File name:

zapret-discord-youtube-1.9.0b.rar

Full analysis: https://app.any.run/tasks/e842a1c2-bc0e-4486-bd64-0c0b88c6db6e
Verdict: Malicious activity
Analysis date: December 19, 2025, 16:40:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
windivert-sys
mal-driver
arch-exec
arch-doc
github
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

33F79F498479445FDD58382A2B52AD16

SHA1:

4EC932339E9EE280BA85B5DEF484498B2958FDCD

SHA256:

EA75ED935B605D705DF22FF977C8BC0122A4274A40E132B919876EDF10870BD9

SSDEEP:

49152:Zb4FMyNCQMf5udb/DNj7Ze9rm45sDC69wDe1fwTCFvppsBS9VWIwQtkcTa8ZM1MC:Zb4utV58b/Jj789rv5D6uDefjFvppr9E

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7612)
    • Detects Cygwin installation

      • WinRAR.exe (PID: 7612)
    • Malicious driver has been detected

      • WinRAR.exe (PID: 7612)
    • Starts NET.EXE for service management

      • net.exe (PID: 508)
      • cmd.exe (PID: 7312)
      • net.exe (PID: 6852)
      • net.exe (PID: 3516)
      • net.exe (PID: 8104)
      • net.exe (PID: 6484)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 7612)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 4292)
      • cmd.exe (PID: 7312)
    • Starts process via Powershell

      • powershell.exe (PID: 7280)
    • Starts CMD.EXE for commands execution

      • powershell.exe (PID: 7280)
      • cmd.exe (PID: 7312)
      • cmd.exe (PID: 7416)
      • cmd.exe (PID: 7204)
      • cmd.exe (PID: 5788)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 8120)
      • cmd.exe (PID: 4124)
    • Executing commands from a ".bat" file

      • powershell.exe (PID: 7280)
      • cmd.exe (PID: 7312)
    • Hides command output

      • cmd.exe (PID: 7416)
      • cmd.exe (PID: 8108)
      • cmd.exe (PID: 7204)
      • cmd.exe (PID: 5788)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 8120)
      • cmd.exe (PID: 7244)
      • cmd.exe (PID: 4124)
    • Application launched itself

      • cmd.exe (PID: 7312)
      • cmd.exe (PID: 7416)
      • cmd.exe (PID: 7204)
      • cmd.exe (PID: 5788)
      • cmd.exe (PID: 8080)
      • cmd.exe (PID: 8120)
      • cmd.exe (PID: 4124)
    • Starts application with an unusual extension

      • cmd.exe (PID: 7312)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 7312)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 7312)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 7312)
    • Windows service management via SC.EXE

      • sc.exe (PID: 3348)
      • sc.exe (PID: 7332)
      • sc.exe (PID: 7276)
      • sc.exe (PID: 7600)
      • sc.exe (PID: 5700)
      • sc.exe (PID: 6484)
      • sc.exe (PID: 4784)
      • sc.exe (PID: 1184)
      • sc.exe (PID: 7900)
      • sc.exe (PID: 5600)
      • sc.exe (PID: 4628)
    • Creates a new Windows service

      • sc.exe (PID: 7352)
      • sc.exe (PID: 2348)
    • Executes as Windows Service

      • winws.exe (PID: 7304)
      • winws.exe (PID: 8032)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 7312)
    • Creates or modifies Windows services

      • reg.exe (PID: 7284)
      • reg.exe (PID: 6556)
    • Get information on the list of running processes

      • cmd.exe (PID: 7312)
  • INFO

    • Checks supported languages

      • TextInputHost.exe (PID: 7964)
      • chcp.com (PID: 7244)
      • chcp.com (PID: 5224)
      • chcp.com (PID: 7848)
      • winws.exe (PID: 7304)
      • chcp.com (PID: 7280)
      • chcp.com (PID: 7764)
      • chcp.com (PID: 3036)
      • chcp.com (PID: 2952)
      • chcp.com (PID: 6156)
      • curl.exe (PID: 8188)
      • chcp.com (PID: 8148)
      • chcp.com (PID: 8168)
      • chcp.com (PID: 8176)
      • chcp.com (PID: 1984)
      • chcp.com (PID: 7344)
      • chcp.com (PID: 7368)
      • chcp.com (PID: 7236)
      • winws.exe (PID: 8032)
      • chcp.com (PID: 5336)
      • chcp.com (PID: 6156)
    • Reads the computer name

      • TextInputHost.exe (PID: 7964)
      • winws.exe (PID: 7304)
      • curl.exe (PID: 8188)
      • winws.exe (PID: 8032)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 7612)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7612)
    • Manual execution by a user

      • cmd.exe (PID: 4292)
    • Changes the display of characters in the console

      • cmd.exe (PID: 7312)
    • Disables trace logs

      • netsh.exe (PID: 4992)
      • netsh.exe (PID: 6456)
      • netsh.exe (PID: 4540)
    • Execution of CURL command

      • cmd.exe (PID: 7312)
    • Create files in a temporary directory

      • curl.exe (PID: 8188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 606
UncompressedSize: 2415
OperatingSystem: Win32
ArchivedFileName: general (ALT10).bat
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
384
Monitored processes
241
Malicious processes
4
Suspicious processes
6

