File name:

OBS Studio.exe

Full analysis: https://app.any.run/tasks/6c369dbf-af99-4504-bb56-a598e3e750ff
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: December 21, 2025, 07:04:58
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
adware
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

081F5F0F20B34C0077AB54DB8AE84712

SHA1:

69FDDDACFAAD04CA3F7F6C94248495D08B9975A2

SHA256:

F3C3E2452239BBA00548C705E546A676392A79BD0474FA57B20BA73E50154566

SSDEEP:

98304:xpUvmenPSZpQzDjFKUm5m20g3wdf6kjXeOHq3DwtQnCgdlDAyS5gACZa8W0gv3b4:XU3Fxac0H

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OBS Studio.exe (PID: 7812)
      • OBS Studio.exe (PID: 7592)
      • OBS Studio.tmp (PID: 7840)
    • Reads security settings of Internet Explorer

      • OBS Studio.tmp (PID: 7616)
      • OBS Studio.tmp (PID: 7840)
    • Reads the Windows owner or organization settings

      • OBS Studio.tmp (PID: 7840)
  • INFO

    • Create files in a temporary directory

      • OBS Studio.exe (PID: 7592)
      • OBS Studio.exe (PID: 7812)
      • OBS Studio.tmp (PID: 7840)
    • Reads the computer name

      • OBS Studio.exe (PID: 7812)
      • OBS Studio.tmp (PID: 7616)
      • OBS Studio.tmp (PID: 7840)
      • TextInputHost.exe (PID: 6000)
    • Checks supported languages

      • OBS Studio.tmp (PID: 7616)
      • OBS Studio.exe (PID: 7592)
      • OBS Studio.exe (PID: 7812)
      • OBS Studio.tmp (PID: 7840)
      • TextInputHost.exe (PID: 6000)
    • Process checks computer location settings

      • OBS Studio.tmp (PID: 7616)
    • Checks proxy server information

      • OBS Studio.tmp (PID: 7840)
    • Reads the machine GUID from the registry

      • OBS Studio.tmp (PID: 7840)
    • Creates files or folders in the user directory

      • OBS Studio.tmp (PID: 7840)
    • Creates files in the program directory

      • OBS Studio.tmp (PID: 7840)
    • Creates a software uninstall entry

      • OBS Studio.tmp (PID: 7840)
    • Application launched itself

      • firefox.exe (PID: 7376)
      • firefox.exe (PID: 7508)
    • Compiled with Borland Delphi (YARA)

      • OBS Studio.exe (PID: 7592)
    • Detects InnoSetup installer (YARA)

      • OBS Studio.exe (PID: 7592)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 7508)
    • Manual execution by a user

      • firefox.exe (PID: 7376)
    • The sample compiled with english language support

      • firefox.exe (PID: 7508)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:11:10 17:25:51+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 716800
InitializedDataSize: 164352
UninitializedDataSize: -
EntryPoint: 0xafe60
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: OBS Studio.exe Setup
FileVersion: 1.0.0.0
LegalCopyright: OBS Studio.exe
OriginalFileName:
ProductName: OBS Studio.exe
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
163
Monitored processes
17
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start obs studio.exe obs studio.tmp no specs obs studio.exe obs studio.tmp firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs textinputhost.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
356"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5288 -prefsLen 39120 -prefMapHandle 5292 -prefMapSize 273045 -jsInitHandle 5296 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5152 -initialChannelId {f7f5c59a-6307-4419-825f-1a8ad2acc3c1} -parentPid 7508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 9 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\vcruntime140.dll
2624"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5000 -prefsLen 39120 -prefMapHandle 5004 -prefMapSize 273045 -jsInitHandle 5008 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4776 -initialChannelId {98d974d1-97f9-45ae-8ec2-17997f20eb87} -parentPid 7508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
3152"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 3356 -prefsLen 37056 -prefMapHandle 3360 -prefMapSize 273045 -ipcHandle 3380 -initialChannelId {32d6bd45-6090-4104-a09a-b2d1d057c1b7} -parentPid 7508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7508" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
3796"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 2028 -prefsLen 36580 -prefMapHandle 2032 -prefMapSize 273045 -ipcHandle 2080 -initialChannelId {0bf11dd6-af11-4442-a87c-ab9d1b1e79f7} -parentPid 7508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7508" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\msvcp140.dll
4508"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 0 -prefsHandle 4892 -prefsLen 45116 -prefMapHandle 4888 -prefMapSize 273045 -ipcHandle 4920 -initialChannelId {2af91771-44ec-4161-ba6d-43a0fabd28ff} -parentPid 7508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 6 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4516"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5172 -prefsLen 39120 -prefMapHandle 5176 -prefMapSize 273045 -jsInitHandle 5180 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5032 -initialChannelId {40180933-d0d6-450b-9d35-a1f9f582f139} -parentPid 7508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 8 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
6000"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
123.26505.0.0
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
7000"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3264 -prefsLen 37056 -prefMapHandle 3268 -prefMapSize 273045 -jsInitHandle 3272 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3280 -initialChannelId {0481f285-d4ab-43c9-952e-2f635bf26408} -parentPid 7508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
7224"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 2236 -prefsLen 36580 -prefMapHandle 2240 -prefMapSize 273045 -ipcHandle 2248 -initialChannelId {b22c55a5-7984-469b-8ea2-d3c7c4a7517f} -parentPid 7508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\msvcp140.dll
7364C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
1 526
Read events
1 508
Write events
18
Delete events
0

