File name:

WeMod Manor Lords Setup.exe

Full analysis: https://app.any.run/tasks/62bb28c6-cc73-4fb1-b0d3-08d6ab2dcc0b
Verdict: Malicious activity
Analysis date: March 19, 2025, 22:59:20
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

82097273963EA15B183283522C99CCEF

SHA1:

BDAF41A36A246099A57D95DD425AACB31E11A365

SHA256:

D732C7BB0C539DFC5B81F0173EA76FC80FFDAD87240E47A089492D63EEF5335E

SSDEEP:

1536:Q668Dtf9nk7RBog5KG6JkOiVPL+09ME5LBtJD64uQgCYO6+YFyHA7OqCkNRBog5m:w8DvE57miVj+J6pHdHg7OA57N/u

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • WeMod Manor Lords Setup.exe (PID: 1328)
    • Reads security settings of Internet Explorer

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • Update.exe (PID: 7052)
      • ShellExperienceHost.exe (PID: 4452)
      • Update.exe (PID: 4560)
      • WeModAuxiliaryService.exe (PID: 7228)
    • Reads Internet Explorer settings

      • WeMod Manor Lords Setup.exe (PID: 1328)
    • Executable content was dropped or overwritten

      • WeMod-Setup-638780219722716362.exe (PID: 2664)
      • Update.exe (PID: 7052)
    • Process drops legitimate windows executable

      • Update.exe (PID: 7052)
    • Reads the date of Windows installation

      • Update.exe (PID: 4560)
    • Application launched itself

      • WeMod.exe (PID: 4812)
  • INFO

    • Checks proxy server information

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • BackgroundTransferHost.exe (PID: 6068)
      • Update.exe (PID: 6652)
    • Reads the machine GUID from the registry

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • Update.exe (PID: 7052)
      • squirrel.exe (PID: 1764)
      • Update.exe (PID: 4560)
      • Update.exe (PID: 6944)
      • WeModAuxiliaryService.exe (PID: 7228)
    • Checks supported languages

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • Update.exe (PID: 7052)
      • squirrel.exe (PID: 1764)
      • WeMod.exe (PID: 5680)
      • WeMod-Setup-638780219722716362.exe (PID: 2664)
      • ShellExperienceHost.exe (PID: 4452)
      • Update.exe (PID: 4560)
      • WeMod.exe (PID: 4812)
      • Update.exe (PID: 6944)
      • WeMod.exe (PID: 2332)
      • Update.exe (PID: 6652)
      • WeModAuxiliaryService.exe (PID: 7228)
    • Creates files or folders in the user directory

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • BackgroundTransferHost.exe (PID: 6068)
      • WeMod-Setup-638780219722716362.exe (PID: 2664)
      • Update.exe (PID: 7052)
      • squirrel.exe (PID: 1764)
      • Update.exe (PID: 6944)
      • Update.exe (PID: 4560)
      • WeMod.exe (PID: 4812)
      • Update.exe (PID: 6652)
      • WeMod.exe (PID: 2332)
    • Reads the software policy settings

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • BackgroundTransferHost.exe (PID: 6068)
      • Update.exe (PID: 7052)
      • Update.exe (PID: 6652)
    • Reads Environment values

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • Update.exe (PID: 7052)
      • WeMod.exe (PID: 5680)
      • Update.exe (PID: 6652)
      • WeMod.exe (PID: 4812)
    • Reads the computer name

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • squirrel.exe (PID: 1764)
      • Update.exe (PID: 4560)
      • Update.exe (PID: 6944)
      • WeMod.exe (PID: 2332)
    • Disables trace logs

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • Update.exe (PID: 7052)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 2516)
      • BackgroundTransferHost.exe (PID: 4428)
      • BackgroundTransferHost.exe (PID: 6068)
      • BackgroundTransferHost.exe (PID: 7012)
      • BackgroundTransferHost.exe (PID: 4932)
    • Create files in a temporary directory

