File name:

SorillusRAT_@ReverseEngineeringLab.rar

Full analysis: https://app.any.run/tasks/8fa008a6-7ac8-404c-a242-9b8e5a4a921c
Verdict: Malicious activity
Threats:

Adwind RAT, sometimes also called Unrecom, Sockrat, Frutas, jRat, and JSocket, is a Malware As A Service Remote Access Trojan that attackers can use to collect information from infected machines. It was one of the most popular RATs in the market in 2015.

Analysis date: November 26, 2024, 17:48:10
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-scr
adwind
java
rat
remote
evasion
arch-html
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

6B59FC4285E7842E36F3EC5A72935B44

SHA1:

C1F3A89AC73F57C68C78BC9A1EC4C1FAC687B9AF

SHA256:

E7AAB6ECC96BE090AB8E04384E4685ED3E92466F5C776AA155A7FD5F05A098E6

SSDEEP:

786432:SgTpulP9RMRYuLx1EefJn/mhE9+5PCghok/uLyWE7yRtl:SgTpcP9R/sx15ea9+5PFekGLyWE7yRv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADWIND has been detected

      • javaw.exe (PID: 5912)
      • java.exe (PID: 5404)
      • javaw.exe (PID: 6912)
      • javaw.exe (PID: 6208)
      • javaw.exe (PID: 1412)
    • ADWIND has been detected (SURICATA)

      • javaw.exe (PID: 5912)
    • Connects to the CnC server

      • javaw.exe (PID: 5912)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 3988)
    • Starts CMD.EXE for commands execution

      • javaw.exe (PID: 5912)
      • javaw.exe (PID: 6912)
      • javaw.exe (PID: 1412)
      • javaw.exe (PID: 6208)
    • Executable content was dropped or overwritten

      • java.exe (PID: 5404)
    • Uses ATTRIB.EXE to modify file attributes

      • javaw.exe (PID: 5912)
      • javaw.exe (PID: 6912)
      • javaw.exe (PID: 1412)
      • javaw.exe (PID: 6208)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 6664)
      • cmd.exe (PID: 6928)
      • cmd.exe (PID: 4188)
      • cmd.exe (PID: 6344)
    • Checks for external IP

      • java.exe (PID: 5404)
      • svchost.exe (PID: 2192)
    • Connects to unusual port

      • javaw.exe (PID: 5912)
      • javaw.exe (PID: 6912)
    • Identifying current user with WHOAMI command

      • cmd.exe (PID: 3896)
    • Contacting a server suspected of hosting an CnC

      • javaw.exe (PID: 5912)
  • INFO

    • Manual execution by a user

      • cmd.exe (PID: 6152)
      • javaw.exe (PID: 6912)
      • javaw.exe (PID: 1412)
      • WinRAR.exe (PID: 4944)
      • javaw.exe (PID: 6208)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 3988)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3988)
    • Application based on Java

      • javaw.exe (PID: 5912)
      • javaw.exe (PID: 6912)
      • javaw.exe (PID: 1412)
      • javaw.exe (PID: 6208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 6288
UncompressedSize: 12224
OperatingSystem: Win32
ArchivedFileName: Sorillus/jre1.8.0_361/bin/api-ms-win-core-console-l1-1-0.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
38
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs cmd.exe no specs conhost.exe no specs #ADWIND java.exe icacls.exe no specs conhost.exe no specs svchost.exe openwith.exe no specs #ADWIND javaw.exe attrib.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs reg.exe no specs #ADWIND javaw.exe attrib.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs reg.exe no specs #ADWIND javaw.exe no specs attrib.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs reg.exe no specs winrar.exe no specs openwith.exe no specs cmd.exe no specs conhost.exe no specs whoami.exe no specs #ADWIND javaw.exe no specs attrib.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs reg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1224C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1348REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v Home /d "C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe -jar C:\Users\admin\AppData\Roaming\Microsoft\.tmp\1732643495408.tmp" /fC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
1412"C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe" -jar "C:\Users\admin\Downloads\client2.jar" C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe
explorer.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1468attrib +H C:\Users\admin\AppData\Roaming\Microsoft\.tmp\1732643679133.tmpC:\Windows\System32\attrib.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\attrib.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1740C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1856REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v Home /d "C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe -jar C:\Users\admin\AppData\Roaming\Microsoft\.tmp\1732643521873.tmp" /fC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
2124\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2192C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2324C:\WINDOWS\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ntmarta.dll
2776\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
35 340
Read events
35 171
Write events
163
Delete events
6

