File name:

uehh.exe

Full analysis: https://app.any.run/tasks/cb5b4b17-559a-40cd-9e3f-42bb312370e7
Verdict: Malicious activity
Analysis date: December 23, 2024, 11:21:44
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

C29215C09E5327546AE851A271A86BA9

SHA1:

13463D49CCEDB3B068BA8E406185B940CABA0D27

SHA256:

05021C2F4DF2687154F46B87E6C4EE7407DF95A81B24B470BE3333867074AB19

SSDEEP:

3072:eITLlTTLb4lasSHyWYCEld+dK9XS0MPwxPfxXrP/m5K:eItTTJRH/YdACP/m5K

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Detects Cygwin installation

      • WinRAR.exe (PID: 4704)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 4704)
    • Reads Microsoft Outlook installation path

      • update.exe (PID: 2280)
      • update.exe (PID: 5592)
      • hh.exe (PID: 2436)
    • Reads security settings of Internet Explorer

      • update.exe (PID: 2280)
      • update.exe (PID: 5592)
      • uedit64.exe (PID: 4528)
    • Executes application which crashes

      • update.exe (PID: 2280)
    • Reads Internet Explorer settings

      • hh.exe (PID: 2436)
      • uedit64.exe (PID: 4528)
    • Creates/Modifies COM task schedule object

      • uedit64.exe (PID: 4528)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 4704)
      • update.exe (PID: 1512)
      • update.exe (PID: 2280)
      • update.exe (PID: 648)
      • update.exe (PID: 5592)
      • msedge.exe (PID: 5304)
      • UACHelper.exe (PID: 1416)
      • UACHelper.exe (PID: 4968)
      • idmcl.exe (PID: 1488)
      • UACHelper.exe (PID: 2160)
      • UACHelper.exe (PID: 6152)
      • hh.exe (PID: 2436)
      • uedit64.com (PID: 2012)
      • UEDOS32.exe (PID: 1904)
      • msedge.exe (PID: 2572)
      • uedit64.exe (PID: 1356)
    • Checks supported languages

      • uehh.exe (PID: 4824)
      • update.exe (PID: 2280)
      • update.exe (PID: 5592)
      • identity_helper.exe (PID: 6368)
      • UACHelper.exe (PID: 4968)
      • idmcl.exe (PID: 1488)
      • uedit64.com (PID: 2012)
      • uedit64.exe (PID: 4528)
      • IDMMonitor.exe (PID: 6368)
      • uedit64.exe (PID: 1356)
      • IDMMonitor.exe (PID: 6164)
      • ues_ctags.exe (PID: 2216)
      • ues_ctags.exe (PID: 4244)
      • ues_ctags.exe (PID: 3092)
      • UEDOS32.exe (PID: 1904)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 4704)
      • update.exe (PID: 2280)
      • update.exe (PID: 5592)
      • uedit64.exe (PID: 4528)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4704)
      • msedge.exe (PID: 6152)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 4704)
      • hh.exe (PID: 2436)
      • msedge.exe (PID: 6152)
    • Create files in a temporary directory

      • update.exe (PID: 2280)
      • update.exe (PID: 5592)
      • uedit64.exe (PID: 4528)
    • Process checks whether UAC notifications are on

      • update.exe (PID: 2280)
      • update.exe (PID: 5592)
    • Reads the computer name

      • update.exe (PID: 2280)
      • update.exe (PID: 5592)
      • uedit64.exe (PID: 4528)
    • Checks proxy server information

      • update.exe (PID: 2280)
      • WerFault.exe (PID: 3884)
      • update.exe (PID: 5592)
      • hh.exe (PID: 2436)
      • uedit64.exe (PID: 4528)
    • Reads security settings of Internet Explorer

      • WerFault.exe (PID: 3884)
      • hh.exe (PID: 2436)
    • Application launched itself

      • msedge.exe (PID: 5304)
      • msedge.exe (PID: 4244)
      • msedge.exe (PID: 6672)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 3884)
      • UACHelper.exe (PID: 2160)
      • hh.exe (PID: 2436)
      • uedit64.exe (PID: 4528)
      • uedit64.exe (PID: 1356)
    • Reads Microsoft Office registry keys

      • uedit64.exe (PID: 4528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:02:04 18:35:03+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 54784
InitializedDataSize: 29696
UninitializedDataSize: -
EntryPoint: 0x169a
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
232
Monitored processes
93
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
448"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6160 --field-trial-handle=2332,i,14562937680661893996,2359969075078974430,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
648"C:\Users\admin\Desktop\UltraEdit\update.exe" C:\Users\admin\Desktop\UltraEdit\update.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\ultraedit\update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
648"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5256 --field-trial-handle=2332,i,14562937680661893996,2359969075078974430,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
776\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeues_ctags.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1076\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeues_ctags.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1328"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5260 --field-trial-handle=2332,i,14562937680661893996,2359969075078974430,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1356"C:\Users\admin\Desktop\UltraEdit\uedit64.exe" C:\Users\admin\Desktop\UltraEdit\uedit64.exeexplorer.exe
User:
admin
Company:
IDM Computer Solutions, Inc.
Integrity Level:
MEDIUM
Description:
UltraEdit Professional Text/Hex Editor
Exit code:
0
Version:
28.00.0.66
Modules
Images
c:\users\admin\desktop\ultraedit\uedit64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1412"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2644 --field-trial-handle=2396,i,3679529484896080314,4994623713895938291,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1416"C:\Users\admin\Desktop\UltraEdit\UACHelper.exe" C:\Users\admin\Desktop\UltraEdit\UACHelper.exeexplorer.exe
User:
admin
Company:
IDM Computer Solutions, Inc.
Integrity Level:
MEDIUM
Description:
UAC helper utility
Exit code:
3221226540
Version:
1.0.0.5
Modules
Images
c:\users\admin\desktop\ultraedit\uachelper.exe
c:\windows\system32\ntdll.dll
1488"C:\Users\admin\Desktop\UltraEdit\idmcl.exe" C:\Users\admin\Desktop\UltraEdit\idmcl.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\ultraedit\idmcl.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
19 094
Read events
18 969
Write events
120
Delete events
5

