-trial-handle=2128,i,5547426010144408216,11447557989369380618,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --variations-seed-version --mojo-platform-channel-handle=1440 /prefetch:3C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exeWeMod.exe
User:
admin
Company:
WeMod
Integrity Level:
MEDIUM
Description:
WeMod - The Ultimate Game Companion
Version:
10.8.1
Modules
Images
c:\users\admin\appdata\local\wemod\app-10.8.1\wemod.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\local\wemod\app-10.8.1\ffmpeg.dll
c:\windows\system32\combase.dll
2516"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
2664"C:\Users\admin\AppData\Local\Temp\WeMod-Setup-638780219722716362.exe" --silentC:\Users\admin\AppData\Local\Temp\WeMod-Setup-638780219722716362.exe
WeMod Manor Lords Setup.exe
User:
admin
Company:
WeMod
Integrity Level:
MEDIUM
Description:
WeMod - The Ultimate Gaming Companion
Exit code:
0
Version:
10.8.1
Modules
Images
c:\users\admin\appdata\local\temp\wemod-setup-638780219722716362.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3240"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4428"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
4452"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\wincorlib.dll
Total events
13 000
Read events
12 918
Write events
62
Delete events
20

Modification events

(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
Executable files
26
Suspicious files
120
Text files
32
Unknown types
0

Dropped files

PID
Process
Filename
Type
6068BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\088366ea-a7e3-4136-a117-04c610c9c96a.down_data
MD5:
SHA256:
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\Local\Temp\WeMod-Setup-638780219722716362.exe
MD5:
SHA256:
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:EA76B1CE6C69004853A01DC8F5096F4B
SHA256:8184C428FF793B00F4B982589CEC054D6A8C61AB705C722CDE5F201DC72A94C7
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C9BE626E9715952E9B70F92F912B9787
SHA256:C13E8D22800C200915F87F71C31185053E4E60CA25DE2E41E160E09CD2D815D4
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:971C514F84BBA0785F80AA1C23EDFD79
SHA256:F157ED17FCAF8837FA82F8B69973848C9B10A02636848F995698212A08F31895
6068BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:8B96DC5A0E8559E641847F4E31011EB7
SHA256:FE61D42A981CE19CB0B18D0FD1D6354B40B817C207B61602194ADAFAB718A99E
2664WeMod-Setup-638780219722716362.exeC:\Users\admin\AppData\Local\SquirrelTemp\WeMod-10.8.1-full.nupkg
MD5:
SHA256:
6068BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\088366ea-a7e3-4136-a117-04c610c9c96a.4df8e1fa-7e2c-4f8f-b67c-09cad36af25b.down_metabinary
MD5:8E020D231D6004285E9F21D5F9A0362A
SHA256:FE3AA907142BCA0029811FF5D4C5199336AC0A3F40B0AEE578C4273B0D7B8428
7052Update.exeC:\Users\admin\AppData\Local\WeMod\packages\WeMod-10.8.1-full.nupkg
MD5:
SHA256:
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\Inter-Light-0f0118feb7[1].woffbinary
MD5:0F0118FEB71664927EA7FB8015778795
SHA256:CB671D0DBC9A61EC80BFC91D5879E8635A09B7F309F5EE57810D4C6B7A26EE0C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
31
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1328
WeMod Manor Lords Setup.exe
GET
200
216.58.206.67:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
1328
WeMod Manor Lords Setup.exe
GET
200
216.58.206.67:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
104.124.11.58:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6652
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1276
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6068
BackgroundTransferHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6652
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3768
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
104.124.11.58:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3304
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1328
WeMod Manor Lords Setup.exe
104.22.42.75:443
api.wemod.com
CLOUDFLARENET
whitelisted
1328
WeMod Manor Lords Setup.exe
216.58.206.67:80
c.pki.goog
GOOGLE
US
whitelisted
3216
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 104.124.11.58
  • 104.124.11.17
whitelisted
api.wemod.com
  • 104.22.42.75
  • 104.22.43.75
  • 172.67.25.118
whitelisted
c.pki.goog
  • 216.58.206.67
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 20.190.160.131
  • 20.190.160.17
  • 40.126.32.74
  • 40.126.32.136
  • 20.190.160.128
  • 40.126.32.134
  • 20.190.160.65
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
storage-cdn.wemod.com
  • 104.22.42.75
  • 104.22.43.75
  • 172.67.25.118
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted

Threats

No threats detected
No debug info