File name:

Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI.rar

Full analysis: https://app.any.run/tasks/e5c4fa54-34fd-486c-ae34-323be4754853
Verdict: Malicious activity
Analysis date: February 27, 2026, 13:08:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
arch-html
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

6BD4B20A0D64264A257CD53630796BA5

SHA1:

B976672BD12BC10A4E1CE0E2BCCC59ADD2996711

SHA256:

D786193318B03FF987E1CB70979C7DB5AF5993DD96CFCFE637D2097A5AE66808

SSDEEP:

98304:6NJzSCGkpnNxPbQjFyGMMsqavwdzVNwJ9LsTJkSVgJ8cnlKodWCEvpw0G1xZSbsB:0foXUKGMpW+cumYzfTPSKO0osKV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • steamclient_loader_x64.exe (PID: 7812)
      • steamclient_loader_x64.exe (PID: 4688)
      • steamclient_loader_x64.exe (PID: 1136)
      • steamclient_loader_x64.exe (PID: 9004)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 412)
  • INFO

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 412)
      • notepad.exe (PID: 2360)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 412)
    • Manual execution by a user

      • watchdog.exe (PID: 5888)
      • notepad.exe (PID: 2360)
      • steamclient_loader_x64.exe (PID: 7812)
      • steamclient_loader_x64.exe (PID: 4688)
      • watchdog.exe (PID: 8428)
      • steamclient_loader_x64.exe (PID: 9004)
      • steamclient_loader_x64.exe (PID: 1136)
      • EfiDSEFix.exe (PID: 8552)
      • WinRAR.exe (PID: 4152)
      • EfiDSEFix.exe (PID: 8748)
    • Reads the computer name

      • steamclient_loader_x64.exe (PID: 1136)
      • steamclient_loader_x64.exe (PID: 4688)
    • Checks supported languages

      • watchdog.exe (PID: 8428)
      • watchdog.exe (PID: 5888)
      • steamclient_loader_x64.exe (PID: 1136)
      • steamclient_loader_x64.exe (PID: 4688)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 412)
    • Checks proxy server information

      • slui.exe (PID: 8472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
164
Monitored processes
14
Malicious processes
0
Suspicious processes
4

Behavior graph

Click at the process to see the details
start winrar.exe steamclient_loader_x64.exe no specs steamclient_loader_x64.exe watchdog.exe no specs watchdog.exe no specs slui.exe notepad.exe no specs steamclient_loader_x64.exe no specs steamclient_loader_x64.exe efidsefix.exe no specs conhost.exe no specs winrar.exe no specs efidsefix.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
412"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1136"C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\steamclient_loader_x64.exe" C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\steamclient_loader_x64.exe
explorer.exe
User:
admin
Company:
GSE
Integrity Level:
HIGH
Description:
GSE
Exit code:
1
Version:
08.56.38.63
Modules
Images
c:\users\admin\desktop\resident.evil.requiem.hypervisor-kirigiri\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2360"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\READNFO-MKDEV TEAM.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4152"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\EfiGuard\EfiGuard.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4688"C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\steamclient_loader_x64.exe" C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\steamclient_loader_x64.exe
explorer.exe
User:
admin
Company:
GSE
Integrity Level:
HIGH
Description:
GSE
Exit code:
1
Version:
08.56.38.63
Modules
Images
c:\users\admin\desktop\resident.evil.requiem.hypervisor-kirigiri\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5888"C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\watchdog.exe" C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\watchdog.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\resident.evil.requiem.hypervisor-kirigiri\watchdog.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7288\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeEfiDSEFix.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7812"C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\steamclient_loader_x64.exe" C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\steamclient_loader_x64.exeexplorer.exe
User:
admin
Company:
GSE
Integrity Level:
MEDIUM
Description:
GSE
Exit code:
3221226540
Version:
08.56.38.63
Modules
Images
c:\users\admin\desktop\resident.evil.requiem.hypervisor-kirigiri\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
8428"C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\watchdog.exe" C:\Users\admin\Desktop\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\watchdog.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\resident.evil.requiem.hypervisor-kirigiri\watchdog.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
8472C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
6 929
Read events
6 913
Write events
16
Delete events
0