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
508C:\WINDOWS\system32\cmd.exe /S /D /c" echo %LISTS%list-general.txt "C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
508net stop zapret C:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\samcli.dll
508findstr ":" C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
748findstr ":" C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
748find /c /v ""C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
936C:\WINDOWS\system32\cmd.exe /S /D /c" echo cd /d %BIN% "C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1088findstr /i "winws.exe" C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1148findstr /i "winws.exe" C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1148C:\WINDOWS\system32\cmd.exe /S /D /c" echo %BIN%quic_initial_www_google_com.bin "C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1184sc delete "WinDivert14" C:\Windows\System32\sc.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
1060
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
Total events
14 536
Read events
14 520
Write events
16
Delete events
0

Modification events

(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\zapret-discord-youtube-1.9.0b.rar
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7304) winws.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Cygwin\Installations
Operation:writeName:4331dfac226259e9
Value:
\??\C:\Users\admin\Desktop\zapret
(PID) Process:(7304) winws.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\System\WinDivert
Operation:writeName:EventMessageFile
Value:
C:\Users\admin\Desktop\zapret\bin\WinDivert64.sys
Executable files
4
Suspicious files
4
Text files
29
Unknown types
0

Dropped files

PID
Process
Filename
Type
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7612.6775\general (FAKE TLS AUTO ALT).battext
MD5:2CC05A727F31AFDF6127547EA606BF0E
SHA256:B8FE3B554155B4CFF1D625FFCD2C79ADD3EA73E11741D92E289AE7BA5F494984
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7612.6775\general (FAKE TLS AUTO).battext
MD5:B8707EE81290939D057B8704B2FBA574
SHA256:9E8754B242BF381A3A918886A9C25CD0A801262A1F8F43C9FF9D22EEF16DBBAD
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7612.6775\general (SIMPLE FAKE ALT).battext
MD5:1221889EBF4C39AF331801C90604C57F
SHA256:034D9C53AE6C4399EC25DAE69FBF83026306EBCD453CCF127046339B68621E6B
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7612.6775\general (ALT10).battext
MD5:666394850863BC1DCE5FA24A49A9D3EA
SHA256:652207A70A993EBCF02FD2463F5E9593AC593FFB75D84EC4B8871CF8D84033C1
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7612.6775\general (FAKE TLS AUTO ALT3).battext
MD5:6EDD4F2F5439991900A96B658823653F
SHA256:A2077B859D7D5955C6F22918EAD0CEAC18D6B986ADE84CA047795AC855B78969
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7612.6775\general.battext
MD5:E7F7B1B92BCE9411C84C3FA13B0F6133
SHA256:E883E1AD4009092E628355E57A8256880B45BBAFE6A51DC502D8E8F41CEBA620
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7612.6775\general (SIMPLE FAKE).battext
MD5:E517DB2B524EC74A81B94CD75CC96476
SHA256:EB3AFA8489A158654D5DC038923338BA9D8FA607CCD1D410967B33577096D940
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7612.6775\bin\tls_clienthello_4pda_to.binbinary
MD5:E6D649DE132C3C10CB62531EF74F5B73
SHA256:EEFEAF09DDE8D69B1F176212541F63C68B314A33A335ECED99A8A29F17254DA8
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7612.6775\general (FAKE TLS AUTO ALT2).battext
MD5:BD80CFF8B83F850512CD7B53B9A78EE6
SHA256:3D03890FEDDB2E0E854FB0656404519590CECF9B037AA50ED2BF9634E236658C
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7612.6775\bin\cygwin1.dllexecutable
MD5:A1C82ED072DC079DD7851F82D9AA7678
SHA256:103104A52E5293CE418944725DF19E2BF81AD9269B9A120D71D39028E821499B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
28
DNS requests
20
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
3304
svchost.exe
POST
200
20.190.159.129:443
https://login.live.com/RST2.srf
US
xml
11.0 Kb
whitelisted
3304
svchost.exe
POST
200
20.190.159.129:443
https://login.live.com/RST2.srf
US
xml
11.1 Kb
whitelisted
1316
SIHClient.exe
GET
200
40.69.42.241:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
1316
SIHClient.exe
GET
200
135.232.92.137:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
1316
SIHClient.exe
GET
304
135.232.92.137:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
3304
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
3304
svchost.exe
POST
200
20.190.159.129:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
whitelisted
3304
svchost.exe
POST
200
20.190.159.129:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
1136
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1176
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3412
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3304
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3304
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1136
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1136
svchost.exe
184.24.77.42:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.238
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.129
  • 40.126.31.3
  • 20.190.159.130
  • 20.190.159.0
  • 20.190.159.71
  • 40.126.31.128
  • 40.126.31.1
  • 40.126.31.67
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 184.24.77.42
  • 184.24.77.11
  • 184.24.77.12
  • 184.24.77.38
  • 184.24.77.23
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 72.246.29.11
  • 23.59.18.102
whitelisted
slscr.update.microsoft.com
  • 135.232.92.137
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
self.events.data.microsoft.com
  • 20.42.65.89
whitelisted

Threats

PID
Process
Class
Message
2292
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
No debug info