File name:

APD_607R1_m50_WM_e.exe

Full analysis: https://app.any.run/tasks/d68f05b1-755e-4d72-a2f3-d66ff3874856
Verdict: Malicious activity
Analysis date: January 22, 2025, 21:28:42
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

5DE915702CD294E86661F0C594E83A7F

SHA1:

E79FFC83F308ECB34D653152FCC1871777C47127

SHA256:

F52F6CEB8D66A18D35B34CFEB6D402FBEB0EE6B00308276861791CBAB7B1FB2D

SSDEEP:

98304:W0Af4V8Fova8kbbRpVmyklBmHMhAhVA0TmwVJlywU1532Gr4O5kH4Dj/JFd1+EeU:JCJRdITYoI8JpTLNZsm7XYEZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • DPInst.exe (PID: 4264)
      • DPInst.exe (PID: 624)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • APD_607R1_m50_WM_e.exe (PID: 5200)
      • APD_607R1_m50_WM_e.tmp (PID: 6232)
      • APD_607R1_m50_WM_e.exe (PID: 6188)
      • APD_607R1_m50.exe (PID: 7008)
      • Setup.exe (PID: 7064)
      • DPInst.exe (PID: 4264)
      • drvinst.exe (PID: 5432)
    • Reads security settings of Internet Explorer

      • APD_607R1_m50_WM_e.tmp (PID: 4624)
      • APD_607R1_m50.exe (PID: 7008)
    • Reads the Windows owner or organization settings

      • APD_607R1_m50_WM_e.tmp (PID: 6232)
    • Drops a system driver (possible attempt to evade defenses)

      • APD_607R1_m50.exe (PID: 7008)
      • DPInst.exe (PID: 4264)
      • Setup.exe (PID: 7064)
      • drvinst.exe (PID: 5432)
    • Process drops legitimate windows executable

      • APD_607R1_m50.exe (PID: 7008)
      • Setup.exe (PID: 7064)
    • Executes as Windows Service

      • APDLog.exe (PID: 3620)
      • spoolsv.exe (PID: 4528)
      • spoolsv.exe (PID: 5856)
      • spoolsv.exe (PID: 488)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 5432)
    • Creates files in the driver directory

      • drvinst.exe (PID: 5432)
  • INFO

    • Create files in a temporary directory

      • APD_607R1_m50_WM_e.exe (PID: 5200)
      • APD_607R1_m50_WM_e.exe (PID: 6188)
      • extrac32.exe (PID: 7084)
      • Setup.exe (PID: 7064)
      • APD_607R1_m50.exe (PID: 7008)
      • APD_607R1_m50_WM_e.tmp (PID: 6232)
      • DPInst.exe (PID: 4264)
    • Checks supported languages

      • APD_607R1_m50_WM_e.tmp (PID: 4624)
      • APD_607R1_m50_WM_e.exe (PID: 5200)
      • APD_607R1_m50_WM_e.exe (PID: 6188)
      • APD_607R1_m50_WM_e.tmp (PID: 6232)
      • APD_607R1_m50.exe (PID: 7008)
      • extrac32.exe (PID: 7084)
      • Setup.exe (PID: 7064)
      • Setup.exe (PID: 5236)
      • Setup.exe (PID: 5588)
      • APDLog.exe (PID: 3620)
      • DPInst.exe (PID: 4264)
      • drvinst.exe (PID: 5432)
      • DPInst.exe (PID: 624)
    • Process checks computer location settings

      • APD_607R1_m50_WM_e.tmp (PID: 4624)
    • Reads the computer name

      • APD_607R1_m50_WM_e.tmp (PID: 4624)
      • APD_607R1_m50_WM_e.tmp (PID: 6232)
      • extrac32.exe (PID: 7084)
      • APD_607R1_m50.exe (PID: 7008)
      • Setup.exe (PID: 7064)
      • DPInst.exe (PID: 4264)
      • APDLog.exe (PID: 3620)
    • Manual execution by a user

      • APD_607R1_m50.exe (PID: 7008)
      • APD_607R1_m50.exe (PID: 6960)
    • The sample compiled with japanese language support

      • APD_607R1_m50.exe (PID: 7008)
      • Setup.exe (PID: 7064)
    • The sample compiled with english language support

      • APD_607R1_m50.exe (PID: 7008)
      • DPInst.exe (PID: 4264)
      • Setup.exe (PID: 7064)
      • drvinst.exe (PID: 5432)
    • Creates files in the program directory

      • Setup.exe (PID: 7064)
      • APDLog.exe (PID: 3620)
    • Reads the machine GUID from the registry

      • DPInst.exe (PID: 4264)
      • drvinst.exe (PID: 5432)
      • DPInst.exe (PID: 624)
    • Reads the software policy settings

