File name:

ScreenConnect.ClientSetup.msi

Full analysis: https://app.any.run/tasks/bc09021f-20ae-485d-9efb-297fe1dc80d6
Verdict: Malicious activity
Analysis date: March 26, 2026, 13:23:06
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
connectwise
rmm-tool
screenconnect
remote
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Default, Author: ScreenConnect Software, Keywords: Default, Comments: Default, Template: Intel;1033, Revision Number: {1C54124B-3EB4-F294-12A8-0DE0A5AA1F16}, Create Time/Date: Wed Mar 11 16:28:48 2026, Last Saved Time/Date: Wed Mar 11 16:28:48 2026, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.0.1701), Security: 2
MD5:

EC55BBDF462C5D95A28304DDB98E6205

SHA1:

92B3A96B8B82F8F12CA09B368778FCDE89806B0F

SHA256:

DFA98A10C4E8D7F15B64C84D4F3EECF11198BE6B1C9A6972F39FB1F4101B81AF

SSDEEP:

3:uKfKYBaluBYyP:Ff/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • SCREENCONNECT has been detected

      • rundll32.exe (PID: 3200)
      • rundll32.exe (PID: 7684)
      • msiexec.exe (PID: 2840)
      • rundll32.exe (PID: 6084)
    • SCREENCONNECT has been detected (SURICATA)

      • ScreenConnect.ClientService.exe (PID: 6228)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 7848)
      • ScreenConnect.ClientService.exe (PID: 6228)
    • Executable content was dropped or overwritten

      • rundll32.exe (PID: 3200)
      • rundll32.exe (PID: 6084)
      • rundll32.exe (PID: 7684)
    • Uses RUNDLL32.EXE to run a file without a DLL extension

      • rundll32.exe (PID: 6084)
      • rundll32.exe (PID: 7684)
    • Creates or modifies Windows services

      • ScreenConnect.ClientService.exe (PID: 6228)
    • Screenconnect has been detected

      • ScreenConnect.ClientService.exe (PID: 6228)
      • ScreenConnect.ClientService.exe (PID: 6228)
    • SCREENCONNECT mutex has been found

      • ScreenConnect.ClientService.exe (PID: 6228)
    • Potential Corporate Privacy Violation

      • ScreenConnect.ClientService.exe (PID: 6228)
  • INFO

    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 6816)
      • ScreenConnect.ClientService.exe (PID: 6228)
      • ScreenConnect.WindowsClient.exe (PID: 4112)
      • ScreenConnect.WindowsClient.exe (PID: 2940)
    • Checks supported languages

      • msiexec.exe (PID: 2840)
      • msiexec.exe (PID: 3380)
      • msiexec.exe (PID: 6768)
      • msiexec.exe (PID: 8152)
      • ScreenConnect.ClientService.exe (PID: 6228)
      • ScreenConnect.WindowsClient.exe (PID: 4112)
      • ScreenConnect.WindowsClient.exe (PID: 2940)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6816)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6816)
      • msiexec.exe (PID: 2840)
    • Create files in a temporary directory

      • rundll32.exe (PID: 3200)
      • rundll32.exe (PID: 7684)
      • rundll32.exe (PID: 6084)
    • Disables trace logs

      • rundll32.exe (PID: 6084)
    • CONNECTWISE has been detected

      • msiexec.exe (PID: 6816)
      • ScreenConnect.ClientService.exe (PID: 6228)
      • ScreenConnect.WindowsClient.exe (PID: 4112)
      • ScreenConnect.WindowsClient.exe (PID: 2940)
    • Manages system restore points

      • SrTasks.exe (PID: 8172)
    • Reads the computer name

      • msiexec.exe (PID: 6768)
      • msiexec.exe (PID: 8152)
      • ScreenConnect.ClientService.exe (PID: 6228)
      • ScreenConnect.WindowsClient.exe (PID: 4112)
      • ScreenConnect.WindowsClient.exe (PID: 2940)
      • msiexec.exe (PID: 3380)
      • msiexec.exe (PID: 2840)
    • Reads the machine GUID from the registry

      • ScreenConnect.ClientService.exe (PID: 6228)
      • ScreenConnect.WindowsClient.exe (PID: 2940)
      • ScreenConnect.WindowsClient.exe (PID: 4112)
    • SCREENCONNECT has been detected

