File name:

zapret_build-main.zip

Full analysis: https://app.any.run/tasks/1431a98c-5101-48d5-8b51-a8d7250b31ed
Verdict: Malicious activity
Analysis date: November 11, 2024, 06:06:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-scr
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

A467443E9E20853672E3B47956F499DA

SHA1:

4EECE99169D716F695B84CD71A97AA6B60636DE0

SHA256:

F2E007E51A2284EAEAF17D63CF20839D6B9EA7742C152B37029A8590201A6259

SSDEEP:

98304:EcZGHlS70yrjpIBHxMwlsgecngos5qdkcjYcZ4v3UcbT2MJUKsL2z8n9poYTo3Nt:VUT7Q49YO93nbpRxjY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 608)
    • Detects Cygwin installation

      • WinRAR.exe (PID: 608)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 608)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 608)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 608)
    • UPX packer has been detected

      • winws.exe (PID: 5788)
    • Manual execution by a user

      • cmd.exe (PID: 5496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:10:08 13:06:40
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: zapret_build-main/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
12
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs cmd.exe no specs conhost.exe no specs winws.exe no specs winws.exe no specs THREAT winws.exe conhost.exe no specs winws.exe no specs winws.exe no specs winws.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
608"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\zapret_build-main.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
916"C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\winws.exe" --wf-tcp=443-65535 --wf-udp=443-65535 --filter-udp=443 --hostlist="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\list-discord.txt" --dpi-desync=fake --dpi-desync-udplen-increment=10 --dpi-desync-repeats=6 --dpi-desync-udplen-pattern=0xDEADBEEF --dpi-desync-fake-quic="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\quic_initial_www_google_com.bin" --new --filter-udp=50000-65535 --dpi-desync=fake,tamper --dpi-desync-any-protocol --dpi-desync-fake-quic="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\quic_initial_www_google_com.bin" --new --filter-tcp=443 --hostlist="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\list-discord.txt" --dpi-desync=fake,split2 --dpi-desync-autottl=2 --dpi-desync-fooling=md5sig --dpi-desync-fake-tls="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\tls_clienthello_www_google_com.bin"C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\winws.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\zapret_build-main\zapret\zapret-winws\winws.exe
c:\windows\system32\ntdll.dll
1572"C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\winws.exe" --wf-tcp=80,443 --wf-udp=443 --filter-udp=443 --hostlist="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\list-youtube.txt" --dpi-desync=fake --dpi-desync-repeats=11 --dpi-desync-fake-quic="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\quic_initial_www_google_com.bin" --new --filter-udp=443 --dpi-desync=fake --dpi-desync-repeats=11 --new --filter-tcp=80 --dpi-desync=fake,split2 --dpi-desync-autottl=2 --dpi-desync-fooling=md5sig --new --filter-tcp=443 --hostlist="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\list-youtube.txt" --dpi-desync=fake,split2 --dpi-desync-autottl=2 --dpi-desync-fooling=md5sig --dpi-desync-fake-tls="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\tls_clienthello_www_google_com.bin" --new --dpi-desync=fake,disorder2 --dpi-desync-autottl=2 --dpi-desync-fooling=md5sigC:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\winws.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\zapret_build-main\zapret\zapret-winws\winws.exe
c:\windows\system32\ntdll.dll
