download:

/FluffyFox337/GoodbyeDPI_Launcher/releases/download/Latest/GoodbyeDPI.0.2.3rc3.-.Launcher.9.1.rar

Full analysis: https://app.any.run/tasks/e9fe3d4e-a5ea-43c6-b5ae-89d780e7255d
Verdict: Malicious activity
Analysis date: January 17, 2025, 11:18:47
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-scr
arch-doc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2F5FB54FF4DD78D46738315F2ED2B43D

SHA1:

42CAA48B2DC885CC62D17AF57214FE8FF7755D88

SHA256:

E3CBC4909313FC9ACC380FB5B6EE9E2C7C051F7B63D2AF24EE8E070003A8F440

SSDEEP:

98304:R/zeKTnKtXHyMMD6QdaE//E17jknuJ9sAvLuLGCmCUwsqAn8dprENbuPfvt4QlJb:9SNiuB6zdPADkursqLaV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Launcher for GoodbyeDPI.exe (PID: 6988)
      • Launcher for GoodbyeDPI.exe (PID: 6936)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 6288)
    • Reads security settings of Internet Explorer

      • Launcher for GoodbyeDPI.exe (PID: 6988)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 6288)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6288)
    • Manual execution by a user

      • Launcher for GoodbyeDPI.exe (PID: 6988)
      • Launcher for GoodbyeDPI.exe (PID: 6936)
      • msedge.exe (PID: 6668)
      • goodbyedpi.exe (PID: 7412)
      • goodbyedpi.exe (PID: 4684)
    • Checks supported languages

      • Launcher for GoodbyeDPI.exe (PID: 6988)
      • goodbyedpi.exe (PID: 4684)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6288)
    • Checks proxy server information

      • Launcher for GoodbyeDPI.exe (PID: 6988)
    • Reads the computer name

      • Launcher for GoodbyeDPI.exe (PID: 6988)
      • goodbyedpi.exe (PID: 4684)
    • Creates files or folders in the user directory

      • Launcher for GoodbyeDPI.exe (PID: 6988)
    • Create files in a temporary directory

      • Launcher for GoodbyeDPI.exe (PID: 6988)
    • Application launched itself

      • msedge.exe (PID: 3080)
      • msedge.exe (PID: 6668)
      • msedge.exe (PID: 7484)
    • Reads the machine GUID from the registry

      • goodbyedpi.exe (PID: 4684)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 774
UncompressedSize: 1917
OperatingSystem: Win32
ArchivedFileName: GoodbyeDPI 0.2.3rc3 - Launcher 9.1/GoodCheck_v1.3.02_by_Ori/CheckLists/default - all.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
191
Monitored processes
62
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs launcher for goodbyedpi.exe no specs launcher for goodbyedpi.exe goodbyedpi.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs goodbyedpi.exe no specs goodbyedpi.exe conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs system

Process information

PID
CMD
Path
Indicators
Parent process
4System
[System Process]
User:
SYSTEM
Integrity Level:
SYSTEM
520"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4472 --field-trial-handle=2312,i,935470998699001392,14845256622695868153,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
648"C:\Users\admin\Desktop\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\x64\goodbyedpi.exe" -pC:\Users\admin\Desktop\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\x64\goodbyedpi.exeLauncher for GoodbyeDPI.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\goodbyedpi 0.2.3rc3 - launcher 9.1\x64\goodbyedpi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1576"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6912 --field-trial-handle=2312,i,935470998699001392,14845256622695868153,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1592"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6696 --field-trial-handle=2312,i,935470998699001392,14845256622695868153,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1604"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=6572 --field-trial-handle=2312,i,935470998699001392,14845256622695868153,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
1804"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x310,0x314,0x318,0x308,0x320,0x7ff821835fd8,0x7ff821835fe4,0x7ff821835ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2144"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6808 --field-trial-handle=2312,i,935470998699001392,14845256622695868153,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2440"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5904 --field-trial-handle=2312,i,935470998699001392,14845256622695868153,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2496"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5320 --field-trial-handle=2312,i,935470998699001392,14845256622695868153,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
9 137
Read events
9 003
Write events
134
Delete events
0

Modification events

(PID) Process:(6288) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6288) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6288) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6288) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\GoodbyeDPI.0.2.3rc3.-.Launcher.9.1.rar
(PID) Process:(6288) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6288) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6288) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6288) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6988) Launcher for GoodbyeDPI.exeKey:HKEY_CURRENT_USER\SOFTWARE\GoodbyeDPILauncher
Operation:writeName:Autostart
Value:
0
(PID) Process:(6988) Launcher for GoodbyeDPI.exeKey:HKEY_CURRENT_USER\SOFTWARE\GoodbyeDPILauncher
Operation:writeName:Traybar
Value:
0
Executable files
30
Suspicious files
307
Text files
133
Unknown types
0

