File name:

inteltcss.1.0.2-installer.exe

Full analysis: https://app.any.run/tasks/48368a7a-5998-452c-a475-b5146ec5b564
Verdict: Malicious activity
Analysis date: May 17, 2025, 16:51:31
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

5E9F48B2F060C6E14D6045418DCBD12C

SHA1:

F65B7587131F61680E15E0EEE39353B552C88323

SHA256:

F29543F4300A533522A9F696856BC31A809E49954FFC7F43AAC5F375848DF75B

SSDEEP:

24576:aRyFUHybNprZpOzBLO8t+5mDpg2Fnm1fZhQ6SiayKJfvnplJI:KyFUHybNprvOzZO8t+5mDpg2Fnm1f/Qw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • inteltcss.1.0.2-installer.exe (PID: 7516)
    • Executable content was dropped or overwritten

      • inteltcss.1.0.2-installer.exe (PID: 7516)
      • drvinst.exe (PID: 7984)
      • dpinst.exe (PID: 7884)
      • dpinst.exe (PID: 8132)
      • drvinst.exe (PID: 8160)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • inteltcss.1.0.2-installer.exe (PID: 7516)
    • Process drops legitimate windows executable

      • inteltcss.1.0.2-installer.exe (PID: 7516)
      • dpinst.exe (PID: 7884)
    • Drops a system driver (possible attempt to evade defenses)

      • inteltcss.1.0.2-installer.exe (PID: 7516)
      • dpinst.exe (PID: 7884)
      • drvinst.exe (PID: 7984)
      • dpinst.exe (PID: 8132)
      • drvinst.exe (PID: 8160)
    • Creates files in the driver directory

      • drvinst.exe (PID: 7984)
      • drvinst.exe (PID: 8160)
    • Creates a software uninstall entry

      • dpinst.exe (PID: 7884)
      • dpinst.exe (PID: 8132)
    • The process executes via Task Scheduler

      • mmc.exe (PID: 6724)
  • INFO

    • Checks supported languages

      • inteltcss.1.0.2-installer.exe (PID: 7516)
      • dpinst.exe (PID: 7884)
      • drvinst.exe (PID: 7984)
      • dpinst.exe (PID: 8132)
      • drvinst.exe (PID: 8160)
    • Create files in a temporary directory

      • inteltcss.1.0.2-installer.exe (PID: 7516)
      • dpinst.exe (PID: 7884)
      • dpinst.exe (PID: 8132)
    • Reads the computer name

      • inteltcss.1.0.2-installer.exe (PID: 7516)
      • dpinst.exe (PID: 7884)
      • drvinst.exe (PID: 7984)
      • dpinst.exe (PID: 8132)
      • drvinst.exe (PID: 8160)
    • Creates files in the program directory

      • inteltcss.1.0.2-installer.exe (PID: 7516)
      • dpinst.exe (PID: 7884)
    • The sample compiled with arabic language support

      • inteltcss.1.0.2-installer.exe (PID: 7516)
      • dpinst.exe (PID: 7884)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 7984)
      • dpinst.exe (PID: 7884)
      • drvinst.exe (PID: 8160)
      • dpinst.exe (PID: 8132)
    • Reads the software policy settings

      • drvinst.exe (PID: 7984)
      • dpinst.exe (PID: 7884)
      • drvinst.exe (PID: 8160)
      • dpinst.exe (PID: 8132)
    • Reads security settings of Internet Explorer

