File name:

CryptoLocker_10Sep2013.zip

Full analysis: https://app.any.run/tasks/85a0b130-024b-4e91-9a8b-2c7cbf228b9f
Verdict: Malicious activity
Analysis date: May 10, 2025, 18:38:19
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

22078FF56E3FCD674EC4B9322A7DEE5B

SHA1:

3A5D07577B40E85047DCFB0BD03A6FC23E7CC671

SHA256:

DDB9B850FA0EEE2F62463728B07BFFC11EAA9B241D215029EADDF1DE4EC54936

SSDEEP:

6144:WUCoUrZ5JGadcmBrwTbp7zgJxhlgL4U569Lmg7KCrrJRj+AP8:WUgrfJGadfByZzgJxhl1U569Lf7KCGA0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 8000)
  • SUSPICIOUS

    • Starts itself from another location

      • {71257279-042b-371d-a1d3-fbf8d2fadffa}.exe (PID: 7976)
    • Executable content was dropped or overwritten

      • {71257279-042b-371d-a1d3-fbf8d2fadffa}.exe (PID: 7976)
    • Application launched itself

      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 8000)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 6348)
    • There is functionality for taking screenshot (YARA)

      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 8000)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 8052)
    • Reads security settings of Internet Explorer

      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 8000)
    • The process executes via Task Scheduler

      • PLUGScheduler.exe (PID: 2968)
  • INFO

    • Manual execution by a user

      • {71257279-042b-371d-a1d3-fbf8d2fadffa}.exe (PID: 7976)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 7256)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 7284)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 5680)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 536)
      • Taskmgr.exe (PID: 5988)
      • Taskmgr.exe (PID: 6876)
      • firefox.exe (PID: 6208)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 6348)
    • Reads the computer name

      • {71257279-042b-371d-a1d3-fbf8d2fadffa}.exe (PID: 7976)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 8000)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 8052)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 7256)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 7284)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 5680)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 536)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7320)
    • Creates files or folders in the user directory

      • {71257279-042b-371d-a1d3-fbf8d2fadffa}.exe (PID: 7976)
    • Checks supported languages

      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 8000)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa}.exe (PID: 7976)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 8052)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 7256)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 7284)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 5680)
      • {71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe (PID: 536)
    • Reads the machine GUID from the registry

      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 8000)
    • Reads the software policy settings

      • slui.exe (PID: 7504)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 5988)
    • Application launched itself

      • firefox.exe (PID: 6280)
      • firefox.exe (PID: 6208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2013:11:26 14:11:00
ZipCRC: 0x412c0ff3
ZipCompressedSize: 289172
ZipUncompressedSize: 346112
ZipFileName: {71257279-042b-371d-a1d3-fbf8d2fadffa}.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
304
Monitored processes
33
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe {71257279-042b-371d-a1d3-fbf8d2fadffa}.exe {34184a33-0407-212e-3300-09040709e2c2}.exe {34184a33-0407-212e-3300-09040709e2c2}.exe no specs {71257279-042b-371d-a1d3-fbf8d2fadffa} - copy.exe no specs {71257279-042b-371d-a1d3-fbf8d2fadffa} - copy.exe no specs {71257279-042b-371d-a1d3-fbf8d2fadffa} - copy.exe no specs {71257279-042b-371d-a1d3-fbf8d2fadffa} - copy.exe taskmgr.exe no specs taskmgr.exe slui.exe no specs plugscheduler.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs {34184a33-0407-212e-3300-09040709e2c2}.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs {34184a33-0407-212e-3300-09040709e2c2}.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536"C:\Users\admin\Desktop\{71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe" C:\Users\admin\Desktop\{71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
522
Modules
Images
c:\users\admin\desktop\{71257279-042b-371d-a1d3-fbf8d2fadffa} - copy.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1180C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
1073807364
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2596"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7552 -parentBuildID 20240213221259 -prefsHandle 7544 -prefMapHandle 7540 -prefsLen 38545 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {62e9051f-240f-46ca-85df-6723f0008d62} 6280 "\\.\pipe\gecko-crash-server-pipe.6280" 1e6d9077510 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2716"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4796 -childID 10 -isForBrowser -prefsHandle 7768 -prefMapHandle 7772 -prefsLen 31597 -prefMapSize 244583 -jsInitHandle 1540 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {aa3adca9-25b7-4e22-8186-a0ecabea3100} 6280 "\\.\pipe\gecko-crash-server-pipe.6280" 1e6d3c414d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2968"C:\Program Files\RUXIM\PLUGscheduler.exe"C:\Program Files\RUXIM\PLUGScheduler.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Update LifeCycle Component Scheduler
Exit code:
0
Version:
10.0.19041.3623 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\xmllite.dll
3936"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=8068 -parentBuildID 20240213221259 -sandboxingKind 1 -prefsHandle 7856 -prefMapHandle 7944 -prefsLen 38545 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7deb9b84-eee1-400c-aab7-9a84ee7ca8f2} 6280 "\\.\pipe\gecko-crash-server-pipe.6280" 1e6d155c710 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
5504"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5364 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5408 -prefMapHandle 5096 -prefsLen 38181 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {aa761e9f-8bf1-4704-a7f0-e95ad30fb3bb} 6280 "\\.\pipe\gecko-crash-server-pipe.6280" 1e6d02b3710 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
5680"C:\Users\admin\Desktop\{71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exe" C:\Users\admin\Desktop\{71257279-042b-371d-a1d3-fbf8d2fadffa} - Copy.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
522
Modules
Images
c:\users\admin\desktop\{71257279-042b-371d-a1d3-fbf8d2fadffa} - copy.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\user32.dll
5988"C:\WINDOWS\system32\taskmgr.exe" /0C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6208"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
Total events
30 591
Read events
30 559
Write events
31
Delete events
1

