File name:

AndroidSideloader.exe

Full analysis: https://app.any.run/tasks/0dfce6f7-a6ae-4491-9cea-99b918d08bcd
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 16, 2026, 17:56:21
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
loader
arch-exec
rclone
tool
arch-doc
arch-html
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

C9FE4D27402DC7F0B5D51F2ED0B60F6E

SHA1:

103A73A10A76D8A7A6F1AB429A16E67056640267

SHA256:

D936EFC3858C5C9D12822D21E10E088EF2B2765FF41C9222C57F43F3541E3D58

SSDEEP:

49152:bz2CafO/p1g59nWQv8+OqVM5hwCnJxHocKVK90fSKz1WzKcDfP/b4Bl:byC+O/pQ9nWuWqVM5XflB2bz14ZP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • AndroidSideloader.exe (PID: 7548)
    • Drops 7-zip archiver for unpacking

      • AndroidSideloader.exe (PID: 7548)
    • Executable content was dropped or overwritten

      • AndroidSideloader.exe (PID: 7548)
      • 7z.exe (PID: 8068)
      • 7z.exe (PID: 2224)
    • Process drops legitimate windows executable

      • AndroidSideloader.exe (PID: 7548)
      • 7z.exe (PID: 2224)
    • RCLONE has been detected

      • rclone.exe (PID: 7172)
      • rclone.exe (PID: 7284)
      • rclone.exe (PID: 7328)
    • Application launched itself

      • adb.exe (PID: 7420)
      • adb.exe (PID: 7444)
  • INFO

    • Checks supported languages

      • AndroidSideloader.exe (PID: 7548)
      • 7z.exe (PID: 8068)
      • 7z.exe (PID: 6156)
      • 7z.exe (PID: 2224)
      • adb.exe (PID: 5104)
      • adb.exe (PID: 7420)
      • rclone.exe (PID: 7172)
      • rclone.exe (PID: 7284)
      • adb.exe (PID: 7528)
      • adb.exe (PID: 1420)
      • adb.exe (PID: 2216)
      • adb.exe (PID: 5408)
      • adb.exe (PID: 7868)
      • adb.exe (PID: 7936)
      • adb.exe (PID: 2144)
      • adb.exe (PID: 5784)
      • adb.exe (PID: 7596)
      • adb.exe (PID: 8028)
      • adb.exe (PID: 6176)
      • adb.exe (PID: 7444)
      • adb.exe (PID: 8116)
      • adb.exe (PID: 2568)
      • adb.exe (PID: 6408)
      • adb.exe (PID: 4744)
      • rclone.exe (PID: 7328)
      • identity_helper.exe (PID: 2612)
    • Reads the computer name

      • AndroidSideloader.exe (PID: 7548)
      • 7z.exe (PID: 8068)
      • 7z.exe (PID: 6156)
      • 7z.exe (PID: 2224)
      • rclone.exe (PID: 7172)
      • rclone.exe (PID: 7284)
      • adb.exe (PID: 5104)
      • rclone.exe (PID: 7328)
      • adb.exe (PID: 6408)
      • identity_helper.exe (PID: 2612)
    • Reads the machine GUID from the registry

      • AndroidSideloader.exe (PID: 7548)
      • rclone.exe (PID: 7284)
    • Disables trace logs

      • AndroidSideloader.exe (PID: 7548)
    • Drops script file

      • AndroidSideloader.exe (PID: 7548)
    • The sample compiled with english language support

      • AndroidSideloader.exe (PID: 7548)
      • 7z.exe (PID: 8068)
      • 7z.exe (PID: 2224)
    • Checks proxy server information

      • AndroidSideloader.exe (PID: 7548)
      • slui.exe (PID: 6556)
    • Create files in a temporary directory

      • rclone.exe (PID: 7284)
      • adb.exe (PID: 5104)
    • Manual execution by a user

      • rclone.exe (PID: 7328)
      • notepad.exe (PID: 7240)
      • notepad.exe (PID: 3656)
      • msedge.exe (PID: 2368)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 7240)
      • notepad.exe (PID: 3656)
    • Application launched itself

