File name:

OpenExamSuite v3.2.0.exe

Full analysis: https://app.any.run/tasks/85dbf966-1be7-4828-b025-6ec926b2821d
Verdict: Malicious activity
Analysis date: March 24, 2025, 12:18:48
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

7F61018250E4A38D94E8FAD5703DE245

SHA1:

BBDE40E5FCDA29AD3F8C2640B5BE495F49D41F72

SHA256:

D7503F11A62C5D805436C141CFCB8A54D62394EE38C37FEBB5369DA3CC3CD09C

SSDEEP:

98304:cqTsXXM4WM1jml/K3BJP6gKk0hG2PoMtRRMv+RtBovXI50M5iePZjwHFaJZfqno3:h

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • OpenExamSuite v3.2.0.exe (PID: 7192)
    • Executable content was dropped or overwritten

      • OpenExamSuite v3.2.0.exe (PID: 7192)
    • The process creates files with name similar to system file names

      • OpenExamSuite v3.2.0.exe (PID: 7192)
    • There is functionality for taking screenshot (YARA)

      • OpenExamSuite v3.2.0.exe (PID: 7192)
    • Creates a software uninstall entry

      • OpenExamSuite v3.2.0.exe (PID: 7192)
    • Reads security settings of Internet Explorer

      • GameBar.exe (PID: 4844)
      • Simulator.exe (PID: 4244)
  • INFO

    • Reads the computer name

      • OpenExamSuite v3.2.0.exe (PID: 7192)
      • Simulator.exe (PID: 4244)
      • GameBar.exe (PID: 4844)
    • Create files in a temporary directory

      • OpenExamSuite v3.2.0.exe (PID: 7192)
    • Checks supported languages

      • OpenExamSuite v3.2.0.exe (PID: 7192)
      • GameBar.exe (PID: 4844)
      • Simulator.exe (PID: 4244)
    • Creates files in the program directory

      • OpenExamSuite v3.2.0.exe (PID: 7192)
    • Creates files or folders in the user directory

      • OpenExamSuite v3.2.0.exe (PID: 7192)
      • Simulator.exe (PID: 4244)
    • Manual execution by a user

      • firefox.exe (PID: 6516)
    • Application launched itself

      • firefox.exe (PID: 6516)
      • firefox.exe (PID: 7432)
    • Reads the machine GUID from the registry