Modification events

(PID) Process:(7840) OBS Studio.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OBS Studio.exe_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.6.0
(PID) Process:(7840) OBS Studio.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OBS Studio.exe_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\Setup
(PID) Process:(7840) OBS Studio.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OBS Studio.exe_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\Setup\
(PID) Process:(7840) OBS Studio.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OBS Studio.exe_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(7840) OBS Studio.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OBS Studio.exe_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(7840) OBS Studio.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OBS Studio.exe_is1
Operation:writeName:Inno Setup: Language
Value:
default
(PID) Process:(7840) OBS Studio.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OBS Studio.exe_is1
Operation:writeName:DisplayName
Value:
OBS Studio.exe version 1.0.0.0
(PID) Process:(7840) OBS Studio.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OBS Studio.exe_is1
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\Setup\unins000.exe"
(PID) Process:(7840) OBS Studio.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OBS Studio.exe_is1
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files (x86)\Setup\unins000.exe" /SILENT
(PID) Process:(7840) OBS Studio.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OBS Studio.exe_is1
Operation:writeName:DisplayVersion
Value:
1.0.0.0
Executable files
10
Suspicious files
206
Text files
188
Unknown types
0

Dropped files

PID
Process
Filename
Type
7508firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
7840OBS Studio.tmpC:\Users\admin\AppData\Local\Temp\is-5EYGLH6RQU.tmp\idp.dllexecutable
MD5:55C310C0319260D798757557AB3BF636
SHA256:54E7E0AD32A22B775131A6288F083ED3286A9A436941377FC20F85DD9AD983ED
7840OBS Studio.tmpC:\Users\admin\AppData\Local\Temp\is-5EYGLH6RQU.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
7592OBS Studio.exeC:\Users\admin\AppData\Local\Temp\is-RW2FY08DY3.tmp\OBS Studio.tmpexecutable
MD5:50B55FDF7D31D481A40807A514D830FA
SHA256:C23829693124CB8739A8DBA936B56DC86945555DADF4A6624DE7A5250FDE8E6B
7840OBS Studio.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C0E5238609191CF60F46D128FEEF9BF4
SHA256:0F71708DBFEE304A55C01245E2E13067D295D1BCBECC1089D2077AACBA83FD5A
7812OBS Studio.exeC:\Users\admin\AppData\Local\Temp\is-DJF9C4DPM3.tmp\OBS Studio.tmpexecutable
MD5:50B55FDF7D31D481A40807A514D830FA
SHA256:C23829693124CB8739A8DBA936B56DC86945555DADF4A6624DE7A5250FDE8E6B
7840OBS Studio.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:1FBB37F79B317A9A248E7C4CE4F5BAC5
SHA256:9BF639C595FE335B6F694EE35990BEFD2123F5E07FD1973FF619E3FC88F5F49F
7840OBS Studio.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:26A109A82A6F81D9FC85B702F67F6A6F
SHA256:5138FDC111363BCA4DE70DA628E4102B79F2A1F0974F4E5BC419A6E8F514ED47
7840OBS Studio.tmpC:\Program Files (x86)\Setup\unins000.datbinary
MD5:D0328225F2E2D9414C1DFEB9FAE77779
SHA256:92D0CAAC8ECB68FB69B6A8FE3BD49099C5216B3990DFCD6DAD1B9E6B081D46A5
7840OBS Studio.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:6D130B07E02BABB47C58CB35E4572DFD
SHA256:FF78FAE003D2AD8B33DE7DC56DD83DC7A983BFCC073336E800FC9B5210874416
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
76
TCP/UDP connections
55
DNS requests
86
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7840
OBS Studio.tmp
HEAD
200
172.67.195.156:443
https://powerwish.xyz/Lg65RXZPLk052nnRGeQ5?e=392&sis=qahitp1tzlb&pid=4027&tid=&a=4027&cc=KR&t=1763696223
unknown
unknown
6768
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
unknown
whitelisted
6908
svchost.exe
POST
200
20.190.159.2:443
https://login.live.com/RST2.srf
unknown
xml
10.3 Kb
whitelisted
7840
OBS Studio.tmp
GET
200
172.67.195.156:443
https://powerwish.xyz/Lg65RXZPLk052nnRGeQ5?e=392&sis=qahitp1tzlb&pid=4027&tid=&a=4027&cc=KR&t=1763696223
unknown
2 b
unknown
6908
svchost.exe
POST
200
20.190.159.2:443
https://login.live.com/RST2.srf
unknown
xml
11.1 Kb
whitelisted
6908
svchost.exe
POST
200
20.190.159.2:443
https://login.live.com/RST2.srf
unknown
xml
10.3 Kb
whitelisted
6908
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5320
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7508
firefox.exe
GET
200
34.160.144.191:443
https://content-signature-2.cdn.mozilla.net/g/chains/202402/remote-settings.content-signature.mozilla.org-2025-11-08-08-20-52.chain
unknown
5.18 Kb
unknown
7508
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5320
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
6768
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1136
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3412
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6908
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6908
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
5320
svchost.exe
2.16.164.49:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
5320
svchost.exe
23.59.18.102:80
www.microsoft.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.78
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.2
  • 40.126.31.131
  • 40.126.31.1
  • 40.126.31.3
  • 20.190.159.23
  • 20.190.159.4
  • 20.190.159.73
  • 20.190.159.71
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 23.59.18.102
whitelisted
powerwish.xyz
  • 172.67.195.156
  • 104.21.44.53
unknown
c.pki.goog
  • 142.250.185.67
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Inno Download Plugin UA
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Inno Download Plugin UA
No debug info