      • drvinst.exe (PID: 5432)
      • DPInst.exe (PID: 4264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (57.2)
.exe | Win32 Executable (generic) (18.2)
.exe | Win16/32 Executable Delphi generic (8.3)
.exe | Generic Win/DOS Executable (8)
.exe | DOS Executable Generic (8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:06:14 13:27:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 343040
UninitializedDataSize: -
EntryPoint: 0x1181c
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Epson America, Inc.
FileDescription: EPSON Driver Package Setup
FileVersion: 1.0
LegalCopyright: Epson America, Inc.
ProductName: EPSON Driver Package
ProductVersion: 1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
19
Malicious processes
4
Suspicious processes
3

Behavior graph

Click at the process to see the details
start apd_607r1_m50_wm_e.exe apd_607r1_m50_wm_e.tmp no specs apd_607r1_m50_wm_e.exe apd_607r1_m50_wm_e.tmp rundll32.exe no specs apd_607r1_m50.exe no specs apd_607r1_m50.exe setup.exe extrac32.exe no specs apdlog.exe no specs spoolsv.exe no specs setup.exe no specs setup.exe no specs dpinst.exe drvinst.exe spoolsv.exe no specs rundll32.exe no specs dpinst.exe no specs spoolsv.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
488C:\WINDOWS\System32\spoolsv.exeC:\Windows\System32\spoolsv.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Spooler SubSystem App
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\spoolsv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
624"C:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 6\DriverPack\TMUSB\TMUSB800\TMUSB64\DPInst.exe" /q /u "C:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 6\DriverPack\Driver\TM-T\EA6INSTMT.INF" /dC:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 6\DriverPack\TMUSB\TMUSB800\TMUSB64\DPInst.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
0
Version:
2.01
Modules
Images
c:\program files (x86)\epson\epson advanced printer driver 6\driverpack\tmusb\tmusb800\tmusb64\dpinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3620"C:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 6\DriverPack\PrinterReg\APDLog.exe"C:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 6\DriverPack\PrinterReg\APDLog.exeservices.exe
User:
SYSTEM
Company:
Seiko Epson Corporation
Integrity Level:
SYSTEM
Description:
APDLog.exe
Exit code:
0
Version:
6.07.0.0
Modules
Images
c:\program files (x86)\epson\epson advanced printer driver 6\driverpack\printerreg\apdlog.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ws2_32.dll
c:\windows\syswow64\rpcrt4.dll
4264TMUSB64\dpinst.exe /s /se /sw /sa /elC:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 6\DriverPack\TMUSB\TMUSB800\TMUSB64\DPInst.exe
Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
2147549184
Version:
2.01
Modules
Images
c:\program files (x86)\epson\epson advanced printer driver 6\driverpack\tmusb\tmusb800\tmusb64\dpinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4528C:\WINDOWS\System32\spoolsv.exeC:\Windows\System32\spoolsv.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Spooler SubSystem App
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\spoolsv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4624"C:\Users\admin\AppData\Local\Temp\is-DVUFA.tmp\APD_607R1_m50_WM_e.tmp" /SL5="$6028C,15309734,410624,C:\Users\admin\AppData\Local\Temp\APD_607R1_m50_WM_e.exe" C:\Users\admin\AppData\Local\Temp\is-DVUFA.tmp\APD_607R1_m50_WM_e.tmpAPD_607R1_m50_WM_e.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\is-dvufa.tmp\apd_607r1_m50_wm_e.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
4864rundll32 printui.dll,PrintUIEntry /q /dd /m "EPSON TM-T(180dpi) Receipt6"C:\Windows\SysWOW64\rundll32.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5200"C:\Users\admin\AppData\Local\Temp\APD_607R1_m50_WM_e.exe" C:\Users\admin\AppData\Local\Temp\APD_607R1_m50_WM_e.exe
explorer.exe
User:
admin
Company:
Epson America, Inc.
Integrity Level:
MEDIUM
Description:
EPSON Driver Package Setup
Exit code:
0
Version:
1.0
Modules
Images
c:\users\admin\appdata\local\temp\apd_607r1_m50_wm_e.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
5236"C:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 6\DriverPack\TMUSB\TMUSB800\Setup.exe" -s2C:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 6\DriverPack\TMUSB\TMUSB800\Setup.exeSetup.exe
User:
admin
Company:
Seiko Epson Corporation
Integrity Level:
HIGH
Description:
EPSON TMUSB Driver Ver.8.00 Installer
Exit code:
2
Version:
TMUSB800a
Modules
Images
c:\program files (x86)\epson\epson advanced printer driver 6\driverpack\tmusb\tmusb800\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
5432DrvInst.exe "4" "8" "C:\Users\admin\AppData\Local\Temp\{61750ce8-705f-1f4b-9a9b-f6946f2e95f9}\tmusb64.inf" "9" "40bb771fb" "00000000000001C8" "WinSta0\Default" "00000000000001E4" "208" "c:\program files (x86)\epson\epson advanced printer driver 6\driverpack\tmusb\tmusb800\tmusb64"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096967
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
Total events
12 841
Read events
12 674
Write events
164
Delete events
3

