Why MID server trying to connect chcp.com

Prabhu6
Tera Guru

This is the first time the Security team has seen this alert as suspicious. Attached Event

1 ACCEPTED SOLUTION

Richard Hine
Tera Guru

It isn't trying to reach chcp.com, chcp is a COM (Component Object Model) file on your MID server. The File extension is .com and the file is called chcp.

You can even see the path to the file in the alert screenshot you posted.

It is related to the system code page : https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/chcp

Hope this helps,

Richard

View solution in original post

2 REPLIES 2

PM20
Tera Expert

adding one more event

Richard Hine
Tera Guru

It isn't trying to reach chcp.com, chcp is a COM (Component Object Model) file on your MID server. The File extension is .com and the file is called chcp.

You can even see the path to the file in the alert screenshot you posted.

It is related to the system code page : https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/chcp

Hope this helps,

Richard