File name:

wiresock-secure-connect-x64-2.4.16.1.exe

Full analysis: https://app.any.run/tasks/f175efdc-90ef-4f98-918c-2f133bb6e019
Verdict: Malicious activity
Analysis date: August 02, 2025, 18:50:09
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, InstallShield self-extracting archive, 9 sections
MD5:

638EA7AAFE99D91B68B5C59566FE8D7C

SHA1:

9A2BC744327C67714F18269B99FE2B1E2030F927

SHA256:

E41C36C2ECF2B6FE1891BCC112CAB04F189F7D21AE3E5779171E3EA8D71BB448

SSDEEP:

98304:9lvKAhyEGqiunoagsOGfkXp69A0+mo/x8Mo50VQ6yRZBN4+oJFPfMwhCHZHPeNBl:jVSZ0VFFPzez

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • wiresock-secure-connect-x64-2.4.16.1.exe (PID: 6104)
    • Process drops legitimate windows executable

      • wiresock-secure-connect-x64-2.4.16.1.exe (PID: 6104)
    • There is functionality for taking screenshot (YARA)

      • wiresock-secure-connect-x64-2.4.16.1.exe (PID: 6104)
    • Searches for installed software

      • wiresock-secure-connect-x64-2.4.16.1.exe (PID: 6104)
  • INFO

    • The sample compiled with english language support

      • wiresock-secure-connect-x64-2.4.16.1.exe (PID: 6104)
    • Create files in a temporary directory

      • wiresock-secure-connect-x64-2.4.16.1.exe (PID: 6104)
    • Checks supported languages

      • wiresock-secure-connect-x64-2.4.16.1.exe (PID: 6104)
      • wixstdba.exe (PID: 6656)
      • netcoresearch.exe (PID: 4520)
      • identity_helper.exe (PID: 7788)
    • Application launched itself

      • msedge.exe (PID: 2428)
    • Reads the computer name

      • wiresock-secure-connect-x64-2.4.16.1.exe (PID: 6104)
      • identity_helper.exe (PID: 7788)
      • wixstdba.exe (PID: 6656)
    • Manual execution by a user

      • msedge.exe (PID: 2428)
    • Reads Environment values

      • identity_helper.exe (PID: 7788)
    • Checks proxy server information

      • slui.exe (PID: 4540)
    • Reads the software policy settings

      • slui.exe (PID: 4540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:04:07 17:50:27+00:00
ImageFileCharacteristics: Executable, Large address aware, Removable run from swap, Net run from swap
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 569344
InitializedDataSize: 795136
UninitializedDataSize: -
EntryPoint: 0x610f0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.4.16.1
ProductVersionNumber: 2.4.16.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: WireSock Foundation
FileDescription: WireSock Secure Connect
FileVersion: 2.4.16.1
InternalName: burn
OriginalFileName: wiresock-secure-connect.exe
ProductName: WireSock Secure Connect
ProductVersion: 2.4.16.1
LegalCopyright: Copyright (c) 2021-2025 WireSock Foundation
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
32
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wiresock-secure-connect-x64-2.4.16.1.exe wixstdba.exe no specs netcoresearch.exe no specs conhost.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
436"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6904,i,5976632814546057111,8927577263251187702,262144 --variations-seed-version --mojo-platform-channel-handle=1520 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
516"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2752,i,5976632814546057111,8927577263251187702,262144 --variations-seed-version --mojo-platform-channel-handle=2760 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1212"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4284,i,5976632814546057111,8927577263251187702,262144 --variations-seed-version --mojo-platform-channel-handle=4356 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1244\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetcoresearch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2428"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.wiresock.net/license/wiresock_eulaC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2976"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5956,i,5976632814546057111,8927577263251187702,262144 --variations-seed-version --mojo-platform-channel-handle=6664 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3688"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5876,i,5976632814546057111,8927577263251187702,262144 --variations-seed-version --mojo-platform-channel-handle=6012 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=588,i,5976632814546057111,8927577263251187702,262144 --variations-seed-version --mojo-platform-channel-handle=1356 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4232"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2268,i,5976632814546057111,8927577263251187702,262144 --variations-seed-version --mojo-platform-channel-handle=2544 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4520"C:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\Wix4NetfxBootstrapperExtension_X64\x64\netcoresearch.exe" runtime 9 Microsoft.WindowsDesktop.AppC:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\Wix4NetfxBootstrapperExtension_X64\x64\netcoresearch.exewiresock-secure-connect-x64-2.4.16.1.exe
User:
admin
Company:
WiX Toolset
Integrity Level:
MEDIUM
Description:
netcoresearch
Exit code:
0
Version:
6.0.1.0
Modules
Images
c:\users\admin\appdata\local\temp\{59375f4c-3704-44f3-aaa7-6d92cf286433}\.ba\wix4netfxbootstrapperextension_x64\x64\netcoresearch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\{59375f4c-3704-44f3-aaa7-6d92cf286433}\.ba\wix4netfxbootstrapperextension_x64\x64\hostfxr.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
8 158
Read events
8 143
Write events
15
Delete events
0

Modification events

(PID) Process:(2428) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2428) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2428) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2428) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
66B6C5A1FC992F00
(PID) Process:(2428) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(2428) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328440
Operation:writeName:WindowTabManagerFileMappingId
Value:
{404F9382-8333-4251-9CCB-6B47E44FDF8B}
(PID) Process:(2428) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328440
Operation:writeName:WindowTabManagerFileMappingId
Value:
{1AD1C546-9D2B-48B4-B31B-D1051126B450}
(PID) Process:(2428) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328440
Operation:writeName:WindowTabManagerFileMappingId
Value:
{FB6995E6-9645-4479-859F-95751D89EFFB}
(PID) Process:(2428) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328440
Operation:writeName:WindowTabManagerFileMappingId
Value:
{B54C4EF0-DD07-4356-BE7A-BE875A675C5A}
(PID) Process:(2428) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
B4C3E1A2FC992F00
Executable files
19
Suspicious files
274
Text files
81
Unknown types
0