Modification events

(PID) Process:(4704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(4704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(4704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(4704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\UltraEdit.zip
(PID) Process:(4704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2280) update.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2280) update.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
82
Suspicious files
1 020
Text files
632
Unknown types
8

Dropped files

PID
Process
Filename
Type
4704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4704.24543\UltraEdit\changes.txttext
MD5:2112DDA6FFCA604C973C959C992979A9
SHA256:5A49F42F7669E965B6A5BE53C56552344536966C240194AA233C31E04FD075F7
4704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4704.24543\UltraEdit\default data\themes\Charcoal.ue-themexml
MD5:BA9EAFD09F293C2E8DB046622E518241
SHA256:1C777EFF316390E55B05A195022B025F36F49CEA51F9CC26BFEBBEF248A221CC
4704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4704.24543\UltraEdit\default data\themes\Classic.ue-themexml
MD5:BEAD5EAF2A6EA532C2F48EAF87E54B56
SHA256:3E76B199DA2B0D7418841219310A69AC8A1E144325DAF37D2AA358C17AA14BDE
4704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4704.24543\UltraEdit\dbghelp.dllexecutable
MD5:6B811708C844E865859B25C097534E4B
SHA256:262DA3D61BCADA823BDC1EC82732527A976A78FC60BD51E977E61A017ABF21F3
4704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4704.24543\UltraEdit\default data\themes\Espresso.ue-themexml
MD5:CF9966D0848A98D36C5FDDD4E0F2B9F5
SHA256:A73B7ECCFE77FB970A08EC288C7EA2FE7B4435BE8C3638FD7EAAF152CC3F64F9
4704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4704.24543\UltraEdit\default data\themes\Midnight.ue-themexml
MD5:3ABE14811ACFDA8141471EACA2CBF13F
SHA256:C2AD50C9BD360D3457010BED7B4052C9DFF9D848303B5DDBE12DDB9D66A3F4D1
4704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4704.24543\UltraEdit\default data\themes\Modern Light.ue-themexml
MD5:E040DB8F5B3057E5DFDB30D8B35C3723
SHA256:38220A0C15616B0D211EFE88E8BF2DE03AFBBAA98F5D0C6A9EF1B07C38D7014D
4704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4704.24543\UltraEdit\default data\themes\Slate.ue-themexml
MD5:E1A116CEA4A9100971CCCF247157C84C
SHA256:EF1EAEE9DE300740ADFDB204D8B5E31F92B34132B0CB0D18D6583BEB30AEBFFF
4704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4704.24543\UltraEdit\default data\themes\Sterling.ue-themexml
MD5:18F8F37ACA5DE12B33684DD9FB89BEC6
SHA256:A12405653CE8B32E8FCE6DEFEFB50E0E4143C625458FFF19084D54170133BFAF
4704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4704.24543\UltraEdit\default data\themes\Glitch.ue-themexml
MD5:EAC93594B3F0F37260AF9FA79B8CCD5C
SHA256:671B0ADE7D3611B00823D412B9AB7561A5DA026028B42CC8661F3832C3013FC9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
56
TCP/UDP connections
138
DNS requests
188
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
314 b
whitelisted
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
5836
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
US
binary
471 b
whitelisted
5912
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
418 b
whitelisted
5912
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
3884
WerFault.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
6900
msedge.exe
GET
304
69.192.161.44:80
http://r3.i.lencr.org/
DE
whitelisted
6900
msedge.exe
GET
304
69.192.161.44:80
http://x1.i.lencr.org/
DE
whitelisted
760
lsass.exe
GET
200
172.217.18.3:80
http://c.pki.goog/r/gsr1.crl
US
binary
1.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1684
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.23.209.158:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.110
whitelisted
www.bing.com
  • 2.23.209.158
  • 2.23.209.160
  • 2.23.209.144
  • 2.23.209.149
  • 2.23.209.177
  • 2.23.209.156
  • 2.23.209.176
  • 2.23.209.148
  • 2.23.209.150
  • 104.126.37.171
  • 104.126.37.163
  • 104.126.37.161
  • 104.126.37.168
  • 104.126.37.170
  • 104.126.37.162
  • 104.126.37.153
  • 104.126.37.155
  • 104.126.37.160
  • 2.23.209.154
  • 2.23.209.141
  • 2.23.209.140
  • 2.23.209.143
  • 2.23.209.183
  • 2.23.209.181
  • 2.23.209.189
  • 2.23.209.182
  • 2.23.209.185
  • 2.23.209.179
  • 2.23.209.130
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.72
  • 23.53.40.178
  • 23.53.40.176
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 184.30.21.171
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.73
  • 20.190.159.75
  • 20.190.159.23
  • 20.190.159.68
  • 20.190.159.71
  • 20.190.159.64
  • 40.126.31.71
whitelisted
go.microsoft.com
  • 184.28.89.167
  • 23.35.238.131
whitelisted
arc.msn.com
  • 20.223.35.26
  • 20.31.169.57
  • 20.103.156.88
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted

Threats

PID
Process
Class
Message
6900
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
6900
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
6900
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
6900
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
No debug info