Dropped files

PID
Process
Filename
Type
6288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6288.6190\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\GoodCheck_v1.3.02_by_Ori\Curl\x86_64\curl-ca-bundle.crttext
MD5:B69D53019578C19B65E5AA8CC6F6AA21
SHA256:189D3CF6D103185FBA06D76C1AF915263C6D42225481A1759E853B33AC857540
6288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6288.6190\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\GoodCheck_v1.3.02_by_Ori\CheckLists\default - googlevideo.txttext
MD5:21A6875A0EE44096C6CCFD1F71B307A7
SHA256:238CD73E9492E45D9B75EF6D8504DB6E721261204D373FD0809D98F6D2F98BF0
6288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6288.6190\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\GoodCheck_v1.3.02_by_Ori\Curl\COPYING.txttext
MD5:EED2E5088E1AC619C9A1C747DA291D75
SHA256:ADB1FC06547FD136244179809F7B7C2D2AE6C4534F160AA513AF9B6A12866A32
6288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6288.6190\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\GoodCheck_v1.3.02_by_Ori\Curl\x86\curl-ca-bundle.crttext
MD5:B69D53019578C19B65E5AA8CC6F6AA21
SHA256:189D3CF6D103185FBA06D76C1AF915263C6D42225481A1759E853B33AC857540
6288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6288.6190\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\GoodCheck_v1.3.02_by_Ori\CheckLists\default - miscellaneous.txttext
MD5:2BDA21B875EC448B06D81496AA1DBF1C
SHA256:EA34E50D34CE0B31D5432FA3447D5E1FC8D0862F8AD7F82728826F73B2CF51CF
6288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6288.6190\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\GoodCheck_v1.3.02_by_Ori\Curl\x86\curl.exeexecutable
MD5:8BCD0DBC69A10E234DF3F351BFF2F21A
SHA256:E74DCA5A781DB61939E4B13265F428676A0DF462E07D4C18A288974B49068E05
6288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6288.6190\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\GoodCheck_v1.3.02_by_Ori\Curl\x86_64\libcurl-x64.deftext
MD5:C262DD6043DEBD2087229A3B4F9C5D6F
SHA256:3FED26066219F488BC8D0819C008B4E5E0A57ECE5B31EFAB555D27B7F974458A
6288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6288.6190\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\GoodCheck_v1.3.02_by_Ori\Curl\x86\libcurl.dllexecutable
MD5:2E6BABB5E3A9B947D88DD02AF45105CB
SHA256:1D340D08DFD0BE38E5A9DC554FD5466ACC6D6A01DAC25D8B14CF360E632199F1
6288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6288.6190\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\GoodCheck_v1.3.02_by_Ori\elevator.vbstext
MD5:699F8C08A4708A4CB5FE27F7A5870D78
SHA256:B0D92CDD3FD81FAEFE2C8D2B470117A9B8CF765EC7673C76FB287A901A3F7977
6288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6288.6190\GoodbyeDPI 0.2.3rc3 - Launcher 9.1\GoodCheck_v1.3.02_by_Ori\Curl\x86_64\curl.exeexecutable
MD5:143E780A9CCE0A67DA05CA6715643FE4
SHA256:4A3FA963113EABEAC7D451AEA0248A64A85232A7E030C4AA635D83428573C0E2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
113
DNS requests
103
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4
System
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4
System
GET
200
23.48.23.137:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6988
Launcher for GoodbyeDPI.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6988
Launcher for GoodbyeDPI.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
4
System
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4
System
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6176
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
unknown
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5004
svchost.exe
23.48.23.137:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
5004
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.163:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
unknown
5064
SearchApp.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
unknown
crl.microsoft.com
  • 23.48.23.137
  • 23.48.23.153
  • 23.48.23.141
  • 23.48.23.149
  • 23.48.23.134
  • 23.48.23.140
  • 23.48.23.156
  • 23.48.23.161
  • 23.48.23.143
unknown
google.com
  • 142.250.186.78
unknown
www.microsoft.com
  • 184.30.21.171
unknown
www.bing.com
  • 104.126.37.163
  • 104.126.37.168
  • 104.126.37.178
  • 104.126.37.171
  • 104.126.37.185
  • 104.126.37.170
  • 104.126.37.176
  • 104.126.37.177
  • 104.126.37.186
  • 104.126.37.160
  • 104.126.37.162
  • 104.126.37.161
unknown
ocsp.digicert.com
  • 2.17.190.73
unknown
login.live.com
  • 20.190.159.68
  • 40.126.31.69
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.67
  • 40.126.31.71
  • 20.190.159.2
  • 20.190.159.64
unknown
go.microsoft.com
  • 23.218.210.69
unknown
arc.msn.com
  • 20.31.169.57
unknown
fd.api.iris.microsoft.com
  • 20.223.35.26
unknown

Threats

PID
Process
Class
Message
6976
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
6976
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
6976
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
6976
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
No debug info