https://www.virustotal.com/gui/file/950eea4e17fa3a7e89fa2c55...
If it is the binary itself making those calls (and not the OS), then anyone with a little bit of reverse engineering experience should be able to prove it and post the assembly.
Edit: I was wrong about the build toolchain, they were built by visual studio, see comment below.
this is not meant to imply anything about whether the binary is malicious or not.
This is almost certainly Windows performing certificate validation.
The "evidence" was just copy pasted from VirusTotal. In fact he forgot to copy from below the cut, which would have shown it also called out to www.microsoft.com - depending who you ask, definitely a malicious address!
VirusTotal just notes all network traffic during the time the binary executed in the sandbox. It doesn't mean it emanated from the binary.
A proposal in the attached issue suggests just building it from openbsd sources which is probably not the worst place to get source for tee.