File name:

app.exe

Full analysis: https://app.any.run/tasks/a8a3703b-2ff2-4602-8f2d-68e84a870b2b
Verdict: Malicious activity
Threats:

Blank Grabber is an infostealer written in Python. It is designed to steal a wide array of data, such as browser login credentials, crypto wallets, Telegram sessions, and Discord tokens. It is an open-source malware, with its code available on GitHub and regularly receiving updates. Blank Grabber builder’s simple interface lets threat actors even with basic skills to deploy it and conduct attacks.

Analysis date: March 15, 2026, 22:44:30
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
blankgrabber
uac
python
anti-evasion
evasion
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 7 sections
MD5:

36CAB9BD36D19C56C2FC176F402EDF71

SHA1:

A2FA7A08E77DECEE25807EC56998FC4BBB3FCD94

SHA256:

D9EAC2F09D63B7A17DE345D93F5100806403B9020F71E17518E3186FF81F9E5A

SSDEEP:

98304:BgsEUsmHOIqbA3foFHmCX+/pYINCaYh3bg/Lk2/xX7PSPQvJVfPVNbequajmAary:mZmIOOq+anpSoI2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • BlankGrabber has been detected

      • app.exe (PID: 8108)
      • app.exe (PID: 2376)
    • Bypass User Account Control (Modify registry)

      • reg.exe (PID: 8168)
    • Bypass User Account Control (ComputerDefaults)

      • ComputerDefaults.exe (PID: 7272)
    • Adds path to the Windows Defender exclusion list

      • app.exe (PID: 1600)
      • cmd.exe (PID: 8876)
    • Antivirus name has been found in the command line (generic signature)

      • cmd.exe (PID: 8988)
    • Changes Controlled Folder Access settings

      • powershell.exe (PID: 8408)
    • Changes settings for real-time protection

      • powershell.exe (PID: 8408)
    • Changes settings for protection against network attacks (IPS)

      • powershell.exe (PID: 8408)
    • Changes Windows Defender settings

      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 8876)
    • Changes antivirus protection settings for downloading files from the Internet (IOAVProtection)

      • powershell.exe (PID: 8408)
    • Changes settings for checking scripts for malicious actions

      • powershell.exe (PID: 8408)
    • Changes settings for sending potential threat samples to Microsoft servers

      • powershell.exe (PID: 8408)
    • Changes settings for reporting to Microsoft Active Protection Service (MAPS)

      • powershell.exe (PID: 8408)
    • Resets Windows Defender malware definitions to the base version

      • MpCmdRun.exe (PID: 6728)
  • SUSPICIOUS

    • Process drops python dynamic module

      • app.exe (PID: 8108)
      • app.exe (PID: 2376)
    • The process drops C-runtime libraries

      • app.exe (PID: 8108)
      • app.exe (PID: 2376)
    • Executable content was dropped or overwritten

      • app.exe (PID: 8108)
      • app.exe (PID: 2376)
    • Starts a Microsoft application from unusual location

      • app.exe (PID: 3516)
      • app.exe (PID: 2376)
      • app.exe (PID: 1600)
    • Loads Python modules

      • app.exe (PID: 3516)
      • app.exe (PID: 1600)
    • Application launched itself

      • app.exe (PID: 8108)
      • app.exe (PID: 2376)
    • Starts CMD.EXE with AutoRun commands disabled

      • cmd.exe (PID: 6864)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 6864)
      • cmd.exe (PID: 4280)
      • cmd.exe (PID: 1872)
      • cmd.exe (PID: 8132)
      • cmd.exe (PID: 5536)
      • cmd.exe (PID: 8632)
      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 8876)
      • cmd.exe (PID: 7844)
      • cmd.exe (PID: 2424)
      • cmd.exe (PID: 7968)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 6864)
      • cmd.exe (PID: 4280)
      • cmd.exe (PID: 8632)
    • Delegate execute modification

      • reg.exe (PID: 8168)
    • Found strings related to reading or modifying Windows Defender settings

      • app.exe (PID: 3516)
      • app.exe (PID: 1600)
    • Uses WEVTUTIL.EXE to query events from a log or log file

      • cmd.exe (PID: 1872)
      • cmd.exe (PID: 5536)
    • Get information on the list of running processes

      • app.exe (PID: 1600)
      • cmd.exe (PID: 7968)
    • Disables Windows Defender IPS (POWERSHELL)

      • cmd.exe (PID: 8988)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 8876)
    • Uses WMIC.EXE to obtain Windows Installer data

