File name:

Nexus 2 Setup.exe

Full analysis: https://app.any.run/tasks/9f1ba8de-635b-4208-b25c-fa95b846ec6f
Verdict: Malicious activity
Analysis date: August 31, 2024, 15:39:50
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

87349254027382D5A1BC066721F0BF2E

SHA1:

9DE52C03379E254CF40B59CB00526DFA98C9A4D0

SHA256:

FB79D89AA17BE34CB6D59BA90B7C9441E4E723D25AB5E7DAA9B62C0EAD393637

SSDEEP:

196608:qjeNO87aObkEVDQM4Cg06lYv638JnaaGKwWdSU:GAO87JYM4HJl8+89aa9wC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • Nexus 2 Setup.tmp (PID: 6960)
      • Nexus 2 Setup.exe (PID: 6196)
      • unins000.exe (PID: 892)
      • Nexus 2 Setup.exe (PID: 5880)
      • _iu14D2N.tmp (PID: 6252)
      • AiR eLicenser Emulator Setup.exe (PID: 4040)
      • AiR eLicenser Emulator Setup.exe (PID: 1748)
      • AiR eLicenser Emulator Setup.tmp (PID: 740)
    • Executable content was dropped or overwritten

      • Nexus 2 Setup.exe (PID: 6196)
      • Nexus 2 Setup.exe (PID: 5880)
      • Nexus 2 Setup.tmp (PID: 6960)
      • unins000.exe (PID: 892)
      • _iu14D2N.tmp (PID: 6252)
      • AiR eLicenser Emulator Setup.exe (PID: 1748)
      • AiR eLicenser Emulator Setup.exe (PID: 4040)
      • AiR eLicenser Emulator Setup.tmp (PID: 740)
    • Reads security settings of Internet Explorer

      • Nexus 2 Setup.tmp (PID: 6792)
      • unins000.exe (PID: 7068)
      • AiR eLicenser Emulator Setup.tmp (PID: 7156)
    • Reads the date of Windows installation

      • Nexus 2 Setup.tmp (PID: 6792)
      • unins000.exe (PID: 7068)
      • AiR eLicenser Emulator Setup.tmp (PID: 7156)
    • Reads the Windows owner or organization settings

      • Nexus 2 Setup.tmp (PID: 6960)
      • _iu14D2N.tmp (PID: 6252)
      • AiR eLicenser Emulator Setup.tmp (PID: 740)
    • Process drops legitimate windows executable

      • Nexus 2 Setup.tmp (PID: 6960)
      • AiR eLicenser Emulator Setup.tmp (PID: 740)
      • _iu14D2N.tmp (PID: 6252)
    • There is functionality for taking screenshot (YARA)

      • Nexus 2 Setup.tmp (PID: 6960)
    • Application launched itself

      • unins000.exe (PID: 7068)
    • Starts itself from another location

      • unins000.exe (PID: 892)
    • Starts application with an unusual extension

      • unins000.exe (PID: 892)
  • INFO

    • Checks supported languages

      • Nexus 2 Setup.tmp (PID: 6792)
      • Nexus 2 Setup.exe (PID: 6196)
      • Nexus 2 Setup.exe (PID: 5880)
      • Nexus 2 Setup.tmp (PID: 6960)
      • unins000.exe (PID: 892)
      • _iu14D2N.tmp (PID: 6252)
      • AiR eLicenser Emulator Setup.tmp (PID: 7156)
      • AiR eLicenser Emulator Setup.exe (PID: 1748)
      • AiR eLicenser Emulator Setup.exe (PID: 4040)
      • AiR eLicenser Emulator Setup.tmp (PID: 740)
      • unins000.exe (PID: 7068)
    • Create files in a temporary directory

      • Nexus 2 Setup.tmp (PID: 6960)
      • Nexus 2 Setup.exe (PID: 5880)
      • Nexus 2 Setup.exe (PID: 6196)
      • unins000.exe (PID: 892)
      • _iu14D2N.tmp (PID: 6252)
      • AiR eLicenser Emulator Setup.exe (PID: 1748)
      • AiR eLicenser Emulator Setup.exe (PID: 4040)
      • AiR eLicenser Emulator Setup.tmp (PID: 740)
    • Reads the computer name

      • Nexus 2 Setup.tmp (PID: 6792)
      • unins000.exe (PID: 7068)
      • _iu14D2N.tmp (PID: 6252)
      • unins000.exe (PID: 892)
      • Nexus 2 Setup.tmp (PID: 6960)
      • AiR eLicenser Emulator Setup.tmp (PID: 7156)
      • AiR eLicenser Emulator Setup.tmp (PID: 740)
    • Manual execution by a user

      • unins000.exe (PID: 7068)
      • AiR eLicenser Emulator Setup.exe (PID: 1748)
    • Process checks computer location settings