      • mmc.exe (PID: 6724)
    • Manual execution by a user

      • WINWORD.EXE (PID: 6132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:57:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 186880
UninitializedDataSize: 2048
EntryPoint: 0x352d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
13
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start inteltcss.1.0.2-installer.exe sppextcomobj.exe no specs slui.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe COpenControlPanel no specs mmc.exe winword.exe ai.exe no specs slui.exe no specs inteltcss.1.0.2-installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2516C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3156"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "13EF369A-2A1C-41C8-9E67-18AD356BBAC2" "A523AAEC-1299-426A-9A36-E78BAAE1931C" "6132"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exeWINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64.
Version:
0.12.2.0
Modules
Images
c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\common files\microsoft shared\clicktorun\c2r64.dll
6132"C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\admin\Desktop\worthrole.rtf" /o ""C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6724"C:\WINDOWS\system32\mmc.exe" C:\WINDOWS\system32\devmgmt.mscC:\Windows\System32\mmc.exe
RuntimeBroker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Management Console
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mmc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7424"C:\Users\admin\Downloads\inteltcss.1.0.2-installer.exe" C:\Users\admin\Downloads\inteltcss.1.0.2-installer.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\inteltcss.1.0.2-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7508C:\WINDOWS\SysWOW64\DllHost.exe /Processid:{06622D85-6856-4460-8DE1-A81921B41C4B}C:\Windows\SysWOW64\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ucrtbase.dll
c:\windows\syswow64\combase.dll
7516"C:\Users\admin\Downloads\inteltcss.1.0.2-installer.exe" C:\Users\admin\Downloads\inteltcss.1.0.2-installer.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\downloads\inteltcss.1.0.2-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7576C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7608"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7884"C:\Program Files\inteltcss\drivers\dpinst.exe" /sw /f /path "C:\Program Files\inteltcss\drivers\intelpmc"C:\Program Files\inteltcss\drivers\dpinst.exe
inteltcss.1.0.2-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\program files\inteltcss\drivers\dpinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
27 232
Read events
26 860
Write events
349
Delete events
23

