URL:

https://you.dj/desktop/YouDJ_Desktop_Win64.exe

Full analysis: https://app.any.run/tasks/5674c4b3-e696-4045-b134-72b5b0905ca2
Verdict: Malicious activity
Analysis date: July 27, 2024, 09:58:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
discord
Indicators:
MD5:

4901A4685AB06C470DA889CC435D4194

SHA1:

A6934A10C84EA78517AF0A5AC3F9902C68515B72

SHA256:

08B0100832F4950490D75BBF4B2952A219BC20B9530C39B9D9B8F06BB3B1DEDC

SSDEEP:

3:N8u1yBZVKIJDjd0C:2uIzT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Application launched itself

      • YOUDJ DESKTOP.exe (PID: 2348)
  • INFO

    • Reads the computer name

      • YOUDJ DESKTOP.exe (PID: 2348)
      • YOUDJ DESKTOP.exe (PID: 7812)
      • YOUDJ DESKTOP.exe (PID: 7656)
      • YOUDJ DESKTOP.exe (PID: 3188)
    • Reads product name

      • YOUDJ DESKTOP.exe (PID: 8000)
    • Checks supported languages

      • YOUDJ DESKTOP.exe (PID: 7812)
      • YOUDJ DESKTOP.exe (PID: 2348)
      • YOUDJ DESKTOP.exe (PID: 7656)
      • YOUDJ DESKTOP.exe (PID: 3472)
      • YOUDJ DESKTOP.exe (PID: 8000)
      • YOUDJ DESKTOP.exe (PID: 3188)
    • Checks proxy server information

      • YOUDJ DESKTOP.exe (PID: 2348)
    • Reads the machine GUID from the registry

      • YOUDJ DESKTOP.exe (PID: 2348)
    • Creates files or folders in the user directory

      • YOUDJ DESKTOP.exe (PID: 2348)
      • YOUDJ DESKTOP.exe (PID: 7656)
    • Process checks computer location settings

      • YOUDJ DESKTOP.exe (PID: 3472)
      • YOUDJ DESKTOP.exe (PID: 2348)
      • YOUDJ DESKTOP.exe (PID: 8000)
    • Attempting to use instant messaging service

      • YOUDJ DESKTOP.exe (PID: 7656)
    • Create files in a temporary directory

      • YOUDJ DESKTOP.exe (PID: 2348)
    • Reads Environment values

      • YOUDJ DESKTOP.exe (PID: 8000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
228
Monitored processes
7
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
msedge.exe youdj desktop.exe no specs youdj desktop.exe no specs youdj desktop.exe no specs youdj desktop.exe youdj desktop.exe no specs youdj desktop.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1884"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2424 --field-trial-handle=2344,i,10653875144477300074,7620620038322642547,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2348"C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exe" C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exeexplorer.exe
User:
admin
Company:
YouDJ
Integrity Level:
MEDIUM
Description:
YOUDJ DESKTOP
Version:
19.2.0
Modules
Images
c:\users\admin\appdata\local\programs\youdj\youdj desktop.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3188"C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --user-data-dir="C:\Users\admin\AppData\Roaming\YOUDJ DESKTOP" --mojo-platform-channel-handle=3272 --field-trial-handle=1692,i,3137145513301497892,16379056138135112462,131072 --disable-features=BlinkSchedulerMicroTaskQueuePerWindowAgent,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exeYOUDJ DESKTOP.exe
User:
admin
Company:
YouDJ
Integrity Level:
LOW
Description:
YOUDJ DESKTOP
Version:
19.2.0
Modules
Images
c:\users\admin\appdata\local\programs\youdj\youdj desktop.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3472"C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\YOUDJ DESKTOP" --app-path="C:\Users\admin\AppData\Local\Programs\YOUDJ\resources\app.asar" --enable-sandbox --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2440 --field-trial-handle=1692,i,3137145513301497892,16379056138135112462,131072 --disable-features=BlinkSchedulerMicroTaskQueuePerWindowAgent,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exeYOUDJ DESKTOP.exe
User:
admin
Company:
YouDJ
Integrity Level:
LOW
Description:
YOUDJ DESKTOP
Exit code:
0
Version:
19.2.0
Modules
Images
c:\users\admin\appdata\local\programs\youdj\youdj desktop.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7656"C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\YOUDJ DESKTOP" --mojo-platform-channel-handle=2084 --field-trial-handle=1692,i,3137145513301497892,16379056138135112462,131072 --disable-features=BlinkSchedulerMicroTaskQueuePerWindowAgent,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exe
YOUDJ DESKTOP.exe
User:
admin
Company:
YouDJ
Integrity Level:
MEDIUM
Description:
YOUDJ DESKTOP
Version:
19.2.0
Modules
Images
c:\users\admin\appdata\local\programs\youdj\youdj desktop.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7812"C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\YOUDJ DESKTOP" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1664 --field-trial-handle=1692,i,3137145513301497892,16379056138135112462,131072 --disable-features=BlinkSchedulerMicroTaskQueuePerWindowAgent,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exeYOUDJ DESKTOP.exe
User:
admin
Company:
YouDJ
Integrity Level:
LOW
Description:
YOUDJ DESKTOP
Version:
19.2.0
Modules
Images
c:\users\admin\appdata\local\programs\youdj\youdj desktop.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8000"C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\YOUDJ DESKTOP" --app-path="C:\Users\admin\AppData\Local\Programs\YOUDJ\resources\app.asar" --no-sandbox --no-zygote --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2728 --field-trial-handle=1692,i,3137145513301497892,16379056138135112462,131072 --disable-features=BlinkSchedulerMicroTaskQueuePerWindowAgent,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1C:\Users\admin\AppData\Local\Programs\YOUDJ\YOUDJ DESKTOP.exeYOUDJ DESKTOP.exe
User:
admin
Company:
YouDJ
Integrity Level:
MEDIUM
Description:
YOUDJ DESKTOP
Version:
19.2.0
Modules
Images
c:\users\admin\appdata\local\programs\youdj\youdj desktop.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
3 162
Read events
3 144
Write events
0
Delete events
18

