File name:

aic8800FC_windows_wifi_driver.exe

Full analysis: https://app.any.run/tasks/71cf8cd0-48aa-4f2f-8cda-a48d255e2977
Verdict: Malicious activity
Analysis date: August 06, 2024, 15:07:16
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B8A3CCE70163D2E1BF8FF299D88481F5

SHA1:

82EEE15C8DA2A7634FE679E148C7E9EA777BC20A

SHA256:

F26F6213B507C2D87A0C574C5C5CBEC32F3A17EB339019B7CEA512D87AB45573

SSDEEP:

49152:qBuZrEUgxQNp/+7MRscBjbhRJIbR31a3cgN3eognTJUU5D4YFvh:MkLgxQKoRscB9qR31asUZaCU5ECp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • aic8800FC_windows_wifi_driver.exe (PID: 6496)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • aic8800FC_windows_wifi_driver.exe (PID: 6496)
      • aic8800FC_windows_wifi_driver.exe (PID: 6604)
      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
      • drvinst.exe (PID: 6940)
      • DPInst64.exe (PID: 6740)
    • Reads security settings of Internet Explorer

      • aic8800FC_windows_wifi_driver.tmp (PID: 6516)
    • Reads the date of Windows installation

      • aic8800FC_windows_wifi_driver.tmp (PID: 6516)
    • Reads the Windows owner or organization settings

      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
    • Drops a system driver (possible attempt to evade defenses)

      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
      • DPInst64.exe (PID: 6740)
      • drvinst.exe (PID: 6940)
    • Creates files in the driver directory

      • drvinst.exe (PID: 6940)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 6940)
    • Executes as Windows Service

      • AicWifiService.exe (PID: 7120)
    • Creates file in the systems drive root

      • AicWifiService.exe (PID: 7120)
  • INFO

    • Checks supported languages

      • aic8800FC_windows_wifi_driver.tmp (PID: 6516)
      • aic8800FC_windows_wifi_driver.exe (PID: 6496)
      • aic8800FC_windows_wifi_driver.exe (PID: 6604)
      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
      • DPInst64.exe (PID: 6740)
      • drvinst.exe (PID: 6940)
      • AicWifiService.exe (PID: 7120)
      • DPInst64.exe (PID: 7112)
      • DPInst64.exe (PID: 6352)
      • devcon.exe (PID: 6436)
    • Reads the computer name

      • aic8800FC_windows_wifi_driver.tmp (PID: 6516)
      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
      • DPInst64.exe (PID: 6740)
      • drvinst.exe (PID: 6940)
      • DPInst64.exe (PID: 7112)
      • DPInst64.exe (PID: 6352)
      • AicWifiService.exe (PID: 7120)
    • Create files in a temporary directory

      • aic8800FC_windows_wifi_driver.exe (PID: 6604)
      • aic8800FC_windows_wifi_driver.exe (PID: 6496)
      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
      • DPInst64.exe (PID: 6740)
    • Process checks computer location settings

      • aic8800FC_windows_wifi_driver.tmp (PID: 6516)
    • Creates files in the program directory

      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
    • Reads Environment values

      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
    • Creates a software uninstall entry

      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 6940)
    • Reads the software policy settings

      • drvinst.exe (PID: 6940)
    • Manual execution by a user

      • DPInst64.exe (PID: 1132)
      • DPInst64.exe (PID: 7112)
      • DPInst64.exe (PID: 6352)
      • DevManView.exe (PID: 3972)
      • DevManView.exe (PID: 5140)
      • DPInst64.exe (PID: 2248)
    • NirSoft software is detected

      • DevManView.exe (PID: 3972)
      • DevManView.exe (PID: 5140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 40960
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: AIC
FileDescription: aic8800FC_windows_wifi_driver Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: aic8800FC_windows_wifi_driver
ProductVersion: 1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
22
Malicious processes
3
Suspicious processes
4

Behavior graph

Click at the process to see the details
start aic8800fc_windows_wifi_driver.exe aic8800fc_windows_wifi_driver.tmp no specs aic8800fc_windows_wifi_driver.exe aic8800fc_windows_wifi_driver.tmp dpinst64.exe drvinst.exe sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs aicwifiservice.exe no specs sc.exe no specs conhost.exe no specs devcon.exe no specs conhost.exe no specs rundll32.exe no specs dpinst64.exe no specs dpinst64.exe dpinst64.exe no specs dpinst64.exe devmanview.exe no specs devmanview.exe

Process information

PID
CMD
Path
Indicators
Parent process
1132"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exe" C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Driver Package Installer
Exit code:
3221226540
Version:
2.1
Modules
Images
c:\program files (x86)\aic8800fc_windows_wifi_driver\win10_x64\dpinst64.exe
c:\windows\system32\ntdll.dll
2248"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exe" C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Driver Package Installer
Exit code:
3221226540
Version:
2.1
Modules
Images
c:\program files (x86)\aic8800fc_windows_wifi_driver\win10_x64\dpinst64.exe
c:\windows\system32\ntdll.dll
3972"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\DevManView.exe" C:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\DevManView.exeexplorer.exe
User:
admin
Company:
NirSoft
Integrity Level:
MEDIUM
Description:
DevManView
Exit code:
3221226540
Version:
1.77
5140"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\DevManView.exe" C:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\DevManView.exe
explorer.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
DevManView
Version:
1.77
6320"C:\WINDOWS\system32\sc.exe" failure AicWifiService reset= 3600 actions=restart/60000/restart/120000/restart/120000C:\Windows\SysWOW64\sc.exeaic8800FC_windows_wifi_driver.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6352"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exe" C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\program files (x86)\aic8800fc_windows_wifi_driver\win10_x64\dpinst64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6376\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6380\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exedevcon.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6436"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\devcon.exe" /rescanC:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\devcon.exeaic8800FC_windows_wifi_driver.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Device Console
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\program files (x86)\aic8800fc_windows_wifi_driver\tool\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6496"C:\Users\admin\AppData\Local\Temp\aic8800FC_windows_wifi_driver.exe" C:\Users\admin\AppData\Local\Temp\aic8800FC_windows_wifi_driver.exe
explorer.exe
User:
admin
Company:
AIC
Integrity Level:
MEDIUM
Description:
aic8800FC_windows_wifi_driver Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\aic8800fc_windows_wifi_driver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
9 021
Read events
8 982
Write events
33
Delete events
6