Modification events

(PID) Process:(7884) dpinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(7884) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\6B1A77C85212509D1C759B940EC55E4308926459
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe /u C:\WINDOWS\System32\DriverStore\FileRepository\intelpmc.inf_amd64_a07b123d916060eb\intelpmc.inf
(PID) Process:(7884) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\6B1A77C85212509D1C759B940EC55E4308926459
Operation:writeName:DisplayName
Value:
Windows Driver Package - CoolStar (intelpmc) System (04/22/2024 1.0.1.0)
(PID) Process:(7884) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\6B1A77C85212509D1C759B940EC55E4308926459
Operation:writeName:DisplayIcon
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe,0
(PID) Process:(7884) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\6B1A77C85212509D1C759B940EC55E4308926459
Operation:writeName:DisplayVersion
Value:
04/22/2024 1.0.1.0
(PID) Process:(7884) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\6B1A77C85212509D1C759B940EC55E4308926459
Operation:writeName:Publisher
Value:
CoolStar
(PID) Process:(8132) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\38C408EEF5D93B010C43A3349C32DF2DC4E409B0
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe /u C:\WINDOWS\System32\DriverStore\FileRepository\inteltcss.inf_amd64_3d152c82c9d341f0\inteltcss.inf
(PID) Process:(8132) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\38C408EEF5D93B010C43A3349C32DF2DC4E409B0
Operation:writeName:DisplayName
Value:
Windows Driver Package - CoolStar (inteltcss) USB (04/17/2024 1.0.1.0)
(PID) Process:(8132) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\38C408EEF5D93B010C43A3349C32DF2DC4E409B0
Operation:writeName:DisplayIcon
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe,0
(PID) Process:(8132) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\38C408EEF5D93B010C43A3349C32DF2DC4E409B0
Operation:writeName:DisplayVersion
Value:
04/17/2024 1.0.1.0
Executable files
47
Suspicious files
164
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
7884dpinst.exeC:\Users\admin\AppData\Local\Temp\{94f08c6f-aca6-fb48-9f10-90fffdd6ec5d}\SETCAA7.tmpexecutable
MD5:276BCB7637488A24099E4522E562B1FB
SHA256:0C155FDB7FF6E680EAC57048AC922843D226A02A98AB1772692644D9019F1F53
7516inteltcss.1.0.2-installer.exeC:\Program Files\inteltcss\drivers\intelpmc\intelpmc.catbinary
MD5:EE36D5B3ECAD1337B252D000EE0C4DFE
SHA256:CF3F390C1D609340EBBEFA54BEA9250374C11A475439D623BB739C9312211B32
7884dpinst.exeC:\Users\admin\AppData\Local\Temp\{94f08c6f-aca6-fb48-9f10-90fffdd6ec5d}\intelpmc.sysexecutable
MD5:276BCB7637488A24099E4522E562B1FB
SHA256:0C155FDB7FF6E680EAC57048AC922843D226A02A98AB1772692644D9019F1F53
7516inteltcss.1.0.2-installer.exeC:\Program Files\inteltcss\drivers\dpinst.exeexecutable
MD5:4192A5B905374E423EC1E545599AA86E
SHA256:567F40A09F1D9E72396296AD194FA7CF48B72361D6E259D6B99DA774C2CD8981
7516inteltcss.1.0.2-installer.exeC:\Users\admin\AppData\Local\Temp\nszB51A.tmp\System.dllexecutable
MD5:CFF85C549D536F651D4FB8387F1976F2
SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
7984drvinst.exeC:\Windows\System32\DriverStore\Temp\{8d2e27fc-4680-0a4c-a54c-23044d3f5633}\SETCAF3.tmpbinary
MD5:EE36D5B3ECAD1337B252D000EE0C4DFE
SHA256:CF3F390C1D609340EBBEFA54BEA9250374C11A475439D623BB739C9312211B32
7984drvinst.exeC:\Windows\System32\DriverStore\Temp\{8d2e27fc-4680-0a4c-a54c-23044d3f5633}\SETCAF4.tmpbinary
MD5:8BB9A736A427002694D9670A2045FB0E
SHA256:0A93E47C38A6997EE82290B0EBDA9EBFD0CE67837E9E0E09DB0CC21B6790D6BB
7884dpinst.exeC:\Users\admin\AppData\Local\Temp\{94f08c6f-aca6-fb48-9f10-90fffdd6ec5d}\SETCA95.tmpbinary
MD5:EE36D5B3ECAD1337B252D000EE0C4DFE
SHA256:CF3F390C1D609340EBBEFA54BEA9250374C11A475439D623BB739C9312211B32
7884dpinst.exeC:\Users\admin\AppData\Local\Temp\{94f08c6f-aca6-fb48-9f10-90fffdd6ec5d}\intelpmc.infbinary
MD5:8BB9A736A427002694D9670A2045FB0E
SHA256:0A93E47C38A6997EE82290B0EBDA9EBFD0CE67837E9E0E09DB0CC21B6790D6BB
7884dpinst.exeC:\Users\admin\AppData\Local\Temp\{94f08c6f-aca6-fb48-9f10-90fffdd6ec5d}\intelpmc.catbinary
MD5:EE36D5B3ECAD1337B252D000EE0C4DFE
SHA256:CF3F390C1D609340EBBEFA54BEA9250374C11A475439D623BB739C9312211B32
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
70
DNS requests
32
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.41:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
672
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
672
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6132
WINWORD.EXE
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6132
WINWORD.EXE
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6132
WINWORD.EXE
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
23.216.77.41:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2924
SearchApp.exe
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.41
  • 23.216.77.6
  • 23.216.77.11
  • 23.216.77.43
  • 23.216.77.31
  • 23.216.77.5
  • 23.216.77.32
  • 23.216.77.37
  • 23.216.77.13
  • 2.19.11.105
  • 2.19.11.120
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 2.23.246.101
whitelisted
google.com
  • 142.250.185.142
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.140
  • 40.126.32.133
  • 20.190.160.66
  • 20.190.160.2
  • 40.126.32.138
  • 20.190.160.14
  • 20.190.160.5
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
whitelisted
fp.msedge.net
  • 204.79.197.222
whitelisted
th.bing.com
  • 2.23.227.215
  • 2.23.227.208
whitelisted

Threats

No threats detected
No debug info