Modification events

(PID) Process:(2348) YOUDJ DESKTOP.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Spelling\Dictionaries
Operation:delete valueName:en-US
Value:
(PID) Process:(2348) YOUDJ DESKTOP.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Spelling\Dictionaries
Operation:delete valueName:en
Value:
(PID) Process:(2348) YOUDJ DESKTOP.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Spelling\Dictionaries
Operation:delete valueName:_Global_
Value:
Executable files
1
Suspicious files
48
Text files
35
Unknown types
0

Dropped files

PID
Process
Filename
Type
1884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Network\1df6b729-3983-4986-9021-fa734dfa6217.tmpini
MD5:D751713988987E9331980363E24189CE
SHA256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
1884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Network\SCT Auditing Pending Reportsini
MD5:D751713988987E9331980363E24189CE
SHA256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
1884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Network\SCT Auditing Pending Reports~RF1eb8fd.TMPini
MD5:D751713988987E9331980363E24189CE
SHA256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
1884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Network\SCT Auditing Pending Reports~RF1eb45a.TMPini
MD5:D751713988987E9331980363E24189CE
SHA256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
1884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Network\6905deb9-fd77-4618-a9ba-49a27157d66e.tmpini
MD5:D751713988987E9331980363E24189CE
SHA256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
1884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\f_000184text
MD5:C9383CF96821455E6E24A111F2BC7367
SHA256:0BEAC9439F7C4A767355BE57C792813102044E0CA8BEC8B2F966E90195CA2429
1884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\f_00018cini
MD5:7F04122FAC450289C5495297BB789A36
SHA256:30062A15F8BAA8B3EB76AC3FF22C7170DD80360044511F478F32F029094990FB
1884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\f_00018ecompressed
MD5:9650FEFE2E26DF37EE19A041B5EC8987
SHA256:C59A3B9E8EA12061F52A0B3756F8809AE6AC3EF939C5FBA3775ADCB9B0603833
1884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\f_000182binary
MD5:7FAA63F1DF39C5C5397AD360FB93BD8D
SHA256:4D4050D9F27A1CC346AEE977E1A1A1E9A7F28CCF223F0579A889C7F803937D97
1884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\f_000180ini
MD5:B199798520B7234EA02A8A1A2E49250F
SHA256:2F7D32B7EB798DBD42A6ECA8EA850EA68732B3FEFD16EF5ABF0F3E0E9C763268
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
120
DNS requests
162
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4792
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3676
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
3184
svchost.exe
GET
206
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/cea6d764-36bf-4144-a357-ec91013ddbf5?P1=1722624441&P2=404&P3=2&P4=l4M%2fcTpzjd7l%2baG8pSLbm2DqajG5jh3uTBGmS2lIEQ3QAv8vmEYuyPpyE52pswBcPZQV4M8mxfTFgez%2f6nCMBg%3d%3d
unknown
whitelisted
3184
svchost.exe
HEAD
200
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/cea6d764-36bf-4144-a357-ec91013ddbf5?P1=1722624441&P2=404&P3=2&P4=l4M%2fcTpzjd7l%2baG8pSLbm2DqajG5jh3uTBGmS2lIEQ3QAv8vmEYuyPpyE52pswBcPZQV4M8mxfTFgez%2f6nCMBg%3d%3d
unknown
whitelisted
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
3184
svchost.exe
GET
206
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/cea6d764-36bf-4144-a357-ec91013ddbf5?P1=1722624441&P2=404&P3=2&P4=l4M%2fcTpzjd7l%2baG8pSLbm2DqajG5jh3uTBGmS2lIEQ3QAv8vmEYuyPpyE52pswBcPZQV4M8mxfTFgez%2f6nCMBg%3d%3d
unknown
whitelisted
3184
svchost.exe
GET
206
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/cea6d764-36bf-4144-a357-ec91013ddbf5?P1=1722624441&P2=404&P3=2&P4=l4M%2fcTpzjd7l%2baG8pSLbm2DqajG5jh3uTBGmS2lIEQ3QAv8vmEYuyPpyE52pswBcPZQV4M8mxfTFgez%2f6nCMBg%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2.16.110.168:443
www.bing.com
Akamai International B.V.
DE
unknown
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2856
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
239.255.255.250:1900
whitelisted
3848
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
whitelisted
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
www.bing.com
  • 2.16.110.168
  • 2.16.110.170
  • 2.16.110.171
  • 2.16.110.203
  • 2.16.110.136
  • 2.16.110.123
  • 2.16.110.195
  • 2.23.209.182
  • 2.23.209.176
  • 2.23.209.133
  • 2.23.209.185
  • 2.23.209.148
  • 2.23.209.140
  • 2.23.209.130
  • 2.23.209.149
  • 2.23.209.187
  • 2.23.209.179
  • 2.23.209.189
  • 2.23.209.177
  • 2.23.209.181
  • 2.23.209.183
  • 2.23.209.135
whitelisted
google.com
  • 142.250.185.238
whitelisted
you.dj
  • 51.79.80.223
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.45
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted

Threats

PID
Process
Class
Message
1884
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1884
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
7656
YOUDJ DESKTOP.exe
Misc activity
ET INFO Observed Discord Domain in DNS Lookup (discord .com)
7656
YOUDJ DESKTOP.exe
Misc activity
ET INFO Observed Discord Domain in DNS Lookup (discord .com)
No debug info