File name:

aic8800FC_windows_wifi_driver.exe

Full analysis: https://app.any.run/tasks/71cf8cd0-48aa-4f2f-8cda-a48d255e2977
Verdict: Malicious activity
Analysis date: August 06, 2024, 15:07:16
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B8A3CCE70163D2E1BF8FF299D88481F5

SHA1:

82EEE15C8DA2A7634FE679E148C7E9EA777BC20A

SHA256:

F26F6213B507C2D87A0C574C5C5CBEC32F3A17EB339019B7CEA512D87AB45573

SSDEEP:

49152:qBuZrEUgxQNp/+7MRscBjbhRJIbR31a3cgN3eognTJUU5D4YFvh:MkLgxQKoRscB9qR31asUZaCU5ECp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • aic8800FC_windows_wifi_driver.exe (PID: 6496)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
    • Executable content was dropped or overwritten

      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
      • aic8800FC_windows_wifi_driver.exe (PID: 6604)
      • aic8800FC_windows_wifi_driver.exe (PID: 6496)
      • DPInst64.exe (PID: 6740)
      • drvinst.exe (PID: 6940)
    • Reads the date of Windows installation

      • aic8800FC_windows_wifi_driver.tmp (PID: 6516)
    • Reads security settings of Internet Explorer

      • aic8800FC_windows_wifi_driver.tmp (PID: 6516)
    • Drops a system driver (possible attempt to evade defenses)

      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
      • drvinst.exe (PID: 6940)
      • DPInst64.exe (PID: 6740)
    • Creates file in the systems drive root

      • AicWifiService.exe (PID: 7120)
    • Creates files in the driver directory

      • drvinst.exe (PID: 6940)
    • Executes as Windows Service

      • AicWifiService.exe (PID: 7120)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 6940)
  • INFO

    • Checks supported languages

      • aic8800FC_windows_wifi_driver.exe (PID: 6496)
      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
      • aic8800FC_windows_wifi_driver.exe (PID: 6604)
      • aic8800FC_windows_wifi_driver.tmp (PID: 6516)
      • DPInst64.exe (PID: 6740)
      • drvinst.exe (PID: 6940)
      • AicWifiService.exe (PID: 7120)
      • devcon.exe (PID: 6436)
      • DPInst64.exe (PID: 6352)
      • DPInst64.exe (PID: 7112)
    • Reads the computer name

      • aic8800FC_windows_wifi_driver.tmp (PID: 6516)
      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
      • DPInst64.exe (PID: 6740)
      • AicWifiService.exe (PID: 7120)
      • DPInst64.exe (PID: 6352)
      • DPInst64.exe (PID: 7112)
      • drvinst.exe (PID: 6940)
    • Create files in a temporary directory

      • aic8800FC_windows_wifi_driver.exe (PID: 6496)
      • aic8800FC_windows_wifi_driver.exe (PID: 6604)
      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
      • DPInst64.exe (PID: 6740)
    • Creates files in the program directory

      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
    • Process checks computer location settings

      • aic8800FC_windows_wifi_driver.tmp (PID: 6516)
    • Reads Environment values

      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
    • Reads the software policy settings

      • drvinst.exe (PID: 6940)
    • Manual execution by a user

      • DPInst64.exe (PID: 2248)
      • DPInst64.exe (PID: 1132)
      • DevManView.exe (PID: 5140)
      • DPInst64.exe (PID: 7112)
      • DPInst64.exe (PID: 6352)
      • DevManView.exe (PID: 3972)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 6940)
    • Creates a software uninstall entry

      • aic8800FC_windows_wifi_driver.tmp (PID: 6628)
    • NirSoft software is detected

      • DevManView.exe (PID: 3972)
      • DevManView.exe (PID: 5140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 40960
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: AIC
FileDescription: aic8800FC_windows_wifi_driver Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: aic8800FC_windows_wifi_driver
ProductVersion: 1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
22
Malicious processes
3
Suspicious processes
4