Modification events

(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\SorillusRAT_@ReverseEngineeringLab.rar
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
Executable files
162
Suspicious files
41
Text files
127
Unknown types
0

Dropped files

PID
Process
Filename
Type
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3988.14833\Sorillus\jre1.8.0_361\bin\api-ms-win-core-handle-l1-1-0.dllexecutable
MD5:BBAFA10627AF6DFAE5ED6E4AEAE57B2A
SHA256:C78A1217F8DCB157D1A66B80348DA48EBDBBEDCEA1D487FC393191C05AAD476D
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3988.14833\Sorillus\jre1.8.0_361\bin\api-ms-win-core-heap-l1-1-0.dllexecutable
MD5:3A4B6B36470BAD66621542F6D0D153AB
SHA256:2E981EE04F35C0E0B7C58282B70DCC9FC0318F20F900607DAE7A0D40B36E80AF
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3988.14833\Sorillus\jre1.8.0_361\bin\api-ms-win-core-console-l1-2-0.dllexecutable
MD5:7676560D0E9BC1EE9502D2F920D2892F
SHA256:00942431C2D3193061C7F4DC340E8446BFDBF792A7489F60349299DFF689C2F9
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3988.14833\Sorillus\jre1.8.0_361\bin\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:35BC1F1C6FBCCEC7EB8819178EF67664
SHA256:7A3C5167731238CF262F749AA46AB3BFB2AE1B22191B76E28E1D7499D28C24B7
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3988.14833\Sorillus\jre1.8.0_361\bin\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:AC51E3459E8FCE2A646A6AD4A2E220B9
SHA256:77577F35D3A61217EA70F21398E178F8749455689DB52A2B35A85F9B54C79638
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3988.14833\Sorillus\jre1.8.0_361\bin\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:94788729C9E7B9C888F4E323A27AB548
SHA256:ACCDD7455FB6D02FE298B987AD412E00D0B8E6F5FB10B52826367E7358AE1187
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3988.14833\Sorillus\jre1.8.0_361\bin\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:B0E0678DDC403EFFC7CDC69AE6D641FB
SHA256:45E48320ABE6E3C6079F3F6B84636920A367989A88F9BA6847F88C210D972CF1
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3988.14833\Sorillus\jre1.8.0_361\bin\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:919E653868A3D9F0C9865941573025DF
SHA256:2AFBFA1D77969D0F4CEE4547870355498D5C1DA81D241E09556D0BD1D6230F8C
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3988.14833\Sorillus\jre1.8.0_361\bin\api-ms-win-core-file-l2-1-0.dllexecutable
MD5:3BF4406DE02AA148F460E5D709F4F67D
SHA256:349A79FA1572E3538DFBB942610D8C47D03E8A41B98897BC02EC7E897D05237E
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3988.14833\Sorillus\jre1.8.0_361\bin\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:580D9EA2308FC2D2D2054A79EA63227C
SHA256:7CB0396229C3DA434482A5EF929D3A2C392791712242C9693F06BAA78948EF66
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
89
DNS requests
13
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
880
svchost.exe
GET
200
23.53.41.242:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
6284
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
880
svchost.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.53.41.242:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
6284
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
418 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.16.204.135:443
www.bing.com
Akamai International B.V.
DE
whitelisted
880
svchost.exe
23.53.41.242:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.53.41.242:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
880
svchost.exe
23.37.237.227:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.37.237.227:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
5404
java.exe
52.18.175.46:443
checkip.amazonaws.com
AMAZON-02
IE
shared
5912
javaw.exe
95.223.77.143:4444
Vodafone GmbH
DE
malicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.16.204.135
  • 2.16.204.141
  • 2.16.204.142
  • 2.16.204.156
  • 2.16.204.153
  • 2.16.204.145
  • 2.16.204.134
  • 2.16.204.146
  • 2.16.204.138
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.206
whitelisted
crl.microsoft.com
  • 23.53.41.242
  • 23.53.42.51
  • 23.53.42.34
whitelisted
www.microsoft.com
  • 23.37.237.227
whitelisted
checkip.amazonaws.com
  • 52.18.175.46
  • 54.73.109.50
  • 54.74.44.6
shared
self.events.data.microsoft.com
  • 104.208.16.88
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

PID
Process
Class
Message
2192
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (checkip .amazonaws .com)
5404
java.exe
Device Retrieving External IP Address Detected
ET INFO Observed External IP Lookup Domain (checkip .amazonaws .com) in TLS SNI
1 ETPRO signatures available at the full report
No debug info