      • cmd.exe (PID: 2424)
    • Disables Windows Defender real-time protection (POWERSHELL)

      • cmd.exe (PID: 8988)
    • Adds exclusion path to Windows Defender (POWERSHELL)

      • cmd.exe (PID: 8876)
    • Executes JavaScript directly as a command

      • cmd.exe (PID: 7844)
    • Accesses product unique identifier via WMI (SCRIPT)

      • WMIC.exe (PID: 2228)
    • Checks for external IP

      • svchost.exe (PID: 2292)
  • INFO

    • Checks supported languages

      • app.exe (PID: 8108)
      • app.exe (PID: 3516)
      • app.exe (PID: 2376)
      • app.exe (PID: 1600)
      • MpCmdRun.exe (PID: 6728)
    • The sample compiled with english language support

      • app.exe (PID: 8108)
      • app.exe (PID: 2376)
    • Create files in a temporary directory

      • app.exe (PID: 8108)
      • app.exe (PID: 3516)
      • app.exe (PID: 1600)
      • app.exe (PID: 2376)
      • MpCmdRun.exe (PID: 6728)
    • Reads the computer name

      • app.exe (PID: 8108)
      • app.exe (PID: 2376)
      • app.exe (PID: 1600)
      • MpCmdRun.exe (PID: 6728)
    • Reads the machine GUID from the registry

      • app.exe (PID: 3516)
      • app.exe (PID: 1600)
    • Reads security settings of Internet Explorer

      • ComputerDefaults.exe (PID: 7272)
      • WMIC.exe (PID: 2228)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 8376)
      • powershell.exe (PID: 8408)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 8376)
      • powershell.exe (PID: 8408)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 7828)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2026:02:15 16:42:46+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.44
CodeSize: 186880
InitializedDataSize: 117760
UninitializedDataSize: -
EntryPoint: 0xd4a0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 10.0.19041.5965
ProductVersionNumber: 10.0.19041.5965
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Windows Diagnosis and Recovery
FileVersion: 10.0.19041.5965 (WinBuild.160101.0800)
InternalName: RelPost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: RelPost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.5965
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
181
Monitored processes
36
Malicious processes
10
Suspicious processes
3

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
748tasklist /FO LISTC:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1600"C:\Users\admin\AppData\Local\Temp\app.exe" C:\Users\admin\AppData\Local\Temp\app.exe
app.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Diagnosis and Recovery
Exit code:
0
Version:
10.0.19041.5965 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\app.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1872C:\WINDOWS\system32\cmd.exe /c "wevtutil qe "Microsoft-Windows-Windows Defender/Operational" /f:text"C:\Windows\System32\cmd.exeapp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
2228wmic csproduct get uuidC:\Windows\System32\wbem\WMIC.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
2292C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2376"C:\Users\admin\AppData\Local\Temp\app.exe" C:\Users\admin\AppData\Local\Temp\app.exe
ComputerDefaults.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Diagnosis and Recovery
Exit code:
0
Version:
10.0.19041.5965 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\app.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2424C:\WINDOWS\system32\cmd.exe /c "wmic csproduct get uuid"C:\Windows\System32\cmd.exeapp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
2460C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2760"C:\WINDOWS\system32\ComputerDefaults.exe" --nouacbypassC:\Windows\System32\ComputerDefaults.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Set Program Access and Computer Defaults Control Panel
Exit code:
3221226540
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\computerdefaults.exe
c:\windows\system32\ntdll.dll
3236\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeapp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
15 846
Read events
15 834
Write events
8
Delete events
4