      • WeMod Manor Lords Setup.exe (PID: 1328)
      • Update.exe (PID: 7052)
      • WeMod.exe (PID: 4812)
    • The sample compiled with english language support

      • Update.exe (PID: 7052)
    • Reads product name

      • WeMod.exe (PID: 5680)
      • WeMod.exe (PID: 4812)
    • Process checks computer location settings

      • Update.exe (PID: 4560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2076:12:06 19:29:50+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 105984
InitializedDataSize: 28160
UninitializedDataSize: -
EntryPoint: 0x1bcfe
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 8.0.0.0
ProductVersionNumber: 8.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: WeMod Setup
CompanyName: WeMod LLC
FileDescription: WeMod Setup
FileVersion: 8.0.0.0
InternalName: WeMod-Setup.exe
LegalCopyright: Copyright © WeMod LLC 2022
LegalTrademarks: -
OriginalFileName: WeMod-Setup.exe
ProductName: WeMod
ProductVersion: 8.0.0.0
AssemblyVersion: 8.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
21
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start wemod manor lords setup.exe sppextcomobj.exe no specs slui.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs wemod-setup-638780219722716362.exe update.exe squirrel.exe no specs wemod.exe no specs update.exe no specs shellexperiencehost.exe no specs update.exe no specs wemod.exe no specs wemod.exe no specs wemod.exe no specs wemod.exe no specs update.exe wemodauxiliaryservice.exe

Process information

PID
CMD
Path
Indicators
Parent process
1128"C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\WeMod" --app-user-model-id=com.squirrel.WeMod.WeMod --app-path="C:\Users\admin\AppData\Local\WeMod\app-10.8.1\resources\app.asar" --no-sandbox --no-zygote --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --field-trial-handle=2580,i,5547426010144408216,11447557989369380618,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --variations-seed-version --mojo-platform-channel-handle=2584 /prefetch:1C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exeWeMod.exe
User:
admin
Company:
WeMod
Integrity Level:
MEDIUM
Description:
WeMod - The Ultimate Game Companion
Version:
10.8.1
Modules
Images
c:\users\admin\appdata\local\wemod\app-10.8.1\wemod.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\users\admin\appdata\local\wemod\app-10.8.1\ffmpeg.dll
1164"C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\WeMod" --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=1872,i,5547426010144408216,11447557989369380618,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --variations-seed-version --mojo-platform-channel-handle=1856 /prefetch:2C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exeWeMod.exe
User:
admin
Company:
WeMod
Integrity Level:
LOW
Description:
WeMod - The Ultimate Game Companion
Version:
10.8.1
Modules
Images
c:\users\admin\appdata\local\wemod\app-10.8.1\wemod.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1328"C:\Users\admin\AppData\Local\Temp\WeMod Manor Lords Setup.exe" C:\Users\admin\AppData\Local\Temp\WeMod Manor Lords Setup.exe
explorer.exe
User:
admin
Company:
WeMod LLC
Integrity Level:
MEDIUM
Description:
WeMod Setup
Exit code:
0
Version:
8.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\wemod manor lords setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1764"C:\Users\admin\AppData\Local\WeMod\app-10.8.1\Squirrel.exe" --updateSelf=C:\Users\admin\AppData\Local\SquirrelTemp\Update.exeC:\Users\admin\AppData\Local\WeMod\app-10.8.1\squirrel.exeUpdate.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\wemod\app-10.8.1\squirrel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2332"C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --force-ui-direction=ltr --user-data-dir="C:\Users\admin\AppData\Roaming\WeMod" --field-trial-handle=2128,i,5547426010144408216,11447557989369380618,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --variations-seed-version --mojo-platform-channel-handle=1440 /prefetch:3C:\Users\admin\AppData\Local\WeMod\app-10.8.1\WeMod.exeWeMod.exe
User:
admin
Company:
WeMod
Integrity Level:
MEDIUM
Description:
WeMod - The Ultimate Game Companion
Version:
10.8.1
Modules
Images
c:\users\admin\appdata\local\wemod\app-10.8.1\wemod.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\local\wemod\app-10.8.1\ffmpeg.dll
c:\windows\system32\combase.dll
2516"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
2664"C:\Users\admin\AppData\Local\Temp\WeMod-Setup-638780219722716362.exe" --silentC:\Users\admin\AppData\Local\Temp\WeMod-Setup-638780219722716362.exe
WeMod Manor Lords Setup.exe
User:
admin
Company:
WeMod
Integrity Level:
MEDIUM
Description:
WeMod - The Ultimate Gaming Companion
Exit code:
0
Version:
10.8.1
Modules
Images
c:\users\admin\appdata\local\temp\wemod-setup-638780219722716362.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3240"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4428"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
4452"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\wincorlib.dll
Total events
13 000
Read events
12 918
Write events
62
Delete events
20

