File name:

GenP_3.4.14.1_Reddit version.rar

Full analysis: https://app.any.run/tasks/bc35200b-68e6-4de3-9cfb-266119448362
Verdict: Malicious activity
Analysis date: September 23, 2025, 14:14:49
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

9B08CDCDD7A3034260503C85B150D18A

SHA1:

38C62D373028B326FB898F34886B1D99E9D9B856

SHA256:

EE6B4AACC846208A96924307F2B6887652F97421D4CC208919F2699027208D64

SSDEEP:

24576:KyCKOSrvmns9nVRq+Wi5GP7D4yQBC/uMfIp2Db/GFYeoEejrCCajWRQqNEmOjyXh:KyCKOSrvmns9nVRq+Wi5GP7D4lBC/uM9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 5436)
  • SUSPICIOUS

    • Application launched itself

      • GenP-3.4.14.1.exe (PID: 3756)
    • Reads security settings of Internet Explorer

      • GenP-3.4.14.1.exe (PID: 3756)
      • GenP-3.4.14.1.exe (PID: 6748)
      • ShellExperienceHost.exe (PID: 4060)
    • Reads the date of Windows installation

      • GenP-3.4.14.1.exe (PID: 3756)
    • Executable content was dropped or overwritten

      • GenP-3.4.14.1.exe (PID: 5576)
      • GenP-3.4.14.1.exe (PID: 6748)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 5436)
    • Manual execution by a user

      • GenP-3.4.14.1.exe (PID: 3756)
      • firefox.exe (PID: 4120)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5436)
    • Checks supported languages

      • GenP-3.4.14.1.exe (PID: 3756)
      • GenP-3.4.14.1.exe (PID: 5576)
      • GenP-3.4.14.1.exe (PID: 6748)
      • NSudoLG.exe (PID: 6856)
      • ShellExperienceHost.exe (PID: 4060)
    • Reads the computer name

      • GenP-3.4.14.1.exe (PID: 3756)
      • GenP-3.4.14.1.exe (PID: 5576)
      • NSudoLG.exe (PID: 6856)
      • GenP-3.4.14.1.exe (PID: 6748)
    • Process checks computer location settings

      • GenP-3.4.14.1.exe (PID: 3756)
    • Reads mouse settings

      • GenP-3.4.14.1.exe (PID: 3756)
      • GenP-3.4.14.1.exe (PID: 5576)
      • GenP-3.4.14.1.exe (PID: 6748)
    • Create files in a temporary directory

      • GenP-3.4.14.1.exe (PID: 5576)
    • Checks proxy server information

      • slui.exe (PID: 3640)
    • Creates files in the program directory

      • GenP-3.4.14.1.exe (PID: 6748)
    • Application launched itself

      • firefox.exe (PID: 4120)
      • firefox.exe (PID: 6304)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 6304)
    • Reads the software policy settings

      • slui.exe (PID: 3640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 2115
UncompressedSize: 7431
OperatingSystem: Win32
ArchivedFileName: GenP_3.4.14.1_Reddit version/config.ini
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
162
Monitored processes
21
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs genp-3.4.14.1.exe no specs genp-3.4.14.1.exe slui.exe nsudolg.exe no specs genp-3.4.14.1.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs shellexperiencehost.exe no specs systemsettingsbroker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1352"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 3292 -prefsLen 36996 -prefMapHandle 2884 -prefMapSize 272997 -ipcHandle 3368 -initialChannelId {7a9de0b7-b0ea-4e7c-93d6-6c707976ea05} -parentPid 6304 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6304" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1356"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 2204 -prefsLen 36520 -prefMapHandle 2208 -prefMapSize 272997 -ipcHandle 2216 -initialChannelId {c47608b1-e714-4752-9cf7-51ef3836164e} -parentPid 6304 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6304" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2592"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5328 -prefsLen 39068 -prefMapHandle 5332 -prefMapSize 272997 -jsInitHandle 5336 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5340 -initialChannelId {ea802e34-9797-4a0a-9b0d-8094de28c350} -parentPid 6304 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6304" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 9 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3640C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3756"C:\Users\admin\Desktop\GenP_3.4.14.1_Reddit version\GenP-3.4.14.1.exe" C:\Users\admin\Desktop\GenP_3.4.14.1_Reddit version\GenP-3.4.14.1.exeexplorer.exe
User:
admin
Company:
GenP
Integrity Level:
MEDIUM
Description:
GenP v3.4.14.1
Exit code:
0
Version:
3.4.14.1
Modules
Images
c:\users\admin\desktop\genp_3.4.14.1_reddit version\genp-3.4.14.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
4048"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5200 -prefsLen 39068 -prefMapHandle 5204 -prefMapSize 272997 -jsInitHandle 5208 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5216 -initialChannelId {4a73cd2d-417a-4dd2-97a8-3e959a0c7674} -parentPid 6304 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6304" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 8 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
4060"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\wincorlib.dll
4120"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
4224"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3260 -prefsLen 36996 -prefMapHandle 3264 -prefMapSize 272997 -jsInitHandle 3268 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3200 -initialChannelId {64c83ead-bdfc-4194-ba90-94810e14cf98} -parentPid 6304 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6304" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
4400C:\Windows\System32\SystemSettingsBroker.exe -EmbeddingC:\Windows\System32\SystemSettingsBroker.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
System Settings Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\systemsettingsbroker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
Total events
19 699
Read events
19 626
Write events
59
Delete events
14

