Probably Windows checking certificate revocation on a signed binary (or linked library).
If it is the binary itself making those calls (and not the OS), then anyone with a little bit of reverse engineering experience should be able to prove it and post the assembly.
Edit: I was wrong about the build toolchain, they were built by visual studio, see comment below.
this is not meant to imply anything about whether the binary is malicious or not.