Modification events

(PID) Process:(7320) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7320) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7320) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7320) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CryptoLocker_10Sep2013.zip
(PID) Process:(7320) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7320) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7320) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7320) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7320) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(7320) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
Executable files
2
Suspicious files
268
Text files
36
Unknown types
3

Dropped files

PID
Process
Filename
Type
7320WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb7320.11902\{71257279-042b-371d-a1d3-fbf8d2fadffa}.exeexecutable
MD5:04FB36199787F2E3E2135611A38321EB
SHA256:D765E722E295969C0A5C2D90F549DB8B89AB617900BF4698DB41C7CDAD993BB9
5988Taskmgr.exeC:\Users\admin\AppData\Local\D3DSCache\3534848bb9f4cb71\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.locktext
MD5:F49655F856ACB8884CC0ACE29216F511
SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA
2968PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.046.etlbinary
MD5:A7A21FBC9D00F33F186B34A50E170C13
SHA256:64CAC91E46D4FC832958232A658431CBF9D8D9F265653ACA2BEB32428D4688EC
2968PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.041.etlbinary
MD5:09359EE89B0634478ADFF73CDA7BFB12
SHA256:4D800AC7C55960B107C9D3E40F63130407835E69DF4F5C558C500FC0BD20D8ED
2968PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.037.etlbinary
MD5:B787593A02A4E0A601164A65952D0CB9
SHA256:3594AD496D8E1771BCC3E8B6F68B4C2B4190A9A331FB43F068A7DF4E1894E2CF
2968PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.045.etlbinary
MD5:89BD161BF7B46C9078937CF832786737
SHA256:2B83DF5532E9F54ED301C8F82E2CDD489799C8D5222A2D44C97DCB151A96FAA9
2968PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.048.etlbinary
MD5:A23907B6FDD47DCABFDFD7CF2FCD7671
SHA256:0C9C33FE9E984A2E5A70EBA51F36B9929A86199E424AF2F8080E1267B87DC970
2968PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.042.etlbinary
MD5:C1F87CF12DD702D2185E703BA004D216
SHA256:9D993487866C9538DC19F281A6346E1796E7478C7C164D61437AF6E698C66125
2968PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.034.etlbinary
MD5:DCB94F822B793FF178C7332174A89DFB
SHA256:4AB418FA76DFA333D37F7401B40B0B0F0E806876C79AB2F36CD3FD7CCAD8665B
2968PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.033.etlbinary
MD5:AB9303129E2242D02DC2069E5A4F3896
SHA256:9031A5BD681D52A903A2BCA625F6D9D8B1456B26D2335CA8170BB39A2FE8F2A0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
71
TCP/UDP connections
222
DNS requests
372
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2284
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2284
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5264
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6280
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
6280
firefox.exe
POST
200
2.16.238.11:80
http://r11.o.lencr.org/
unknown
whitelisted
6280
firefox.exe
POST
200
2.16.238.11:80
http://r11.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6544
svchost.exe
20.190.160.66:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
whitelisted
google.com
  • 172.217.16.206
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
login.live.com
  • 20.190.160.66
  • 20.190.160.20
  • 40.126.32.140
  • 40.126.32.72
  • 20.190.160.67
  • 40.126.32.74
  • 40.126.32.136
  • 20.190.160.64
  • 20.190.160.3
  • 20.190.160.128
  • 20.190.160.130
  • 20.190.160.17
  • 40.126.32.134
  • 20.190.160.2
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
ojkyiqumgktqduy.info
unknown

Threats

PID
Process
Class
Message
6280
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
6280
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
6280
firefox.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6280
firefox.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6280
firefox.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6280
firefox.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6280
firefox.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info