Modification events

(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(1328) WeMod Manor Lords Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WeMod Manor Lords Setup_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
Executable files
26
Suspicious files
120
Text files
32
Unknown types
0

Dropped files

PID
Process
Filename
Type
6068BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\088366ea-a7e3-4136-a117-04c610c9c96a.down_data
MD5:
SHA256:
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\Local\Temp\WeMod-Setup-638780219722716362.exe
MD5:
SHA256:
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C9BE626E9715952E9B70F92F912B9787
SHA256:C13E8D22800C200915F87F71C31185053E4E60CA25DE2E41E160E09CD2D815D4
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\Inter-Medium-5ce3e4db96[1].woffbinary
MD5:5CE3E4DB9634913232403F166B2447DE
SHA256:68D52E74E8171DDB2C94CA60A2596DC8A46407320449881FD09369DBC317624C
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\Inter-ExtraLight-7d759358c1[1].woffbinary
MD5:7D759358C1372FA6ACAE4CB22F93DEFA
SHA256:07F5B5F734793F48613D8DA246F4DB2B564BFA7149F62526326BE9CB8BB94841
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:EA76B1CE6C69004853A01DC8F5096F4B
SHA256:8184C428FF793B00F4B982589CEC054D6A8C61AB705C722CDE5F201DC72A94C7
2664WeMod-Setup-638780219722716362.exeC:\Users\admin\AppData\Local\SquirrelTemp\WeMod-10.8.1-full.nupkg
MD5:
SHA256:
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:971C514F84BBA0785F80AA1C23EDFD79
SHA256:F157ED17FCAF8837FA82F8B69973848C9B10A02636848F995698212A08F31895
7052Update.exeC:\Users\admin\AppData\Local\WeMod\packages\WeMod-10.8.1-full.nupkg
MD5:
SHA256:
1328WeMod Manor Lords Setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\Inter-Thin-0f080c40c6[1].woffbinary
MD5:0F080C40C639962E1CAD093AA58192DC
SHA256:E9DA5A64A6A8EB87A2C6D475327F072B5CA25731DF07119F576C10C50AA9554D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
31
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1328
WeMod Manor Lords Setup.exe
GET
200
216.58.206.67:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
104.124.11.58:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1328
WeMod Manor Lords Setup.exe
GET
200
216.58.206.67:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6068
BackgroundTransferHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6652
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1276
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6652
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3768
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
104.124.11.58:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3304
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1328
WeMod Manor Lords Setup.exe
104.22.42.75:443
api.wemod.com
CLOUDFLARENET
whitelisted
1328
WeMod Manor Lords Setup.exe
216.58.206.67:80
c.pki.goog
GOOGLE
US
whitelisted
3216
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 104.124.11.58
  • 104.124.11.17
whitelisted
api.wemod.com
  • 104.22.42.75
  • 104.22.43.75
  • 172.67.25.118
whitelisted
c.pki.goog
  • 216.58.206.67
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 20.190.160.131
  • 20.190.160.17
  • 40.126.32.74
  • 40.126.32.136
  • 20.190.160.128
  • 40.126.32.134
  • 20.190.160.65
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
storage-cdn.wemod.com
  • 104.22.42.75
  • 104.22.43.75
  • 172.67.25.118
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted

Threats

No threats detected
No debug info