File name:

PowerISO6-x64-Full.exe

Full analysis: https://app.any.run/tasks/04778fe3-9442-4fb1-b81b-d2adf13dfae8
Verdict: Malicious activity
Analysis date: May 14, 2025, 15:04:41
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

B16CEFB8F9462D3F98826CC4D77792EB

SHA1:

B004E4CD921A47073AA64805727850C4BB610E06

SHA256:

F4080C293CB19C76850A605DC3ED61FD832E7D0FE942A9D0E2BB50AA7C8343F3

SSDEEP:

98304:pVI8+z06IW9ijs4VQex6D/4axE2oSqmvw2jj2AH5Xkd4z3VkFI4SJpIS7R+K+jiv:r3ymEN5Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • PowerISO6-x64-Full.exe (PID: 7360)
      • setup64.exe (PID: 8012)
      • PWRISOVM.EXE (PID: 6068)
      • PowerISO.exe (PID: 4336)
    • Registers / Runs the DLL via REGSVR32.EXE

      • PowerISO6-x64-Full.exe (PID: 7464)
      • PowerISO.exe (PID: 4336)
    • Changes the autorun value in the registry

      • PowerISO6-x64-Full.exe (PID: 7464)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setup64.exe (PID: 8012)
      • PowerISO6-x64-Full.exe (PID: 7464)
    • Creates files in the driver directory

      • setup64.exe (PID: 8012)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • PowerISO6-x64-Full.exe (PID: 7464)
    • The process creates files with name similar to system file names

      • PowerISO6-x64-Full.exe (PID: 7464)
    • Drops a system driver (possible attempt to evade defenses)

      • setup64.exe (PID: 8012)
    • Creates or modifies Windows services

      • PowerISO6-x64-Full.exe (PID: 7464)
    • Reads security settings of Internet Explorer

      • PowerISO6-x64-Full.exe (PID: 7464)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2152)
    • There is functionality for taking screenshot (YARA)

      • PowerISO6-x64-Full.exe (PID: 7464)
    • Creates a software uninstall entry

      • PowerISO6-x64-Full.exe (PID: 7464)
  • INFO

    • Create files in a temporary directory

      • PowerISO6-x64-Full.exe (PID: 7464)
    • The sample compiled with english language support

      • PowerISO6-x64-Full.exe (PID: 7464)
      • setup64.exe (PID: 8012)
    • Reads the computer name

      • PowerISO6-x64-Full.exe (PID: 7464)
      • identity_helper.exe (PID: 7796)
      • identity_helper.exe (PID: 4220)
    • Checks supported languages

      • PowerISO6-x64-Full.exe (PID: 7464)
      • devcon.exe (PID: 7988)
      • PWRISOVM.EXE (PID: 6068)
      • identity_helper.exe (PID: 7796)
      • identity_helper.exe (PID: 4220)
      • setup64.exe (PID: 8012)
    • The sample compiled with chinese language support

      • PowerISO6-x64-Full.exe (PID: 7464)
    • Process checks computer location settings

      • PowerISO6-x64-Full.exe (PID: 7464)
    • Application launched itself

      • msedge.exe (PID: 5212)
      • msedge.exe (PID: 7248)
      • msedge.exe (PID: 7832)
    • Reads Environment values

      • identity_helper.exe (PID: 7796)
      • identity_helper.exe (PID: 4220)
    • Manual execution by a user

      • msedge.exe (PID: 5212)
      • PowerISO.exe (PID: 4336)
    • Creates files in the program directory

      • PowerISO6-x64-Full.exe (PID: 7464)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:02:24 19:19:59+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 28672
InitializedDataSize: 445952
UninitializedDataSize: 16896
EntryPoint: 0x39e3
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 6.9.0.0
ProductVersionNumber: 6.9.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: Power Software Ltd
FileDescription: PowerISO Setup
FileVersion: 6.9.0.0
LegalCopyright: Copyright(c) 2004-2017
ProductName: PowerISO Setup
ProductVersion: 6.9.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
195
Monitored processes
60
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start poweriso6-x64-full.exe sppextcomobj.exe no specs slui.exe no specs regsvr32.exe no specs devcon.exe no specs setup64.exe regsvr32.exe no specs pwrisovm.exe no specs regsvr32.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs poweriso.exe no specs regsvr32.exe no specs poweriso6-x64-full.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5540 --field-trial-handle=2412,i,11458884242805114418,6349519504417022450,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
728"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3772 --field-trial-handle=2412,i,11458884242805114418,6349519504417022450,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
896"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6168 --field-trial-handle=2412,i,11458884242805114418,6349519504417022450,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1300"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3276 --field-trial-handle=2356,i,16622624696939446518,6003895085337941369,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1324"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2436 --field-trial-handle=2356,i,16622624696939446518,6003895085337941369,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1628"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2332 --field-trial-handle=2412,i,11458884242805114418,6349519504417022450,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2136"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5260 --field-trial-handle=2412,i,11458884242805114418,6349519504417022450,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2152 /s "C:\Program Files\PowerISO\PWRISOSH.DLL"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2340"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6136 --field-trial-handle=2412,i,11458884242805114418,6349519504417022450,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2384"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5680 --field-trial-handle=2412,i,11458884242805114418,6349519504417022450,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
8 046
Read events
7 978
Write events
65
Delete events
3