Modification events

(PID) Process:(5436) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(5436) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(5436) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(5436) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\GenP_3.4.14.1_Reddit version.rar
(PID) Process:(5436) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5436) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5436) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5436) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6748) GenP-3.4.14.1.exeKey:HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{F02C1A0D-BE21-4350-88B0-7367FC96EF3C} {000214E6-0000-0000-C000-000000000046} 0xFFFF
Value:
01000000000000007C590794942CDC01
(PID) Process:(6748) GenP-3.4.14.1.exeKey:HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF
Value:
0100000000000000B6BE0994942CDC01
Executable files
7
Suspicious files
230
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
6748GenP-3.4.14.1.exeC:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.dll.bak
MD5:
SHA256:
6748GenP-3.4.14.1.exeC:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.dll
MD5:
SHA256:
5436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5436.7371\GenP_3.4.14.1_Reddit version\GenP-3.4.14.1.exeexecutable
MD5:5AA73CE6297B35AAC0067529A47B44C5
SHA256:3BDDB83344219A07A43E53F68A0F6920FDD51B7412540D0DAAEAC353B6AB11A2
5436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5436.7371\GenP_3.4.14.1_Reddit version\config.initext
MD5:7AB47E11F3C18CE69BCC342D97A05493
SHA256:BE225C52F378DBB8D7638AB7C8BF19F4313AFE7D15C2D364B24A84592B34C181
5436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5436.7371\GenP_3.4.14.1_Reddit version\SOURCE\NSudoLG.exeexecutable
MD5:7AACFD85B8DFF0AA6867BEDE82CFD147
SHA256:871E4F28FE39BCAD8D295AE46E148BE458778C0195ED660B7DB18EB595D00BD8
5436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5436.7371\GenP_3.4.14.1_Reddit version\SOURCE\ICONS\Logo.icoimage
MD5:C383035A57C2E7A39803F71096011CA6
SHA256:71DE01801146E8DBE1EA5771A80B5F8E39693A58AD12987022DDE335B9D7CA86
5436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5436.7371\GenP_3.4.14.1_Reddit version\SOURCE\config.initext
MD5:ADD427035968BC6F8BCDF0C5D7580495
SHA256:66232A4D8677CD50612EAEBC664B2F2F3556B497D5BF8657967C259EF4723B68
5436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5436.7371\GenP_3.4.14.1_Reddit version\SOURCE\COMPILE.txttext
MD5:B089647B4BFE6964655CB784D4F1AE38
SHA256:87B24B13BAA368A62E7F5E377BFA1551CCE0BB2224AA350309F571C24452AC30
5436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5436.7371\GenP_3.4.14.1_Reddit version\SOURCE\GenP-3.4.14.1.au3text
MD5:42C434F0A040132E37EDDB5B1D886F8E
SHA256:3DD6CF96E38768110C8F0E64AE8C698E43931FF9FB57B4A1476B63F4E5D45554
5436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5436.7371\GenP_3.4.14.1_Reddit version\SOURCE\README.txttext
MD5:7C8C065A6D1563CCE7A73C3D3FA66FAE
SHA256:4AE4BC30641801C603C0EB36B2DDFC06081B91CF2E614E6565F489187EF1B027
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
62
DNS requests
81
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.55.110.193:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
2880
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
2880
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
407 b
whitelisted
2880
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
NL
binary
814 b
whitelisted
2880
SIHClient.exe
GET
200
23.216.77.25:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
DE
binary
824 b
whitelisted
2880
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl
NL
binary
400 b
whitelisted
2880
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl
NL
binary
813 b
whitelisted
2880
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.1.crl
NL
binary
401 b
whitelisted
2940
svchost.exe
GET
200
23.40.125.39:80
http://x1.c.lencr.org/
SE
binary
734 b
whitelisted
6304
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
US
text
90 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2432
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2704
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2704
svchost.exe
23.196.96.159:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.55.110.193:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
login.live.com
  • 20.190.160.130
  • 40.126.32.134
  • 40.126.32.140
  • 40.126.32.138
  • 20.190.160.132
  • 40.126.32.68
  • 40.126.32.133
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 23.196.96.159
whitelisted
crl.microsoft.com
  • 23.55.110.193
  • 23.55.110.211
  • 23.216.77.25
  • 23.216.77.36
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 135.232.92.137
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
self.events.data.microsoft.com
  • 51.132.193.104
whitelisted

Threats

No threats detected
No debug info