Modification events

(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI.rar
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(4152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
Executable files
19
Suspicious files
1
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.36098\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\coldclient\steam_settings\steam_appid.txttext
MD5:DBE81A5523F97F0FEB305A325B505C5F
SHA256:C0D7C219DD57927835839C3A3BDDB73E2E81C17687D2D7697813DCC7C17F38FD
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.36098\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\coldclient\steam_settings\configs.user.initext
MD5:9026EA52B22C80BF7C6E5FB4DDA04324
SHA256:6910FA848124F4858C8A3C97F0348556BE9F46360845A39046ED337288DCDEA3
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.36098\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\coldclient\steam_settings\configs.app.initext
MD5:7F43980C384FA5CF5FA0D1A421031135
SHA256:51DE7A34D85F958880F1D6787143E6B157D70FC81842D726C026E962D302BF43
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.36098\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\coldclient\steamclient.dllexecutable
MD5:FCE3578D6AB6B1EBDE776765E7249956
SHA256:E29AEDAC4769E51862E96116063419BAC6B27A3B687E773813248460D5B66D1C
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.36098\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\coldclient\steamclient64.dllexecutable
MD5:8C4A558F0A3DDC511C4DA97DFB304392
SHA256:CA54CAD7913279985734945907973F5B37C957D69FDAAF46A058470DE12AA55B
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.36098\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\coldclient\steam_settings\configs.main.initext
MD5:47A31FC4B75A0642C7CC5675FE8FB4F1
SHA256:5DD219DF4B0BB37C07ECD90CCF5215ED182E229D5D7D24B6BA31429CE46C91D4
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.36098\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\amd_ags_x64.dllexecutable
MD5:F2460940C72FEE2C051EA594FD495712
SHA256:3FF29DCBB7267AC98455C7661F9A07F07672F4232723DBC7E6AF62811962D746
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.36098\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\coldclient\GameOverlayRenderer64.dllexecutable
MD5:BDB340F609A136B0D81E486D6E8B7BE2
SHA256:ED41C49B18B9F29427B1D4330D3F1A743A460EA722FD33CF5F389301A19E3925
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.36098\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\coldclient\steam_settings\steam_interfaces.txttext
MD5:B160E3F00EEFC9AB4DDEEDAED51266E0
SHA256:F851B4BD9AF4CA83F9374A9CEC31079327628876D854606E9EF9CFE78CFDBB7B
412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa412.36098\Resident.Evil.Requiem.HYPERVISOR-KIRIGIRI\EfiGuard\EfiGuard.rarcompressed
MD5:D4A74EE1BC45BE228F65075823F2ECAA
SHA256:4F7E9565B89FF565E2B97B8A867E04BC8B992CC3C3A281F9FCD2784EA283E691
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
31
DNS requests
25
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
8628
svchost.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
468
SIHClient.exe
GET
304
20.165.94.63:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
468
SIHClient.exe
GET
200
20.165.94.54:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
468
SIHClient.exe
GET
200
20.165.94.63:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
468
SIHClient.exe
GET
304
20.165.94.63:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
US
binary
314 b
whitelisted
356
svchost.exe
POST
200
40.126.28.22:443
https://login.live.com/RST2.srf
US
binary
11.1 Kb
whitelisted
356
svchost.exe
POST
200
40.126.28.22:443
https://login.live.com/RST2.srf
US
binary
10.3 Kb
whitelisted
8628
svchost.exe
GET
200
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.67 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
8628
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8068
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
23.3.89.90:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
356
svchost.exe
40.126.28.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
self.events.data.microsoft.com
  • 40.79.150.120
  • 20.189.173.26
whitelisted
google.com
  • 142.251.208.174
whitelisted
www.bing.com
  • 23.3.89.90
  • 95.100.158.114
  • 23.3.89.113
  • 23.11.206.96
  • 23.11.206.99
  • 23.11.206.98
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.28.22
  • 40.126.28.21
  • 20.190.135.6
  • 40.126.28.19
  • 20.190.135.4
  • 40.126.28.11
  • 20.190.135.2
  • 20.190.135.19
whitelisted
crl.microsoft.com
  • 23.216.77.30
  • 23.216.77.25
  • 23.216.77.36
  • 23.216.77.42
  • 23.216.77.28
  • 23.216.77.19
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 23.52.181.212
  • 88.221.169.152
whitelisted

Threats

PID
Process
Class
Message
8628
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info