      • ScreenConnect.ClientService.exe (PID: 6228)
    • Reads CPU info

      • ScreenConnect.WindowsClient.exe (PID: 2940)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Default
Author: ScreenConnect Software
Keywords: Default
Comments: Default
Template: Intel;1033
RevisionNumber: {1C54124B-3EB4-F294-12A8-0DE0A5AA1F16}
CreateDate: 2026:03:11 16:28:48
ModifyDate: 2026:03:11 16:28:48
Pages: 200
Words: 2
Software: Windows Installer XML Toolset (3.11.0.1701)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
14
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe #SCREENCONNECT msiexec.exe msiexec.exe no specs #SCREENCONNECT rundll32.exe #SCREENCONNECT rundll32.exe #SCREENCONNECT rundll32.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs #SCREENCONNECT screenconnect.clientservice.exe screenconnect.windowsclient.exe no specs screenconnect.windowsclient.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2728\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2840C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2940"C:\Program Files (x86)\ScreenConnect Client (427ce716b0899a30)\ScreenConnect.WindowsClient.exe" "RunRole" "95550d85-bf1c-49eb-83cf-8854aff5de6c" "System"C:\Program Files (x86)\ScreenConnect Client (427ce716b0899a30)\ScreenConnect.WindowsClient.exeScreenConnect.ClientService.exe
User:
SYSTEM
Company:
ScreenConnect Software
Integrity Level:
SYSTEM
Description:
ScreenConnect Client
Exit code:
0
Version:
26.1.18.9566
Modules
Images
c:\program files (x86)\screenconnect client (427ce716b0899a30)\screenconnect.windowsclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3200rundll32.exe "C:\Users\admin\AppData\Local\Temp\MSI21E.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_918156 1 ScreenConnect.InstallerActions!ScreenConnect.ClientInstallerActions.FixupServiceArgumentsC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3380C:\Windows\syswow64\MsiExec.exe -Embedding 0B743D9073CA37600995CB6AC22C1344 CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4112"C:\Program Files (x86)\ScreenConnect Client (427ce716b0899a30)\ScreenConnect.WindowsClient.exe" "RunRole" "7d4dd002-56a7-43e1-9b1c-f3300230ef8b" "User"C:\Program Files (x86)\ScreenConnect Client (427ce716b0899a30)\ScreenConnect.WindowsClient.exeScreenConnect.ClientService.exe
User:
admin
Company:
ScreenConnect Software
Integrity Level:
MEDIUM
Description:
ScreenConnect Client
Version:
26.1.18.9566
Modules
Images
c:\program files (x86)\screenconnect client (427ce716b0899a30)\screenconnect.windowsclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6084rundll32.exe "C:\Users\admin\AppData\Local\Temp\MSI4A0.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_918718 10 ScreenConnect.InstallerActions!ScreenConnect.ClientInstallerActions.CheckMsiMotwC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6228"C:\Program Files (x86)\ScreenConnect Client (427ce716b0899a30)\ScreenConnect.ClientService.exe" "?e=Access&y=Guest&h=instance-xea8z2-relay.screenconnect.com&p=443&s=f4d4779a-5881-4fff-bd54-46d5491f269f&k=BgIAAACkAABSU0ExAAgAAAEAAQBVt716lxG244ane8kqnu6B0lFQcDkssydrOjgniDBQFjn4GkwoMTgB%2bftup4ZEO9Gb15AsnOJygCOZMc2Iw5EcyU0EJFGadT0AFbB50FqSfTGRrRzpPW%2f%2bmQ76J0dXY3S5cKSQBy0ICzB4q9sbZzJ2yVqCwrpjphxw4lthVacrmx6eYmTaqmUiQgR9Qi5r%2bNI4F44kd7dfTtCdpCzNfTF4Gx9dRiN%2fHhkwXpRMv45zaFM15mRbRrcy%2bKwTEDE%2bsTsrh%2fA7071mGijxiu05HKA0sBjtBPE6Y7t4bAgllvr4P5hZKsWk%2fSzABT%2bWzTxaooLXP5CbU%2b6xWF8YNQJeMGbI"C:\Program Files (x86)\ScreenConnect Client (427ce716b0899a30)\ScreenConnect.ClientService.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Version:
26.1.18.9566
Modules
Images
c:\program files (x86)\screenconnect client (427ce716b0899a30)\screenconnect.clientservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
6768C:\Windows\syswow64\MsiExec.exe -Embedding 8DFDF92D45BC613101765D48B8594F26C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6816"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\ScreenConnect.ClientSetup.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
14 387
Read events
14 214
Write events
164
Delete events
9

Modification events

(PID) Process:(6084) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6084) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6084) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6084) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6084) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6084) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6084) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6084) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\rundll32_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6084) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\rundll32_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6084) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\rundll32_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
38
Suspicious files
24
Text files
10
Unknown types
1