Modification events

(PID) Process:(4528) spoolsv.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print
Operation:writeName:BeepEnabled
Value:
0
(PID) Process:(4528) spoolsv.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Devices
Operation:writeName:OneNote (Desktop)
Value:
winspool,nul:
(PID) Process:(4528) spoolsv.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PrinterPorts
Operation:writeName:OneNote (Desktop)
Value:
winspool,nul:,15,45
(PID) Process:(4528) spoolsv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports
Operation:writeName:Ne00:
Value:
(PID) Process:(4528) spoolsv.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Devices
Operation:writeName:Microsoft XPS Document Writer
Value:
winspool,Ne00:
(PID) Process:(4528) spoolsv.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PrinterPorts
Operation:writeName:Microsoft XPS Document Writer
Value:
winspool,Ne00:,15,45
(PID) Process:(4528) spoolsv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports
Operation:writeName:Ne01:
Value:
(PID) Process:(4528) spoolsv.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Devices
Operation:writeName:Microsoft Print to PDF
Value:
winspool,Ne01:
(PID) Process:(4528) spoolsv.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PrinterPorts
Operation:writeName:Microsoft Print to PDF
Value:
winspool,Ne01:,15,45
(PID) Process:(4528) spoolsv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports
Operation:writeName:Ne02:
Value:
Executable files
94
Suspicious files
36
Text files
511
Unknown types
0

Dropped files

PID
Process
Filename
Type
6232APD_607R1_m50_WM_e.tmpC:\Users\admin\AppData\Local\Temp\APD_607R1_m50_WM_e_\is-S57A9.tmp
MD5:
SHA256:
6232APD_607R1_m50_WM_e.tmpC:\Users\admin\AppData\Local\Temp\APD_607R1_m50_WM_e_\APD6_Printer_en_revC.pdf
MD5:
SHA256:
7008APD_607R1_m50.exeC:\Users\admin\AppData\Local\Temp\APD6\Driver\TM-T\ea6instmt.catbinary
MD5:CB3AB8A64258BC09A8E927FD49AAA422
SHA256:BF580666D7EE673D25E83663F908A4B39C412BA844FBC2C34A29D1E526F3E250
6232APD_607R1_m50_WM_e.tmpC:\Users\admin\AppData\Local\Temp\is-HF2EF.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6188APD_607R1_m50_WM_e.exeC:\Users\admin\AppData\Local\Temp\is-VODSF.tmp\APD_607R1_m50_WM_e.tmpexecutable
MD5:540A091AE91BA8C455A52EEDADF8AB6C
SHA256:99B63685F226798A0CADBA2FB8F82F07D367F2EDE3CA40581C155D10AA79B523
6232APD_607R1_m50_WM_e.tmpC:\Users\admin\AppData\Local\Temp\APD_607R1_m50_WM_e_\APD6_Install_en_revF.pdfpdf
MD5:28F433E2CA3488F9DF50AE8D50ADF2CA
SHA256:E563797A8A44BED8343AECCB65655E9FCC5B70CC29FC26AEDA2EB60265ED45D0
6232APD_607R1_m50_WM_e.tmpC:\Users\admin\AppData\Local\Temp\APD_607R1_m50_WM_e_\is-P94QN.tmppdf
MD5:28F433E2CA3488F9DF50AE8D50ADF2CA
SHA256:E563797A8A44BED8343AECCB65655E9FCC5B70CC29FC26AEDA2EB60265ED45D0
6232APD_607R1_m50_WM_e.tmpC:\Users\admin\AppData\Local\Temp\APD_607R1_m50_WM_e_\APD_607R1_m50.exeexecutable
MD5:25F270078FB5FB6F9F3FEEB2EDA851DD
SHA256:6A2DA8A465FCC5F5BAAA2D08B5E3067AFC23515C2AE92DFF971ACA3CDF44D18D
6232APD_607R1_m50_WM_e.tmpC:\Users\admin\AppData\Local\Temp\APD_607R1_m50_WM_e_\is-2CCJ9.tmppdf
MD5:F3966F9C5AB202E86125E8FFEE13B800
SHA256:95D043E6333CB22A756441BDB4ACD79F38438A9F98AC7D397A7A8522869B7169
6232APD_607R1_m50_WM_e.tmpC:\Users\admin\AppData\Local\Temp\APD_607R1_m50_WM_e_\APD6_Spec_m50_en_revA.pdfpdf
MD5:F3966F9C5AB202E86125E8FFEE13B800
SHA256:95D043E6333CB22A756441BDB4ACD79F38438A9F98AC7D397A7A8522869B7169
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
30
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7152
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7152
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3628
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
95.101.136.223:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4
System
192.168.100.255:137
whitelisted
1176
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
23.210.18.13:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
7152
SIHClient.exe
20.109.210.53:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 95.101.136.223
  • 95.101.136.201
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.133
  • 40.126.32.138
  • 40.126.32.136
  • 40.126.32.140
  • 40.126.32.74
  • 40.126.32.76
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
go.microsoft.com
  • 23.210.18.13
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted

Threats

No threats detected
No debug info