Modification events

(PID) Process:(7464) PowerISO6-x64-Full.exeKey:HKEY_CURRENT_USER\SOFTWARE\PowerISO
Operation:writeName:TbInstallFlag
Value:
0
(PID) Process:(7464) PowerISO6-x64-Full.exeKey:HKEY_CURRENT_USER\SOFTWARE\PowerISO
Operation:writeName:TbInstallFlag2
Value:
0
(PID) Process:(7464) PowerISO6-x64-Full.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\PowerISO
Operation:writeName:Install_Dir_x64
Value:
C:\Program Files\PowerISO
(PID) Process:(7464) PowerISO6-x64-Full.exeKey:HKEY_CURRENT_USER\SOFTWARE\PowerISO
Operation:writeName:Install_Dir_x64
Value:
C:\Program Files\PowerISO
(PID) Process:(7464) PowerISO6-x64-Full.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PowerISO
Operation:writeName:DisplayName
Value:
PowerISO
(PID) Process:(7464) PowerISO6-x64-Full.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PowerISO
Operation:writeName:DisplayIcon
Value:
"C:\Program Files\PowerISO\PowerISO.exe"
(PID) Process:(7464) PowerISO6-x64-Full.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PowerISO
Operation:writeName:UninstallString
Value:
"C:\Program Files\PowerISO\uninstall.exe"
(PID) Process:(7464) PowerISO6-x64-Full.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PowerISO
Operation:writeName:InstallLocation
Value:
C:\Program Files\PowerISO
(PID) Process:(7464) PowerISO6-x64-Full.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PowerISO
Operation:writeName:DisplayVersion
Value:
6.9
(PID) Process:(7464) PowerISO6-x64-Full.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PowerISO
Operation:writeName:VersionMajor
Value:
6
Executable files
27
Suspicious files
292
Text files
72
Unknown types
1

Dropped files

PID
Process
Filename
Type
7464PowerISO6-x64-Full.exeC:\Program Files\PowerISO\Lang\SimpChinese.lngbinary
MD5:74D6FE92A3A36CBF1E2C6EFD251E21EE
SHA256:B91D8F208DE504E8E6850350736A980547691201CD396784D85DF21CEDF86F7E
7464PowerISO6-x64-Full.exeC:\Program Files\PowerISO\Lang\Polish.lngbinary
MD5:727FB71394E1CB34073C3D43E6944B46
SHA256:5FB58E33D7E45C60541A1F18182FF5A54983E0DEBA5892A363B4B0BB0A969780
8012setup64.exeC:\Windows\System32\drivers\scdemu.sysexecutable
MD5:92EAE8DEC1F992DB12AA23D9D55F264A
SHA256:D01A58E0A222E4D301B75AE80150D8CBC17F56B3F6458352D2C7C449BE302EEE
7464PowerISO6-x64-Full.exeC:\Program Files\PowerISO\devcon.exeexecutable
MD5:9D199564B65A91A531B23844649459E9
SHA256:8DC2490D1D650E3FFBF70922B81AE9800DDD29A644E4D7D29E9616E22A7D0F42
7464PowerISO6-x64-Full.exeC:\Program Files\PowerISO\Lang\french.lngbinary
MD5:DB7B9EB98F8EC89FE8ED9F8D5B50D786
SHA256:9ED195D96375683B71DC5B3DEA9C99F067B06FDB5D866985BFF9C84802354783
7464PowerISO6-x64-Full.exeC:\Program Files\PowerISO\setup64.exeexecutable
MD5:AC7886BF54734D8DB8416BE2CDE5FB9D
SHA256:5522BB7C89D189C4E979CAEA6092383DF15F18FCA382648D473945D6FE41ECA4
7464PowerISO6-x64-Full.exeC:\Program Files\PowerISO\Lang\TradChinese.lngbinary
MD5:9CB42901399D21539AC4BCA31CE5DC8D
SHA256:3E990742832026CDF5C0809ABDB4A1909169987B54C763F3C2133FE9256FC244
7464PowerISO6-x64-Full.exeC:\Users\admin\AppData\Local\Temp\nsuE813.tmpexecutable
MD5:92EAE8DEC1F992DB12AA23D9D55F264A
SHA256:D01A58E0A222E4D301B75AE80150D8CBC17F56B3F6458352D2C7C449BE302EEE
7464PowerISO6-x64-Full.exeC:\Users\admin\AppData\Local\Temp\nswB990.tmp\System.dllexecutable
MD5:BF712F32249029466FA86756F5546950
SHA256:7851CB12FA4131F1FEE5DE390D650EF65CAC561279F1CFE70AD16CC9780210AF
7464PowerISO6-x64-Full.exeC:\Program Files\PowerISO\Lang\Greek.lngbinary
MD5:C3F88049D369F38E17F29E6E3DF92924
SHA256:731747470EC944CD00857C087A001C55B4E48ECCFC865DC5D9288945E6782FD2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
77
DNS requests
59
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.145:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7852
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7852
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.145:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.128:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.145
  • 23.48.23.146
  • 23.48.23.133
  • 23.48.23.142
  • 23.48.23.141
  • 23.48.23.140
  • 23.48.23.132
  • 23.48.23.195
  • 23.48.23.191
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.159.128
  • 40.126.31.3
  • 40.126.31.130
  • 20.190.159.131
  • 40.126.31.0
  • 40.126.31.1
  • 20.190.159.2
  • 40.126.31.69
  • 20.190.159.68
  • 20.190.159.64
  • 40.126.31.128
  • 20.190.159.73
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.253.45
whitelisted

Threats

PID
Process
Class
Message
6712
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
6712
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
6712
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
6712
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info