Dropped files

PID
Process
Filename
Type
6816msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:4073ECDFC35AB708B9E7A21512EAB6A9
SHA256:42BADF727C04C14124A54E5884E434305CD879864FF6038DD022D79E8551BC38
6816msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:BB4F9F8625E93C73A2818ED44B172029
SHA256:2FEB3DE86F9EC1412F3E894DA4C31BE456434F88BA6AD8E6EF0E3B889E179FFD
6816msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_59E89BCE9615F2B61F2F2C691688F111binary
MD5:CF89C60BE483490284C325E0846D48F7
SHA256:AAF640EF4FCF5B17DCF35AE00AA27180CE4FE4F428C0EEFB4E8DE309C895FEF6
6816msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI21E.tmpexecutable
MD5:3DA27D0C256A14BB017F21F3A486D136
SHA256:AC1B1AFB6C8E73E6A476DE1C2EF07E8D31888468BA705B9AC548A0E860017363
6816msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_59E89BCE9615F2B61F2F2C691688F111binary
MD5:EE45620DFFE4892C11EEB8BF852A471A
SHA256:615E58A78A99F51B88521AB9992AEFDFB886A6FA4DDDDE108004A2BFCFB13563
3200rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI21E.tmp-\Microsoft.Deployment.WindowsInstaller.Package.dllexecutable
MD5:A921A2B83B98F02D003D9139FA6BA3D8
SHA256:548C551F6EBC5D829158A1E9AD1948D301D7C921906C3D8D6B6D69925FC624A1
3200rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI21E.tmp-\Microsoft.Deployment.WindowsInstaller.dllexecutable
MD5:5EF88919012E4A3D8A1E2955DC8C8D81
SHA256:3E54286E348EBD3D70EAED8174CCA500455C3E098CDD1FCCB167BC43D93DB29D
3200rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI21E.tmp-\ScreenConnect.InstallerActions.dllexecutable
MD5:0C94BBD2593BB06F7E96A3F19DE39EF0
SHA256:54ED2A3200E96D8CF603E594F148F2832340FA23A6CE0140A16B666966CD5D3B
3200rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI21E.tmp-\ScreenConnect.Windows.dllexecutable
MD5:0E7A185162AFAAE9E8B9E088D97A0887
SHA256:D61EA81371332C01BE9969D359DF8412B7E1B0F5803C08DFC480C0421DCE8A44
3200rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI21E.tmp-\ScreenConnect.WindowsInstaller.dllexecutable
MD5:32BC6332F1C75908D862CDD7DF4E981D
SHA256:0DFB99E851541CEF064ABC98270922CA8F9380635B58F43219557E828634F3BE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
45
TCP/UDP connections
34
DNS requests
22
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6084
rundll32.exe
POST
35.172.252.168:443
https://check.screenconnect.com/InstallerOriginInfo.axd
US
unknown
5276
MoUsoCoreWorker.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
6816
msiexec.exe
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
NL
binary
727 b
whitelisted
7788
svchost.exe
POST
403
23.52.181.141:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
US
html
384 b
whitelisted
7788
svchost.exe
POST
403
23.52.181.141:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
US
html
384 b
whitelisted
6816
msiexec.exe
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAHd28bpFj1AfZgKPq95hSg%3D
NL
binary
727 b
whitelisted
5316
svchost.exe
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
NL
binary
471 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
5316
svchost.exe
POST
400
20.190.159.129:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
5316
svchost.exe
POST
200
20.190.159.129:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
7784
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
6816
msiexec.exe
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
6084
rundll32.exe
35.172.252.168:443
check.screenconnect.com
AMAZON-AES
US
whitelisted
3428
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
  • 40.127.240.158
  • 4.231.128.59
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 142.251.141.142
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
check.screenconnect.com
  • 35.172.252.168
  • 107.21.141.65
  • 18.214.243.167
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.129
  • 40.126.31.131
  • 20.190.159.4
  • 40.126.31.130
  • 40.126.31.128
  • 40.126.31.69
  • 40.126.31.2
  • 40.126.31.0
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.166
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 95.100.102.101
whitelisted
go.microsoft.com
  • 23.52.181.141
whitelisted

Threats

PID
Process
Class
Message
2232
svchost.exe
Misc activity
ET REMOTE_ACCESS Observed DNS Query to Known ScreenConnect/ConnectWise Remote Desktop Service Domain
7784
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2232
svchost.exe
Misc activity
ET REMOTE_ACCESS Observed DNS Query to Known ScreenConnect/ConnectWise Remote Desktop Service Domain
6228
ScreenConnect.ClientService.exe
Potential Corporate Privacy Violation
REMOTE [ANY.RUN] ScreenConnect Server Response
No debug info