      • msedge.exe (PID: 2368)
    • Reads Environment values

      • identity_helper.exe (PID: 2612)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2053:05:23 13:01:49+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 1110016
InitializedDataSize: 34816
UninitializedDataSize: -
EntryPoint: 0x110f4e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Rookie Sideloader
CompanyName: Rookie.AndroidSideloader
FileDescription: AndroidSideloader
FileVersion: 2.0.0.0
InternalName: AndroidSideloader.exe
LegalCopyright: Copyright © 2020
LegalTrademarks: -
OriginalFileName: AndroidSideloader.exe
ProductName: AndroidSideloader
ProductVersion: 2.0.0.0
AssemblyVersion: 2.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
212
Monitored processes
71
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start androidsideloader.exe 7z.exe conhost.exe no specs 7z.exe no specs conhost.exe no specs 7z.exe conhost.exe no specs THREAT rclone.exe no specs conhost.exe no specs THREAT rclone.exe conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs adb.exe no specs adb.exe no specs conhost.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs adb.exe no specs conhost.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs THREAT rclone.exe no specs conhost.exe no specs notepad.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs notepad.exe no specs slui.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
408"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2332,i,11537102199652378856,6185651232767991290,262144 --variations-seed-version --mojo-platform-channel-handle=2324 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1204\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeadb.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1420"C:\Users\admin\Desktop\platform-tools\adb.exe" shell dfC:\Users\admin\Desktop\platform-tools\adb.exeAndroidSideloader.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\platform-tools\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1600"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=3216,i,11537102199652378856,6185651232767991290,262144 --variations-seed-version --mojo-platform-channel-handle=6604 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1752\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeadb.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1872\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeadb.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2144"C:\Users\admin\Desktop\platform-tools\adb.exe" shell getprop ro.product.modelC:\Users\admin\Desktop\platform-tools\adb.exeAndroidSideloader.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\platform-tools\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2216"C:\Users\admin\Desktop\platform-tools\adb.exe" shell getprop ro.product.modelC:\Users\admin\Desktop\platform-tools\adb.exeAndroidSideloader.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\platform-tools\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2224"7z.exe" x "C:\Users\admin\Desktop\runtimes.7z" -y -o"C:\Users\admin\Desktop" -bsp1C:\Users\admin\Desktop\7z.exe
AndroidSideloader.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Console
Exit code:
0
Version:
24.09
Modules
Images
c:\users\admin\desktop\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2224"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --disable-quic --onnx-enabled-for-ee --string-annotations --always-read-main-dll --field-trial-handle=5700,i,11537102199652378856,6185651232767991290,262144 --variations-seed-version --mojo-platform-channel-handle=5692 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
17 392
Read events
17 378
Write events
14
Delete events
0

Modification events

(PID) Process:(7548) AndroidSideloader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AndroidSideloader_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7548) AndroidSideloader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AndroidSideloader_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7548) AndroidSideloader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AndroidSideloader_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7548) AndroidSideloader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AndroidSideloader_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7548) AndroidSideloader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AndroidSideloader_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7548) AndroidSideloader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AndroidSideloader_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7548) AndroidSideloader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AndroidSideloader_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(7548) AndroidSideloader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AndroidSideloader_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7548) AndroidSideloader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AndroidSideloader_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7548) AndroidSideloader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AndroidSideloader_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
20
Suspicious files
22
Text files
153
Unknown types
1