      • Simulator.exe (PID: 4244)
    • Reads the software policy settings

      • slui.exe (PID: 4528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:24:41+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25600
InitializedDataSize: 162816
UninitializedDataSize: 1024
EntryPoint: 0x320c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
180
Monitored processes
39
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start openexamsuite v3.2.0.exe sppextcomobj.exe no specs slui.exe simulator.exe no specs gamebar.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs openexamsuite v3.2.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
968"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4236 -childID 2 -isForBrowser -prefsHandle 4228 -prefMapHandle 4224 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1424 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f8335e5f-cbda-40ed-9083-b8bc75eb4b6a} 7432 "\\.\pipe\gecko-crash-server-pipe.7432" 263530a8bd0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
1324"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5520 -childID 10 -isForBrowser -prefsHandle 4440 -prefMapHandle 6056 -prefsLen 31548 -prefMapSize 244583 -jsInitHandle 1424 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {76bc508e-b02d-4fd9-a276-acaa1a8a5a0b} 7432 "\\.\pipe\gecko-crash-server-pipe.7432" 26359d45150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2284"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5432 -childID 25 -isForBrowser -prefsHandle 4248 -prefMapHandle 6688 -prefsLen 31684 -prefMapSize 244583 -jsInitHandle 1424 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f3025e4f-1c69-4df8-9652-261825ea520f} 7432 "\\.\pipe\gecko-crash-server-pipe.7432" 26358711d90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140_1.dll
2432"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6628 -childID 17 -isForBrowser -prefsHandle 6672 -prefMapHandle 6676 -prefsLen 31548 -prefMapSize 244583 -jsInitHandle 1424 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {58fa0235-ad00-4ff9-ac09-829bed7f70ab} 7432 "\\.\pipe\gecko-crash-server-pipe.7432" 2635ab42310 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
3028"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4628 -childID 14 -isForBrowser -prefsHandle 6156 -prefMapHandle 5348 -prefsLen 31548 -prefMapSize 244583 -jsInitHandle 1424 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {41154356-5425-42a4-97d8-0725dd542189} 7432 "\\.\pipe\gecko-crash-server-pipe.7432" 26354398310 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
3992"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5756 -childID 23 -isForBrowser -prefsHandle 7160 -prefMapHandle 4540 -prefsLen 31548 -prefMapSize 244583 -jsInitHandle 1424 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {10f79382-1b8a-4ade-b8ea-eba34293cf88} 7432 "\\.\pipe\gecko-crash-server-pipe.7432" 26357f80a10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4244"C:\Program Files (x86)\Open Exam Suite\Simulator.exe"C:\Program Files (x86)\Open Exam Suite\Simulator.exeOpenExamSuite v3.2.0.exe
User:
admin
Company:
Invenio Technologies
Integrity Level:
HIGH
Description:
Simulator
Version:
3.2.0.0
Modules
Images
c:\program files (x86)\open exam suite\simulator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4376"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5760 -childID 18 -isForBrowser -prefsHandle 6448 -prefMapHandle 5640 -prefsLen 31548 -prefMapSize 244583 -jsInitHandle 1424 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {e7e607f9-8f87-482c-bd79-ed12819ec882} 7432 "\\.\pipe\gecko-crash-server-pipe.7432" 26354398310 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4380"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5296 -childID 5 -isForBrowser -prefsHandle 5372 -prefMapHandle 5368 -prefsLen 31251 -prefMapSize 244583 -jsInitHandle 1424 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ecbd708b-3e55-48d2-93c5-d22e12f1a511} 7432 "\\.\pipe\gecko-crash-server-pipe.7432" 26359d45150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
4528C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
42 445
Read events
42 389
Write events
55
Delete events
1

Modification events

(PID) Process:(7192) OpenExamSuite v3.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Open Exam Suite
Operation:writeName:DisplayName
Value:
Open Exam Suite 3.2.0
(PID) Process:(7192) OpenExamSuite v3.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Open Exam Suite
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\Open Exam Suite\uninst.exe
(PID) Process:(7192) OpenExamSuite v3.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Open Exam Suite
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\Open Exam Suite\Simulator.exe
(PID) Process:(7192) OpenExamSuite v3.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Open Exam Suite
Operation:writeName:DisplayVersion
Value:
3.2.0
(PID) Process:(7192) OpenExamSuite v3.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Open Exam Suite
Operation:writeName:URLInfoAbout
Value:
https://bolorundurowb.github.io/Open-Exam-Suite/
(PID) Process:(7192) OpenExamSuite v3.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Open Exam Suite
Operation:writeName:Publisher
Value:
bolorundurowb
(PID) Process:(4844) GameBar.exeKey:\REGISTRY\A\{7a0b87ce-d04e-8199-ba80-5a80305f2a1e}\LocalState
Operation:writeName:CurrentDisplayMonitor
Value:
670061006D0065000000D8CB53FAB69CDB01
(PID) Process:(4844) GameBar.exeKey:\REGISTRY\A\{7a0b87ce-d04e-8199-ba80-5a80305f2a1e}\LocalState
Operation:writeName:InstalledVersionMajor
Value:
0200C1034FFAB69CDB01
(PID) Process:(4844) GameBar.exeKey:\REGISTRY\A\{7a0b87ce-d04e-8199-ba80-5a80305f2a1e}\LocalState
Operation:writeName:InstalledVersionMinor
Value:
2200C1034FFAB69CDB01
(PID) Process:(4844) GameBar.exeKey:\REGISTRY\A\{7a0b87ce-d04e-8199-ba80-5a80305f2a1e}\LocalState
Operation:writeName:InstalledVersionBuild
Value:
616DC1034FFAB69CDB01
Executable files
12
Suspicious files
251
Text files
28
Unknown types
1