4304"C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\winws.exe" --wf-tcp=443-65535 --wf-udp=443-65535 --filter-udp=443 --hostlist="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\list-discord.txt" --dpi-desync=fake --dpi-desync-udplen-increment=10 --dpi-desync-repeats=6 --dpi-desync-udplen-pattern=0xDEADBEEF --dpi-desync-fake-quic="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\quic_initial_www_google_com.bin" --new --filter-udp=50000-65535 --dpi-desync=fake,tamper --dpi-desync-any-protocol --dpi-desync-fake-quic="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\quic_initial_www_google_com.bin" --new --filter-tcp=443 --hostlist="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\list-discord.txt" --dpi-desync=fake,split2 --dpi-desync-autottl=2 --dpi-desync-fooling=md5sig --dpi-desync-fake-tls="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\tls_clienthello_www_google_com.bin"C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\winws.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\zapret_build-main\zapret\zapret-winws\winws.exe
c:\windows\system32\ntdll.dll
4584\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4680\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exewinws.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5496C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\preset_russia+discord.cmd" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
5756"C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\winws.exe" --wf-tcp=80,443 --wf-udp=443 --filter-udp=443 --hostlist="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\list-youtube.txt" --dpi-desync=fake --dpi-desync-repeats=11 --dpi-desync-fake-quic="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\quic_initial_www_google_com.bin" --new --filter-udp=443 --dpi-desync=fake --dpi-desync-repeats=11 --new --filter-tcp=80 --dpi-desync=fake,split2 --dpi-desync-autottl=2 --dpi-desync-fooling=md5sig --new --filter-tcp=443 --hostlist="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\list-youtube.txt" --dpi-desync=fake,split2 --dpi-desync-autottl=2 --dpi-desync-fooling=md5sig --dpi-desync-fake-tls="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\tls_clienthello_www_google_com.bin" --new --dpi-desync=fake,disorder2 --dpi-desync-autottl=2 --dpi-desync-fooling=md5sigC:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\winws.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\zapret_build-main\zapret\zapret-winws\winws.exe
c:\windows\system32\ntdll.dll
5788"C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\winws.exe" --wf-tcp=443-65535 --wf-udp=443-65535 --filter-udp=443 --hostlist="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\list-discord.txt" --dpi-desync=fake --dpi-desync-udplen-increment=10 --dpi-desync-repeats=6 --dpi-desync-udplen-pattern=0xDEADBEEF --dpi-desync-fake-quic="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\quic_initial_www_google_com.bin" --new --filter-udp=50000-65535 --dpi-desync=fake,tamper --dpi-desync-any-protocol --dpi-desync-fake-quic="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\quic_initial_www_google_com.bin" --new --filter-tcp=443 --hostlist="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\list-discord.txt" --dpi-desync=fake,split2 --dpi-desync-autottl=2 --dpi-desync-fooling=md5sig --dpi-desync-fake-tls="C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\tls_clienthello_www_google_com.bin"C:\Users\admin\Desktop\zapret_build-main\zapret\zapret-winws\winws.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\zapret_build-main\zapret\zapret-winws\winws.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6208C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
Total events
2 131
Read events
2 110
Write events
21
Delete events
0