Dropped files

PID
Process
Filename
Type
7548AndroidSideloader.exeC:\Users\admin\Desktop\dependencies.7z
MD5:
SHA256:
7548AndroidSideloader.exeC:\Users\admin\Desktop\AddDefenderExceptions.ps1text
MD5:D4C169C2F22D0138A973F81AC6BD5F3A
SHA256:D33272FAA34B9F435A3AE5844E2022D6A70232B42F957E31FA37F6501B12A128
7548AndroidSideloader.exeC:\Users\admin\Desktop\settings.jsontext
MD5:1E5A970F1068E021B9886DB1B3E2918B
SHA256:5B277263B721D373927AEB37BD1BD929B3105467C493435E668E7D3430EC6FD0
7548AndroidSideloader.exeC:\Users\admin\Desktop\Rookie Offline.cmdtext
MD5:513248E44025E42FD2B8F9280501A8BB
SHA256:7DD245A6267A6D9500EE6B13A29FBDD80CEF9A020162C0E24A228558C58FA092
7548AndroidSideloader.exeC:\Users\admin\Desktop\CleanupInstall.cmdtext
MD5:90B4AFB2EAA57F8C8C2DD43EB9F3339E
SHA256:B3AC3DC1F31FC857A53A5670740EB9666682F03B0552EB1E4AE4E48A51DDC259
7548AndroidSideloader.exeC:\Users\admin\Desktop\debuglog.txttext
MD5:68772848361150973C639BB1C681DE93
SHA256:83F56BD8DDE932C29B0AB0E4F7ABF3507B1A40B2972476E807CF0A124DCCD8B1
7548AndroidSideloader.exeC:\Users\admin\Desktop\7z.exeexecutable
MD5:B6D5860F368B28CAA9DD14A51666A5CD
SHA256:E2CA3EC168AE9C0B4115CD4FE220145EA9B2DC4B6FC79D765E91F415B34D00DE
7548AndroidSideloader.exeC:\Users\admin\Desktop\7z.dllexecutable
MD5:C4AABD70DC28C9516809B775A30FDD3F
SHA256:882063948D675EE41B5AE68DB3E84879350EC81CF88D15B9BABF2FA08E332863
80687z.exeC:\Users\admin\Desktop\platform-tools\hprof-conv.exeexecutable
MD5:1952192783C64352A6C93F2562FAAA56
SHA256:35D9734B4F8A0F82698578F3529E946C6FE21F70AE245ABA61AADE6B52CC6E14
80687z.exeC:\Users\admin\Desktop\platform-tools\AdbWinUsbApi.dllexecutable
MD5:E6E1716F53624AFF7DBCE5891334669A
SHA256:51A61758A6F1F13DD36530199C0D65E227CD9D43765372B2942944CC3296CA2C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
161
TCP/UDP connections
106
DNS requests
72
Threats
40

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7548
AndroidSideloader.exe
GET
302
140.82.121.4:443
https://github.com/VRPirates/rookie/raw/master/Sideloader%20Launcher.exe
unknown
unknown
7548
AndroidSideloader.exe
GET
302
140.82.121.4:443
https://github.com/VRPirates/rookie/raw/master/Rookie%20Offline.cmd
unknown
unknown
7548
AndroidSideloader.exe
GET
302
140.82.121.4:443
https://github.com/VRPirates/rookie/raw/master/CleanupInstall.cmd
unknown
unknown
7548
AndroidSideloader.exe
GET
302
140.82.121.4:443
https://github.com/VRPirates/rookie/raw/master/AddDefenderExceptions.ps1
unknown
unknown
7548
AndroidSideloader.exe
GET
302
140.82.121.4:443
https://github.com/VRPirates/rookie/raw/master/dependencies.7z
unknown
unknown
6768
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4636
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5788
RUXIMICS.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4636
svchost.exe
GET
200
23.38.74.64:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6768
MoUsoCoreWorker.exe
GET
200
23.38.74.64:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
4636
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5788
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
4636
svchost.exe
23.216.77.28:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
6768
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
5788
RUXIMICS.exe
23.216.77.28:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
4636
svchost.exe
23.38.74.64:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
6768
MoUsoCoreWorker.exe
23.38.74.64:80
www.microsoft.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.38.74.64
whitelisted
raw.githubusercontent.com
  • 185.199.110.133
  • 185.199.111.133
  • 185.199.108.133
  • 185.199.109.133
whitelisted
downloads.rclone.org
  • 95.217.6.16
unknown
vrpirates.wiki
  • 185.247.224.87
unknown
github.com
  • 140.82.121.4
whitelisted
there-is-a.vrpmonkey.help
  • 104.21.78.210
  • 172.67.137.133
unknown
self.events.data.microsoft.com
  • 13.89.179.13
whitelisted

Threats

PID
Process
Class
Message
2292
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
Misc activity
ET HUNTING EXE Downloaded from Github
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
Misc activity
ET HUNTING EXE Downloaded from Github
Potentially Bad Traffic
ET INFO PS1 Powershell File Request
Potentially Bad Traffic
ET INFO PS1 Powershell File Request
Potentially Bad Traffic
ET INFO PS1 Powershell File Request
Potentially Bad Traffic
ET INFO PS1 Powershell File Request
Process
Message
AndroidSideloader.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.