Behavior graph

Click at the process to see the details
start aic8800fc_windows_wifi_driver.exe aic8800fc_windows_wifi_driver.tmp no specs aic8800fc_windows_wifi_driver.exe aic8800fc_windows_wifi_driver.tmp dpinst64.exe drvinst.exe sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs aicwifiservice.exe no specs sc.exe no specs conhost.exe no specs devcon.exe no specs conhost.exe no specs rundll32.exe no specs dpinst64.exe no specs dpinst64.exe dpinst64.exe no specs dpinst64.exe devmanview.exe no specs devmanview.exe

Process information

PID
CMD
Path
Indicators
Parent process
1132"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exe" C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Driver Package Installer
Exit code:
3221226540
Version:
2.1
Modules
Images
c:\program files (x86)\aic8800fc_windows_wifi_driver\win10_x64\dpinst64.exe
c:\windows\system32\ntdll.dll
2248"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exe" C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Driver Package Installer
Exit code:
3221226540
Version:
2.1
Modules
Images
c:\program files (x86)\aic8800fc_windows_wifi_driver\win10_x64\dpinst64.exe
c:\windows\system32\ntdll.dll
3972"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\DevManView.exe" C:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\DevManView.exeexplorer.exe
User:
admin
Company:
NirSoft
Integrity Level:
MEDIUM
Description:
DevManView
Exit code:
3221226540
Version:
1.77
5140"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\DevManView.exe" C:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\DevManView.exe
explorer.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
DevManView
Version:
1.77
6320"C:\WINDOWS\system32\sc.exe" failure AicWifiService reset= 3600 actions=restart/60000/restart/120000/restart/120000C:\Windows\SysWOW64\sc.exeaic8800FC_windows_wifi_driver.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6352"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exe" C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win10_x64\DPInst64.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\program files (x86)\aic8800fc_windows_wifi_driver\win10_x64\dpinst64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6376\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6380\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exedevcon.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6436"C:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\devcon.exe" /rescanC:\Program Files (x86)\aic8800FC_windows_wifi_driver\tool\devcon.exeaic8800FC_windows_wifi_driver.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Device Console
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\program files (x86)\aic8800fc_windows_wifi_driver\tool\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6496"C:\Users\admin\AppData\Local\Temp\aic8800FC_windows_wifi_driver.exe" C:\Users\admin\AppData\Local\Temp\aic8800FC_windows_wifi_driver.exe
explorer.exe
User:
admin
Company:
AIC
Integrity Level:
MEDIUM
Description:
aic8800FC_windows_wifi_driver Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\aic8800fc_windows_wifi_driver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
9 021
Read events
8 982
Write events
33
Delete events
6

Modification events

(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
E4190000050F895C12E8DA01
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
3924374A362E0FF40F1D9C0E5576FD6BDE3EC51F7BB7E902B4B4B63275FCF865
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x64\DPInst64.exe
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
EE4EA025C93265E266B4530719DCADDA3714AD034D92EBAC4058D66FDB7C1841
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9728BC4C-A4CB-470A-B1EA-FB98D8BED1C0}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.1
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9728BC4C-A4CB-470A-B1EA-FB98D8BED1C0}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\aic8800FC_windows_wifi_driver
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9728BC4C-A4CB-470A-B1EA-FB98D8BED1C0}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\aic8800FC_windows_wifi_driver\
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9728BC4C-A4CB-470A-B1EA-FB98D8BED1C0}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
aic8800FC_windows_wifi_driver
(PID) Process:(6628) aic8800FC_windows_wifi_driver.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9728BC4C-A4CB-470A-B1EA-FB98D8BED1C0}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
31
Suspicious files
13
Text files
8
Unknown types
14