      • Nexus 2 Setup.tmp (PID: 6792)
      • unins000.exe (PID: 7068)
      • AiR eLicenser Emulator Setup.tmp (PID: 7156)
    • Creates files in the program directory

      • Nexus 2 Setup.tmp (PID: 6960)
    • Creates a software uninstall entry

      • Nexus 2 Setup.tmp (PID: 6960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37376
InitializedDataSize: 14848
UninitializedDataSize: -
EntryPoint: 0x9a58
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.2.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName:
FileDescription: reFX Nexus
FileVersion: 2.2.0.0
LegalCopyright:
ProductName: reFX Nexus
ProductVersion: 2.2.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
12
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
start nexus 2 setup.exe nexus 2 setup.tmp no specs nexus 2 setup.exe THREAT nexus 2 setup.tmp rundll32.exe no specs unins000.exe no specs unins000.exe _iu14d2n.tmp air elicenser emulator setup.exe air elicenser emulator setup.tmp no specs air elicenser emulator setup.exe air elicenser emulator setup.tmp

Process information

PID
CMD
Path
Indicators
Parent process
740"C:\Users\admin\AppData\Local\Temp\is-JV8DE.tmp\AiR eLicenser Emulator Setup.tmp" /SL5="$50380,1841672,318976,C:\Users\admin\Desktop\AiR eLicenser Emulator Setup.exe" /SPAWNWND=$70224 /NOTIFYWND=$A02FA C:\Users\admin\AppData\Local\Temp\is-JV8DE.tmp\AiR eLicenser Emulator Setup.tmp
AiR eLicenser Emulator Setup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.49.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-jv8de.tmp\air elicenser emulator setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
892"C:\Program Files (x86)\Uninstall Nexus\unins000.exe" /INITPROCWND=$9032C C:\Program Files (x86)\Uninstall Nexus\unins000.exe
unins000.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.49.0.0
Modules
Images
c:\program files (x86)\uninstall nexus\unins000.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1748"C:\Users\admin\Desktop\AiR eLicenser Emulator Setup.exe" C:\Users\admin\Desktop\AiR eLicenser Emulator Setup.exe
explorer.exe
User:
admin
Company:
TEAM AiR
Integrity Level:
MEDIUM
Description:
AiR eLicenser Emulator
Exit code:
0
Version:
2.1.0.6
Modules
Images
c:\users\admin\desktop\air elicenser emulator setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2112C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
4040"C:\Users\admin\Desktop\AiR eLicenser Emulator Setup.exe" /SPAWNWND=$70224 /NOTIFYWND=$A02FA C:\Users\admin\Desktop\AiR eLicenser Emulator Setup.exe
AiR eLicenser Emulator Setup.tmp
User:
admin
Company:
TEAM AiR
Integrity Level:
HIGH
Description:
AiR eLicenser Emulator
Exit code:
0
Version:
2.1.0.6
Modules
Images
c:\users\admin\desktop\air elicenser emulator setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5880"C:\Users\admin\AppData\Local\Temp\Nexus 2 Setup.exe" /SPAWNWND=$7032E /NOTIFYWND=$403A8 C:\Users\admin\AppData\Local\Temp\Nexus 2 Setup.exe
Nexus 2 Setup.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
reFX Nexus
Exit code:
0
Version:
2.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\nexus 2 setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6196"C:\Users\admin\AppData\Local\Temp\Nexus 2 Setup.exe" C:\Users\admin\AppData\Local\Temp\Nexus 2 Setup.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
reFX Nexus
Exit code:
0
Version:
2.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\nexus 2 setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6252"C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp" /SECONDPHASE="C:\Program Files (x86)\Uninstall Nexus\unins000.exe" /FIRSTPHASEWND=$60232 /INITPROCWND=$9032C C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp
unins000.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.49.0.0
Modules
Images
c:\users\admin\appdata\local\temp\_iu14d2n.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6792"C:\Users\admin\AppData\Local\Temp\is-NM6OM.tmp\Nexus 2 Setup.tmp" /SL5="$403A8,15020542,53248,C:\Users\admin\AppData\Local\Temp\Nexus 2 Setup.exe" C:\Users\admin\AppData\Local\Temp\is-NM6OM.tmp\Nexus 2 Setup.tmpNexus 2 Setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.49.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-nm6om.tmp\nexus 2 setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6960"C:\Users\admin\AppData\Local\Temp\is-0G0R3.tmp\Nexus 2 Setup.tmp" /SL5="$A0312,15020542,53248,C:\Users\admin\AppData\Local\Temp\Nexus 2 Setup.exe" /SPAWNWND=$7032E /NOTIFYWND=$403A8 C:\Users\admin\AppData\Local\Temp\is-0G0R3.tmp\Nexus 2 Setup.tmp
Nexus 2 Setup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.49.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-0g0r3.tmp\nexus 2 setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
12 092
Read events
12 066
Write events
25
Delete events
1