Dropped files

PID
Process
Filename
Type
7192OpenExamSuite v3.2.0.exeC:\Program Files (x86)\Open Exam Suite\Open Exam Suite.urlbinary
MD5:A9AAE75E34BEE3A77FFA9D0F2B1C50DB
SHA256:A6B36B99491447A01779234E2B9335405D0A293CE2D2825F9F71D2802C89AEDB
7192OpenExamSuite v3.2.0.exeC:\Users\admin\Desktop\Creator.lnkbinary
MD5:3BB1056B637B17027B7439444392DD29
SHA256:5AD6FC4E6AD4B3A403AF1A5823D0AAF0F3766A86104A572B1BD478BEC19088FE
7192OpenExamSuite v3.2.0.exeC:\Program Files (x86)\Open Exam Suite\LiteDB.dllexecutable
MD5:8E049A7520C4A13C00F5CDCE4728ACD0
SHA256:EE12622FE73E8B6A92780AF24FF58B9DC934F5582AA1F6E6E51CC01437AD7844
7192OpenExamSuite v3.2.0.exeC:\Program Files (x86)\Open Exam Suite\Logging.dllexecutable
MD5:79ED97F36BF319DF669E8544A02A7F66
SHA256:74EA3BCC89A19F7642C9A301FC34D0123129EE4E1F05D6F77CB4144F37F322E4
7192OpenExamSuite v3.2.0.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Exam Suite\Simulator.lnkbinary
MD5:DD832343A3CCC0A5E76202638B4DD4CF
SHA256:ACE77F7B134D6EE02610BBD4D24CF1A7EDCE5F56F46BBC9AA191A556F5E4661D
7192OpenExamSuite v3.2.0.exeC:\Program Files (x86)\Open Exam Suite\Shared.dllexecutable
MD5:D1592E6B271D7BA015DB951B9E459413
SHA256:4314065F624A05A1EA431DAADE7841E62B07599149B53DF1A84C06BA7DD9A355
7192OpenExamSuite v3.2.0.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Exam Suite\Creator.lnkbinary
MD5:2860240EA364F618A2565A445A71823E
SHA256:9FF2BC1FCAD9CB460C18DA9688175E89B059C401B2968592969A610EC93BD920
7192OpenExamSuite v3.2.0.exeC:\Program Files (x86)\Open Exam Suite\Creator.exeexecutable
MD5:C1458472FC2E943144FBDC37DFE609CA
SHA256:6FDCAC1BF95ECD89B268390D8F353AA6BDB2056111759FCBCD951B1CBCFB2A87
7432firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
7192OpenExamSuite v3.2.0.exeC:\Users\admin\Desktop\Simulator.lnkbinary
MD5:CF7A5ACB81B06440C3B248E62157E48A
SHA256:6B073ECBFDD5101B0E7D2A7A4B19397DCC8752215390684CF5549466A9058E41
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
94
TCP/UDP connections
195
DNS requests
222
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.16.164.51:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
8136
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8136
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7648
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7432
firefox.exe
POST
200
2.23.82.57:80
http://r10.o.lencr.org/
unknown
whitelisted
7432
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
7432
firefox.exe
POST
200
2.23.82.57:80
http://r11.o.lencr.org/
unknown
whitelisted
7432
firefox.exe
POST
200
142.250.181.227:80
http://o.pki.goog/s/wr3/cgo
unknown
whitelisted
7432
firefox.exe
POST
200
142.250.181.227:80
http://o.pki.goog/we2
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.51:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2104
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2112
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.31.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
7648
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.164.51
  • 2.16.164.106
  • 2.16.164.120
  • 2.16.164.72
  • 2.16.164.81
  • 2.16.164.9
  • 2.16.164.18
whitelisted
google.com
  • 142.250.184.206
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
client.wns.windows.com
  • 40.113.110.67
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.31.129
  • 20.190.159.73
  • 40.126.31.128
  • 20.190.159.71
  • 20.190.159.131
  • 40.126.31.3
  • 20.190.159.0
  • 40.126.31.130
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
No debug info