Modification events

(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
E4190000050F895C12E8DA01
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
3924374A362E0FF40F1D9C0E5576FD6BDE3EC51F7BB7E902B4B4B63275FCF865
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x64\DPInst64.exe
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
EE4EA025C93265E266B4530719DCADDA3714AD034D92EBAC4058D66FDB7C1841
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9728BC4C-A4CB-470A-B1EA-FB98D8BED1C0}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.1
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9728BC4C-A4CB-470A-B1EA-FB98D8BED1C0}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\aic8800FC_windows_wifi_driver
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9728BC4C-A4CB-470A-B1EA-FB98D8BED1C0}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\aic8800FC_windows_wifi_driver\
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9728BC4C-A4CB-470A-B1EA-FB98D8BED1C0}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
aic8800FC_windows_wifi_driver
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9728BC4C-A4CB-470A-B1EA-FB98D8BED1C0}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
31
Suspicious files
13
Text files
8
Unknown types
14

Dropped files

PID
Process
Filename
Type
6628aic8800FC_windows_wifi_driver.tmpC:\Users\admin\AppData\Local\Temp\is-OAOOE.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x64\aicusbwifi.sysexecutable
MD5:84413D614C7FC00DF383B10933D1EAD2
SHA256:84EE1652BE43EB2138781FD52FA223D05BB4B6FF5741FD1E2C571FE694381374
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x86\aicusbwifi.catcat
MD5:6FD5EBCD1286D867A39439BDB7C14663
SHA256:1ABCDBC25F4AF8B67369576CEA8C40E61707A4B6EB7EBF82F76EDB0617504F82
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x64\is-3G98G.tmpexecutable
MD5:25D0A711E33C75B197D76884DBA1DBF1
SHA256:B6BAE3BB8FE8DEE5DB004965BBEA0466BAB7BB4B4193E8FA544ABF47F03562A5
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x86\is-RVDUL.tmpcat
MD5:6FD5EBCD1286D867A39439BDB7C14663
SHA256:1ABCDBC25F4AF8B67369576CEA8C40E61707A4B6EB7EBF82F76EDB0617504F82
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x64\DPInst64.exeexecutable
MD5:25D0A711E33C75B197D76884DBA1DBF1
SHA256:B6BAE3BB8FE8DEE5DB004965BBEA0466BAB7BB4B4193E8FA544ABF47F03562A5
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x86\aicusbwifi.infbinary
MD5:18617155006A77CCE8C8126FB0004D5D
SHA256:6A71B51EB186B7C796C3D5175C1F374E4A227C6D5B566AB79159505ECEA60007
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x86\is-OVG6P.tmpbinary
MD5:18617155006A77CCE8C8126FB0004D5D
SHA256:6A71B51EB186B7C796C3D5175C1F374E4A227C6D5B566AB79159505ECEA60007
6496aic8800FC_windows_wifi_driver.exeC:\Users\admin\AppData\Local\Temp\is-IV4FD.tmp\aic8800FC_windows_wifi_driver.tmpexecutable
MD5:B9718CCC1BBF8345F784907172F60E86
SHA256:EE079CF21E4340393727A4ABE86D73967E7D4E283A92C88FB358AFAD67B80967
6604aic8800FC_windows_wifi_driver.exeC:\Users\admin\AppData\Local\Temp\is-M90GM.tmp\aic8800FC_windows_wifi_driver.tmpexecutable
MD5:B9718CCC1BBF8345F784907172F60E86
SHA256:EE079CF21E4340393727A4ABE86D73967E7D4E283A92C88FB358AFAD67B80967
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
37
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5212
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5212
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5992
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3144
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5044
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
unknown
4088
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
unknown
4
System
192.168.100.255:137
unknown
5044
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5336
SearchApp.exe
92.123.104.67:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
unknown
google.com
  • 142.250.185.142
unknown
www.bing.com
  • 92.123.104.67
  • 92.123.104.66
  • 92.123.104.62
  • 92.123.104.58
  • 92.123.104.61
  • 92.123.104.53
  • 92.123.104.65
  • 92.123.104.54
  • 92.123.104.59
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
client.wns.windows.com
  • 40.113.110.67
unknown
login.live.com
  • 40.126.32.136
  • 20.190.160.22
  • 40.126.32.76
  • 40.126.32.133
  • 40.126.32.138
  • 20.190.160.14
  • 20.190.160.17
  • 40.126.32.74
unknown
th.bing.com
  • 92.123.104.60
  • 92.123.104.65
  • 92.123.104.53
  • 92.123.104.61
  • 92.123.104.52
  • 92.123.104.63
  • 92.123.104.64
  • 92.123.104.59
  • 92.123.104.58
unknown
fd.api.iris.microsoft.com
  • 20.31.169.57
unknown
arc.msn.com
  • 20.103.156.88
unknown
slscr.update.microsoft.com
  • 40.127.169.103
unknown

Threats

No threats detected
No debug info