Modification events

(PID) Process:(6960) Nexus 2 Setup.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\DirectSound\Speaker Configuration
Operation:writeName:Speaker Configuration
Value:
4
(PID) Process:(6960) Nexus 2 Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\reFX\Nexus
Operation:writeName:Contrast
Value:
80
(PID) Process:(6960) Nexus 2 Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\reFX\Nexus
Operation:writeName:Skin
Value:
silver
(PID) Process:(6960) Nexus 2 Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\reFX\Nexus
Operation:writeName:sortByName
Value:
false
(PID) Process:(6960) Nexus 2 Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\reFX\Nexus
Operation:writeName:fontSize
Value:
1
(PID) Process:(6960) Nexus 2 Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\reFX\Nexus
Operation:delete valueName:ContentPath
Value:
(PID) Process:(6960) Nexus 2 Setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\reFX\Nexus
Operation:writeName:ContentPath
Value:
(PID) Process:(6960) Nexus 2 Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\reFX Nexus_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.2.3
(PID) Process:(6960) Nexus 2 Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\reFX Nexus_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)
(PID) Process:(6960) Nexus 2 Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\reFX Nexus_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\
Executable files
32
Suspicious files
6
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
6960Nexus 2 Setup.tmpC:\Users\admin\AppData\Local\Temp\is-CB163.tmp\Music
MD5:
SHA256:
6960Nexus 2 Setup.tmpC:\Users\admin\AppData\Local\Temp\is-CB163.tmp\skin.cjstylesexecutable
MD5:31E3FE928C4524CBC648205296E600E9
SHA256:268B637662DDF5EA58AE7A531A075DC71076F1093B6F9E68A0C1DB8F79CA4349
6960Nexus 2 Setup.tmpC:\Users\admin\AppData\Local\Temp\is-CB163.tmp\_isetup\_setup64.tmpexecutable
MD5:B4604F8CD050D7933012AE4AA98E1796
SHA256:B50B7AC03EC6DA865BF4504C7AC1E52D9F5B67C7BCB3EC0DB59FAB24F1B471C5
6960Nexus 2 Setup.tmpC:\Users\admin\AppData\Local\Temp\is-CB163.tmp\WaterLib.dllexecutable
MD5:7AAF9F850B21512678623A9206F572A3
SHA256:AD46A43F535D647AB6ED9A8BADCEE1EFF3497E45348844BE327F505905B66E2B
6960Nexus 2 Setup.tmpC:\Program Files (x86)\is-S5SHO.tmpexecutable
MD5:2A0778490DFEFFD905CDBDCF7A065BC6
SHA256:2017E3BB9CCE0A619CD1FB5D062C2AC2EC8DB35819EBDB5D91C827FABC68DB91
6960Nexus 2 Setup.tmpC:\Users\admin\AppData\Local\Temp\is-CB163.tmp\isskin.dllexecutable
MD5:B31AD1BACFD7C51F35E052B8C7047D44
SHA256:117AE53CF3E8BC95E6297A15D8365EFD792DA04DF90744D4E244BBF72075CCC3
6960Nexus 2 Setup.tmpC:\Windows\SysWOW64\SYNSOEMU.DLLexecutable
MD5:7286412B479FE399BC94AFFB9A85BA55
SHA256:97312BAF6F45A445A137AAF7958C58B6902D364206930E5EA2528B79B1BEE86D
6960Nexus 2 Setup.tmpC:\Program Files (x86)\Uninstall Nexus\unins000.exeexecutable
MD5:A580EC2233328B11F2FCB99BBE3E4A46
SHA256:555E4693AFB3495C892E495B082BD54F5F2F28FF666BDA4E20AF6DD1E07069EA
6960Nexus 2 Setup.tmpC:\Program Files (x86)\Common Files\Digidesign\DAE\Plug-Ins\Nexus.dpmexecutable
MD5:94C53071EDB04638119149CD25E8806E
SHA256:83A23232BC0ECEFC0E8DE909A4966C4069EDAE4D57E057465C16DDD20F57FF2A
5880Nexus 2 Setup.exeC:\Users\admin\AppData\Local\Temp\is-0G0R3.tmp\Nexus 2 Setup.tmpexecutable
MD5:DF378EC3751FA0B4815A15B0A7BF365B
SHA256:C9015443A8680296828834326DCDC982C8ED8F6EC6C69F219CAC39C3E94B8798
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
31
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6780
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1360
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6780
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
608
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:138
whitelisted
6440
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
608
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1360
svchost.exe
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1360
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6780
SIHClient.exe
20.12.23.50:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.181.238
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 40.126.31.69
  • 20.190.159.2
  • 20.190.159.68
  • 20.190.159.0
  • 40.126.31.67
  • 40.126.31.71
  • 20.190.159.75
  • 40.126.31.73
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
No debug info