Modification events

(PID) Process:(7272) ComputerDefaults.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(7272) ComputerDefaults.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7272) ComputerDefaults.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7272) ComputerDefaults.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(8168) reg.exeKey:HKEY_CLASSES_ROOT\ms-settings\shell\open\command
Operation:writeName:DelegateExecute
Value:
(PID) Process:(8788) reg.exeKey:HKEY_CLASSES_ROOT\ms-settings\shell\open\command
Operation:delete keyName:(default)
Value:
(PID) Process:(8788) reg.exeKey:HKEY_CLASSES_ROOT\ms-settings\shell\open
Operation:delete keyName:(default)
Value:
(PID) Process:(8788) reg.exeKey:HKEY_CLASSES_ROOT\ms-settings\shell
Operation:delete keyName:(default)
Value:
(PID) Process:(8788) reg.exeKey:HKEY_CLASSES_ROOT\ms-settings
Operation:delete keyName:(default)
Value:
(PID) Process:(7828) mshta.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
36
Suspicious files
5
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
8108app.exeC:\Users\admin\AppData\Local\Temp\_MEI81082\_socket.pydexecutable
MD5:55FE72D1D8583B4A0751BC97CE3B1944
SHA256:73E04A819BB465A73F773F191F442659005F9796C611C010FEB5866D7F23493A
8108app.exeC:\Users\admin\AppData\Local\Temp\_MEI81082\_queue.pydexecutable
MD5:FB0CE59A33477B65891E0DF6E1E2BA92
SHA256:7689BD316439DFAEB8CC530965EF0D52A04DE359BC6DE49B72539BA0CBA8719C
8108app.exeC:\Users\admin\AppData\Local\Temp\_MEI81082\blank.aesbinary
MD5:108506A3D82C82DD961946441173F384
SHA256:4445B65C98E6181D62812FCA3854F4622508449D9E75B074D5EC71EFD626FF9B
8108app.exeC:\Users\admin\AppData\Local\Temp\_MEI81082\libcrypto-1_1.dllexecutable
MD5:DAA2EED9DCEAFAEF826557FF8A754204
SHA256:4DAB915333D42F071FE466DF5578FD98F38F9E0EFA6D9355E9B4445FFA1CA914
8108app.exeC:\Users\admin\AppData\Local\Temp\_MEI81082\_sqlite3.pydexecutable
MD5:FC2B1614E88479C194C06F1264F779D4
SHA256:7D59BDCD691B752CB3790E68B25BBB24A15BDBF9B9666364F37AEAA0E4421941
8108app.exeC:\Users\admin\AppData\Local\Temp\_MEI81082\_lzma.pydexecutable
MD5:4F5417C91858BBE06452765DADD78F81
SHA256:9684A6EC04D48D6738726BB0485D5DD9973E3F2722C7C0551A8D455A35D9B37B
8108app.exeC:\Users\admin\AppData\Local\Temp\_MEI81082\VCRUNTIME140.dllexecutable
MD5:F12681A472B9DD04A812E16096514974
SHA256:D66C3B47091CEB3F8D3CC165A43D285AE919211A0C0FCB74491EE574D8D464F8
8108app.exeC:\Users\admin\AppData\Local\Temp\_MEI81082\_decimal.pydexecutable
MD5:FC679A622CB3013AE33DDA27E1027016
SHA256:91573C5FFD30B170545958F1B6FB816D324FBB161D6FF60ED90F0DCCDF6EA8DB
8108app.exeC:\Users\admin\AppData\Local\Temp\_MEI81082\_ctypes.pydexecutable
MD5:23F57BED93249426FB321D9AE9D948BF
SHA256:42D85A21A0C9FD6ED8B59379B7D21FC6EE4FFF18570B3CD34AB7FB0F7377DE06
8108app.exeC:\Users\admin\AppData\Local\Temp\_MEI81082\_bz2.pydexecutable
MD5:A02BB62401DC2FD7D2BF7B92731B664B
SHA256:25643AF3668B145D5029E01376326246555CCAA0DBAA64DD70C8F49A94C37257
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
23
TCP/UDP connections
22
DNS requests
18
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7544
svchost.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
5632
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5632
SIHClient.exe
GET
200
74.178.240.51:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
5632
SIHClient.exe
GET
200
135.233.95.144:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
5632
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
1600
app.exe
GET
200
208.95.112.1:80
http://ip-api.com/line/?fields=hosting
US
text
5 b
unknown
7544
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
7544
svchost.exe
GET
200
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=1&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.74 Kb
whitelisted
7544
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
7544
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
5408
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
92.123.104.67:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
1600
app.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
whitelisted
7544
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7544
svchost.exe
2.16.164.49:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
7544
svchost.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
www.bing.com
  • 92.123.104.67
  • 92.123.104.52
  • 92.123.104.61
  • 92.123.104.6
  • 92.123.104.17
  • 92.123.104.34
  • 92.123.104.32
  • 92.123.104.31
  • 92.123.104.19
whitelisted
google.com
  • 142.251.141.78
whitelisted
blank-6ycsm.in
unknown
ip-api.com
  • 208.95.112.1
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.72
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.31.73
  • 40.126.31.1
  • 40.126.31.3
  • 20.190.159.23
  • 40.126.31.129
  • 20.190.159.128
  • 40.126.31.0
  • 40.126.31.71
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

PID
Process
Class
Message
2292
svchost.exe
Misc activity
INFO [ANY.RUN] External IP Check (ip-api .com)
2292
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
7544
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info