Dropped files

PID
Process
Filename
Type
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x64\is-MCP2G.tmpexecutable
MD5:84413D614C7FC00DF383B10933D1EAD2
SHA256:84EE1652BE43EB2138781FD52FA223D05BB4B6FF5741FD1E2C571FE694381374
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x64\is-ACFT5.tmpbinary
MD5:9A7EB91A7A82E67EECE2443528B21952
SHA256:CEEF43D2C483B9A3EB13A91A7C220E0DA80B3D86EE97D33C1BC946355FC72F91
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\unins000.exeexecutable
MD5:777CD0397AEE015C5B83C1836DA8150B
SHA256:3EDDBA2A6913E7C7D01B2BC889E30CB1B8850E776BE9CF88725E3CEC8B51909F
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\is-5DTV2.tmpexecutable
MD5:777CD0397AEE015C5B83C1836DA8150B
SHA256:3EDDBA2A6913E7C7D01B2BC889E30CB1B8850E776BE9CF88725E3CEC8B51909F
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x64\aicusbwifi.catcat
MD5:56AC913C23313FF19CD0E098D36373F0
SHA256:2CE9A9E47E44704032FC0BB7269A854956AF1EDB7C38669878B5258D4E607E14
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x86\aicusbwifi.sysexecutable
MD5:7A400A4E7B734E8D6EF9FDF711375DA1
SHA256:F05076A50A0506E6ED53F45760B741AD7608AB906E8BAD5BEA174D7ADD54C809
6604aic8800FC_windows_wifi_driver.exeC:\Users\admin\AppData\Local\Temp\is-M90GM.tmp\aic8800FC_windows_wifi_driver.tmpexecutable
MD5:B9718CCC1BBF8345F784907172F60E86
SHA256:EE079CF21E4340393727A4ABE86D73967E7D4E283A92C88FB358AFAD67B80967
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x86\aicusbwifi.infbinary
MD5:18617155006A77CCE8C8126FB0004D5D
SHA256:6A71B51EB186B7C796C3D5175C1F374E4A227C6D5B566AB79159505ECEA60007
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x86\is-OVG6P.tmpbinary
MD5:18617155006A77CCE8C8126FB0004D5D
SHA256:6A71B51EB186B7C796C3D5175C1F374E4A227C6D5B566AB79159505ECEA60007
6628aic8800FC_windows_wifi_driver.tmpC:\Program Files (x86)\aic8800FC_windows_wifi_driver\win7_x86\is-OK570.tmpexecutable
MD5:3FD16C1CCA83D9F0E91FCCFE32D812D0
SHA256:0AF038B08F84604D2805202B5429210C5EF37F23623B8DAE2BD8921E4E76A0C8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
37
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5212
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5212
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5992
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3144
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5044
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
unknown
4088
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
unknown
4
System
192.168.100.255:137
unknown
5044
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5336
SearchApp.exe
92.123.104.67:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
unknown
google.com
  • 142.250.185.142
unknown
www.bing.com
  • 92.123.104.67
  • 92.123.104.66
  • 92.123.104.62
  • 92.123.104.58
  • 92.123.104.61
  • 92.123.104.53
  • 92.123.104.65
  • 92.123.104.54
  • 92.123.104.59
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
client.wns.windows.com
  • 40.113.110.67
unknown
login.live.com
  • 40.126.32.136
  • 20.190.160.22
  • 40.126.32.76
  • 40.126.32.133
  • 40.126.32.138
  • 20.190.160.14
  • 20.190.160.17
  • 40.126.32.74
unknown
th.bing.com
  • 92.123.104.60
  • 92.123.104.65
  • 92.123.104.53
  • 92.123.104.61
  • 92.123.104.52
  • 92.123.104.63
  • 92.123.104.64
  • 92.123.104.59
  • 92.123.104.58
unknown
fd.api.iris.microsoft.com
  • 20.31.169.57
unknown
arc.msn.com
  • 20.103.156.88
unknown
slscr.update.microsoft.com
  • 40.127.169.103
unknown

Threats

No threats detected
No debug info