Modification events

(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\zapret_build-main.zip
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
147
Suspicious files
189
Text files
83
Unknown types
5

Dropped files

PID
Process
Filename
Type
608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa608.969\zapret_build-main\Start winws (preset_russia+discord).lnklnk
MD5:38F6F44A7296303298D5AA4AD1C301C8
SHA256:D0342D2035F4656153925D982802B69FE45C4268DA7854E7C232FBF44A9E0CB4
608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa608.969\zapret_build-main\zapret\blockcheck\blockcheck.cmdtext
MD5:C8F6CE2373AE8CFCBE070E8347FEC6B7
SHA256:C62021151E53F72DE851086CE377B13FF7BCE291D4D58BCC527CC2BE5DE6D697
608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa608.969\zapret_build-main\README.mdtext
MD5:ED875A3DD021A279A4EB2C53D07CC956
SHA256:977D500FE396F14F970D2482A6A5EC4EE4910F078F6E0804F93673855B89BF6C
608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa608.969\zapret_build-main\zapret\.gitattributestext
MD5:847ED55B058F99CA654DAA2F0363711A
SHA256:9CB902885C6862F5C4D719B24D0A795EE0B67F6A4EF5E6B75286DE914F33A81E
608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa608.969\zapret_build-main\zapret\binaries\win64\zapret-winws\WinDivert64.sysexecutable
MD5:89ED5BE7EA83C01D0DE33D3519944AA5
SHA256:8DA085332782708D8767BCACE5327A6EC7283C17CFB85E40B03CD2323A90DDC2
608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa608.969\zapret_build-main\zapret\blockcheck\zapret\common\fwtype.shtext
MD5:870DCC207C4808CC6934D204A1F2311A
SHA256:8A21E8F8FB1878BEF256A467540A9FAE42F9135201CBAD06C1118C1F2BF69B50
608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa608.969\zapret_build-main\zapret\blockcheck\zapret\files\fake\dht_get_peers.binbinary
MD5:D755F09EA9D03F842E1AD2693EBC4BBE
SHA256:B57F6584EB58689CCF81702B44103FA53EA31A5DBA00BE9C95B4059BAD602E77
608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa608.969\zapret_build-main\zapret\blockcheck\zapret\common\elevate.shtext
MD5:2370B5897E36E9D63CBDF1E533C2B08C
SHA256:0C73B7BB0CE73AB0E962DCA6C8274FF07AEAAF1B6CCFDD8103898B0950042446
608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa608.969\zapret_build-main\zapret\blockcheck\zapret\common\virt.shtext
MD5:58716E351159127B3CB47D737402221F
SHA256:E334C1E7B378BAA6FE706CF912CF701F867C91004DC1834565C15F59785965F4
608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa608.969\zapret_build-main\zapret\blockcheck\zapret\blog.shtext
MD5:A5F7B48E604B1CD5B929879FDCA4D856
SHA256:A848F249447E65346ED4BB44FDAC5DE4C515522896C251CBCB937E2A701EAB08
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
36
DNS requests
20
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6944
svchost.exe
GET
200
23.32.238.107:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4
System
GET
200
192.229.221.95:80
http://www.iana.org/
unknown
whitelisted
4700
svchost.exe
GET
200
192.229.221.95:80
http://www.iana.org/
unknown
whitelisted
4
System
GET
200
184.30.21.171:80
http://www.iana.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3524
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
104.126.37.169:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6944
svchost.exe
23.32.238.107:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
  • 51.124.78.146
  • 4.231.128.59
whitelisted
www.bing.com
  • 104.126.37.169
  • 104.126.37.155
  • 104.126.37.170
  • 104.126.37.137
  • 104.126.37.139
  • 104.126.37.163
  • 104.126.37.152
  • 104.126.37.153
  • 104.126.37.161
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.185.174
whitelisted
crl.microsoft.com
  • 23.32.238.107
  • 23.32.238.112
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.74
  • 40.126.32.68
  • 40.126.32.134
  • 40.126.32.72
  • 20.190.160.17
  • 20.190.160.14
  • 40.126.32.140
whitelisted
th.bing.com
  • 104.126.37.155
  • 104.126.37.128
  • 104.126.37.130
  • 104.126.37.139
  • 104.126.37.186
  • 104.126.37.184
  • 104.126.37.131
  • 104.126.37.136
  • 104.126.37.137
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted

Threats

PID
Process
Class
Message
4
System
Generic Protocol Command Decode
SURICATA TLS invalid record version
4
System
Generic Protocol Command Decode
SURICATA TLS invalid record version
4360
SearchApp.exe
Generic Protocol Command Decode
SURICATA TLS handshake invalid length
4360
SearchApp.exe
Generic Protocol Command Decode
SURICATA TLS handshake invalid length
4360
SearchApp.exe
Generic Protocol Command Decode
SURICATA TLS invalid record version
4360
SearchApp.exe
Generic Protocol Command Decode
SURICATA TLS invalid record version
4
System
Generic Protocol Command Decode
SURICATA TLS handshake invalid length
4
System
Generic Protocol Command Decode
SURICATA TLS handshake invalid length
No debug info