Dropped files

PID
Process
Filename
Type
6104wiresock-secure-connect-x64-2.4.16.1.exeC:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\icon.icoimage
MD5:8B4CD6BEA65A2FC8E1D5B3C90D989066
SHA256:F7A7AA48644508A9C624F4B9ACDC8D03031BFD45097D93D7AC3337F34300AB6A
6104wiresock-secure-connect-x64-2.4.16.1.exeC:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\1034\logo.pngimage
MD5:594F3877CCE1DB2395ACFFBB6C182E4E
SHA256:E627A5A1D090ADC3F85EB6C52DBCB6BD8B7B07B6395EBBF7F281235C929D7BE2
6104wiresock-secure-connect-x64-2.4.16.1.exeC:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\1031\icon.icoimage
MD5:8B4CD6BEA65A2FC8E1D5B3C90D989066
SHA256:F7A7AA48644508A9C624F4B9ACDC8D03031BFD45097D93D7AC3337F34300AB6A
6104wiresock-secure-connect-x64-2.4.16.1.exeC:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\1031\thm.wxltext
MD5:437F7882DA28890BA5CA1D8977BA2989
SHA256:2AEE0E49423F443DB0ACBC297F68EC5BD03A79B95B057F9D53EEBA2D8C289E03
6104wiresock-secure-connect-x64-2.4.16.1.exeC:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\1031\logo.pngimage
MD5:594F3877CCE1DB2395ACFFBB6C182E4E
SHA256:E627A5A1D090ADC3F85EB6C52DBCB6BD8B7B07B6395EBBF7F281235C929D7BE2
6104wiresock-secure-connect-x64-2.4.16.1.exeC:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\1034\thm.xmlxml
MD5:4BD16A2ADAFDAAE8673EC963F7D1333A
SHA256:74D464822EBC30ACDE5A4F2C5E83F143B58381C43F1940CE66F95EF5C1127A2D
6104wiresock-secure-connect-x64-2.4.16.1.exeC:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\1049\thm.xmlxml
MD5:4BD16A2ADAFDAAE8673EC963F7D1333A
SHA256:74D464822EBC30ACDE5A4F2C5E83F143B58381C43F1940CE66F95EF5C1127A2D
6104wiresock-secure-connect-x64-2.4.16.1.exeC:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\1034\icon.icoimage
MD5:8B4CD6BEA65A2FC8E1D5B3C90D989066
SHA256:F7A7AA48644508A9C624F4B9ACDC8D03031BFD45097D93D7AC3337F34300AB6A
6104wiresock-secure-connect-x64-2.4.16.1.exeC:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\1036\thm.wxltext
MD5:41A70C87923686217CB1814CEBF82FB8
SHA256:E710D9961B5CAE4AB1D94BA49F7112BE4F786019F1B8EA9BBC0EAF70A4DAF58F
6104wiresock-secure-connect-x64-2.4.16.1.exeC:\Users\admin\AppData\Local\Temp\{59375F4C-3704-44F3-AAA7-6D92CF286433}\.ba\1036\icon.icoimage
MD5:8B4CD6BEA65A2FC8E1D5B3C90D989066
SHA256:F7A7AA48644508A9C624F4B9ACDC8D03031BFD45097D93D7AC3337F34300AB6A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
147
TCP/UDP connections
138
DNS requests
86
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.15:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
POST
200
40.126.32.72:443
https://login.live.com/RST2.srf
unknown
xml
1.24 Kb
whitelisted
GET
200
23.216.77.15:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.216.77.15:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
400
40.126.32.72:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
text
203 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
200
40.126.32.76:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
text
16.7 Kb
whitelisted
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=EdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=51&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1754160630&lafgdate=0
unknown
binary
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.216.77.15:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.216.77.15:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.216.77.15:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
69.192.161.161:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
69.192.161.161:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
69.192.161.161:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
20.190.160.65:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.216.77.15
  • 23.216.77.18
  • 23.216.77.27
  • 23.216.77.32
  • 23.216.77.19
  • 23.216.77.16
  • 23.216.77.30
  • 23.216.77.28
  • 23.216.77.13
  • 23.216.77.17
  • 23.216.77.29
  • 23.216.77.21
  • 23.216.77.23
  • 23.216.77.22
whitelisted
google.com
  • 142.250.184.238
whitelisted
www.microsoft.com
  • 69.192.161.161
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.160.65
  • 40.126.32.74
  • 20.190.160.66
  • 40.126.32.76
  • 20.190.160.20
  • 20.190.160.64
  • 40.126.32.138
  • 40.126.32.136
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
www.wiresock.net
  • 104.21.16.1
  • 104.21.64.1
  • 104.21.112.1
  • 104.21.32.1
  • 104.21.96.1
  • 104.21.48.1
  • 104.21.80.1
unknown
copilot.microsoft.com
  • 92.123.104.53
  • 92.123.104.45
whitelisted
www.bing.com
  • 2.16.241.218
  • 2.16.241.205
  • 92.123.104.58
  • 92.123.104.62
  • 92.123.104.53
  • 92.123.104.5
  • 92.123.104.66
  • 92.123.104.63
  • 92.123.104.65
  • 92.123.104.67
  • 92.123.104.61
whitelisted

Threats

PID
Process
Class
Message
4232
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
4232
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
4232
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
4232
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Potentially Bad Traffic
ET INFO Possible Chrome Plugin install
No debug info