| URL: | https://linkprotect.cudasvc.com/url?a=https%3a%2f%2furl.us.m.mimecastprotect.com%2fr%2fyjL1O27sqef8SriFmS_RZsdXYeoyIcecwGpXZUCk9lIT1_xxTiQGNTR1XkQKDcen-P-cOtkQ3abasmNKa2inLL_8mHMKih3gm99o3HQ7YgttZLdiPyCtruTSUZo2HCtNCcu7ihMc9-G4vTTiMWQqQas4CnHstQw5zSYybbdiBrDNyFWa9sM8yYLWP15q8Mxjv7pBbarLNyfXpo_vq-t_B11JbKMtm8u4dh-m4EqT6PpuDbkDdRisvtVmZGnytQDNxK05iLp76jDRCoQeG4Tn5Sqb90w8VmEbNTc_C5wpCp7qG2Ub0d7l8l1wtvTfmtI6aMI832U1ytvK11sgrGVtz85ZfjKuLgbJQah6OALVKmkYXxlJvCimLnH-S94XkQTREYZTqspxEAL9NbUrHnbZGdT_NlfdvW5rZ3q4ogbzTxjn8pHagA4oIlBGBOPA3ZdXQyqLALhW6x9fwogj7so8I9FVzMOP__BPH58qW7Zcb39kH3uva04YQMrsJiOm1TguBqTuzROexRd6YBqp_if-LLIzG_7T5bhuOTMiI2ppsNfJJhPyaK0uUFVtXos0iOqu7aFxU1x_we89IiWkXzB1_V8UDoPlrN8-xCymONiFXJ6ASYC_WIaseThITYcK7a0cbHQJJrp2Pk6J6Mo-QI4cYyhzXLpEDSOcGXGDLi7_ZVCVu5wlhYdnuj4xrCmDJcXWeRisDzEpVATALTZzH_o9oBgY7tUHPohrv9yrwYVhlozAEvB6nQwXKUQWTUwByPyeg4rmFwvxUhFcFhrNCgw-brJeqJKXSeZIhAyhn8MTXVAn5QLWBAznsdpafrtxAjF_HEoKSt7bLEB7j-RKOMuhDMSuNLPdAPBIbMxdgmXjAUdAcTXaOvsbjfMpKsOIeKk-1O0RYoDf325443mZuPedmlGk4b5wtTAhIsIjdhHz8BwEzACQnRx1sUT6kVWkj9R86M83vwyGn-QIQJ-ggDTnldruAfFsRZKGh-8Ml05e6IfHx8M5cBryB3XyC3vgctH6wyKDkv5swPL79g9w_SvMallv7UO7-Vp4PIoz8jEHIH_wOJ2yhWtENHbZAvSg7hh2h0sKE-rbKfc7sxKQsHiUNP15I-0IlvYBh6vmdHtnBJEX0Ecthz9zt4DNIMLZnm1y6LJzSnyBX7d18RdtCyTKCsoToKSIqhpjY3igW8zUhumUAxQJxN93QwgHDld0luTRE6VIE-13niCLPrbsL7l3SukAjse5o7_mkgXad9Zh9kEepoIYsFzQ2qTeQ3K0cHVp2vr3NwsgaTZ-wBSzEhAY2TNxdGEGep2ppTu5XFYCEfzwSDg3TEWL2Y_KQspADRQ6Rp_6dSrPJlg-lbVMteVpdBbonJDcI5xWcnCLAZE7dxda_6owWH5oYCR7vYqHNPduHh2myCB0mYnuPxjS-hbsM5Ps1rKJxGw0aUqJk_AK2kODPZ5deQGb97Nwb_lOUIz0PiqJGLt01Ld6KDZbAQhj0BdGD1T-S6XigrBTKrD5fDKE-MrJh2mA3Tl278GpmqS5oPGi42a4Fb6XE1QNY_T6M-9bdPQHzeIWtVOwD-piu1HX_PKwoz0IVPtdWu7MX_E7PhCmgOYFiitUXOAZC5jK3g1bUxvFGu22JrhvXMa0pupzjes2fQd4a8o8symRNKUEkJzuqF0H9lmBVWaKf4CIfwTJbL_b0hnhvSFfNFHIxC_FFZ6JFPeAOTdp680To8WgOyoY24w6sfQR1PqAjwf6Hl7D1u7vq0hi4hC3luSaP4k5Cgw_x51DmWf0KVQyauuYLDbvQLjjSo27BJ9VWDoYjIWjEPCeE1wLDZbdBJsprrezMKrI4lUj18Iu1w5dSX8WsAE0v7HslkeqB9X4euBhrKwVFyTWtaqfr_6flA2myAiq5CkQR2ExnBMNyFB6F3zb20NUdsFj7tUB6rySlObq03YHfZT9q4dqDzWTSBAi4PRZ2m2hrKgzmtAwtQX-cOz8_gAENInFsAzm7C4cyAVWlqDNU4LonWCozoBwHhC1gJKakYEGC77djtXuGXI9yvU_Rw0f1vFHtYV5Hw5fkf1u_s7zN-S7qjGUw52nJhk3X3eThzrDplwmOwB-j4AMM_j21lEOSFLweASNRmMNCSHUgZPTSPB5LoD0jrceYCz-ZZ1jsYYgpBS_B7WG1igoSqzNVOADI_1o9BjlAohrNEkr0fQKjGZU7ZjIlx6QGvt5WPy2HR4n_7JAbw8wmiQx3h9OC0J8xpNf6SXfZAvyJtI1pIMmlbWFVg4vKYJY9Rh27C-XYuZ1Q2M-PNJrbRHjye6xrq_82YMCbSskhh_h0pSh213nLzr4Nd0XcqUvFflyIqylfTTfGpxWUf8HOWZlBVsU96J6ina-gA59qrjx8n2dLykQ-PXuEBPFbmJILDtgAgyHlJYezozXpnfd6twdP1yxPzZwqKfwPHe1OmISRAS0EuimGENchUnNJukjRrdbciusiuEwspHQhox7831bRsBimAOSN-ffSOwdkHhDO9096oB2OosZNtjnnuC9sf30kbUrkbIB3-_Jvm2uvCgn14XdBd4Q8XY8EVlivyKwEsRiWAyNVJW_h_28d8S0BDHyeXZlIf6uNt1m-BToyo5fLlFotLDFMDkPOFwBSfgT1iEMeScpmj6aMhBldUgXqlCWJ3IREPFOt7ipZpqOCK5XOqTXS0M9o4eRF-_OlxX_gcNulXSatdrx-hMEzvBCUfgdVUB0VPGVlWIIzPqN7BMee6ii3jMvmp3STRTQGfGC3s2p8vOCZq4o7C0k79dWTeDSX6XELXS6VC9Q8mvwHPf9QLtww4fXFJkGznPGdAuJFRCBlxfSQNEPTLM-xzRZLEvgEQ2O6JhH8o5a1BJjpYtqY_WKBPaQREruyYrKBFzbPASx4EkGv4SApLty1OaQv2ksxHAm3l-wyuYvSidwKE0ux-6gOGpZKcTNo4Gw3-GTz4okxiyS9z1ioAucrolKi75oaqJ-B1Z6atq67F5syecy-2GApDh7o4S8a0dmVDqXQEvhAzfDxBSgREHs6UgCzstKbzkL4N6KAMeNTOBinef_3kJxqKQ5G3O3eyfPMOyxQDWmZCrEWlmLrskCkgErCizMM2H4N3TUDYvGtshfa2jH2tUVm59Ft6YkbGBk4VeJqT44R6nNOmOA5frXD0xQPKQ-dhcyzh9WjyXOZN9VPbnakIEPQ2ppbbbv52RkmLirNVwq1qUkM0O4cMg3ik-1sgdV9XKxtaiJ8qqDubkIUL_PqWt7ykC0pTXiZF2FWqRu2ddWSNrJoHZrxx0fPzh-KgX-0vVHn68R7q6I_HH-NwLhLDqQrsiDyghG6oKLAYl1ZHk7VNPNtkQk9ns-n3bmmQtRdeks4C_Shth8lL1-rqwoUIw1d1H6xGZt2UwkG2ZrXG-pYixpZdGUjpnXbAAi9JmtuGfmy2iDRPQ2WDS76Y9dcqnxDnm9SmQSAHAxCFp8-zOPR2vau9Db7ILZEFr9ETCpE5Lwn6-Xgjq-LfjJDW5npJkDl90FfRbm1PSxbLly4p8qQeTQNKkaqnbbLZlpeDc5fRGaYptM85HFymbA-VE9DCh3M04cBxI0hHmZgFRpHHl3eT63ZkBwDdj8kzKAtH7FG99o_Fi9a25gsLLraT32kZFwkf3iAX5kOEVBK3VxB8SzrAz0N_DQekY0ap1ZzvIjXzzCiKVY8b_yinKigaOGCKvzzoDY2IxGjwupK1-u4tIHuqtfM2o9p6vlFrEh6o27FhyhO-hiV8qzAwp0D5vU2Rmo6e9Yjb59FIR7Rg-WE4dkTkx1bt03BWTOtjDuV5TN6_fBnNhlt7DXqjWmL-Y14tbjDAc5PvzeRpUCP-HzmvLUIf9JJZNH_irb5e9EOzGXVdS_ssfdDi4rmqcMfWeAKVwA7miAqEbB_A94F_WsyjzBSuhEEqgU0zpI7UNqVWUrpNfx1dknOWJ8xJEbK-rzFX7G9tAla9RaUYYeM5rWy-4ibpB9UGV6RI9i2NDikzSTx1oA88cwDU20j-AKuU92XUu_Bdw6E8fG0ElNh3D233jUNcjiktjT0shv8brOPG7X0-LYUL3XQhxEOcg2EPb2NjNHK6h1BWuRAMo5y6UtxWVMicIhcR9Gpco6bl3VdPUI-WSKcoexvbMKGOjgS6ciZVXhzW9_4hjyGUdnxduswhx0aKoYhRNQt64Hh1dwkjlA71PzclRHOicK1SbQc_4eSqOn1HVi1LR7Ront2mud79xPao7d1s39FCew_1b7Q13s3t-gMV_4VhI9pZ6CoPJt1bCIyoy_0oHJJ_JXK8vYltk97lmO06bpyOF6v5d1bMArWmQln9iJbrBtGho9gd_aIN8C2V_V7Xna20S3MfVetM6izj8bNp_acN6C0UUq_q62dEmI7-brc7AziiEJ7mHR71NHt7eK2fZ5L8QOk2pRubjTMKQ5rYiS2Hd5G2eO9dJBvk0Qe-GCYVkuJLr8eh492Eui8WVFShL8qSUhqMgbNrHMAop0S6rc8l0q86UQoWtJ8hW3ul-xZl0a1dPjLB-8MHSdnFndfr-QtlW6CX2xUNm-qzQxbaVhUBBn-kkxfnVKvOg5ASIE2ayhpu5kBST0JmUKiVThqxETDoIIvjmrgEx3OVBO8ZKr1MxGYH7b2SyEQgtxiXaRMLbX_Nn_oOSYZYW2c3mTkb9yzlbak5X5Ic8TpbhudvZem6FVG8glgOmDFwUbYrLvOtLcORuEM4jTasNH7S3smkR1ld0oG4ZUZE2CjdqUWZMBzjrRkA_kzsnuij3De3hWQARtjpt9A7wpof7xFHaYQPNZo2a5wku142Hlr5hhq6O-zp2Xov3UzOKTshJe3nvbVhLHs3NVEl1kvZrsQ3myJcQpd8oC9hxdwG4RNYAunDbCp_0dFRWnGKGH6pjNi40qNG8zs_374ztLuzQUlj-_FEemwwpRbHN5Vs-g8zI9rj9DnUDViSIYknWDqNArNKHuPMO9W1-uu58DGa63fZAdVnS7SwFgW29MiMHmggpgvM8NlCfFyozeiEbmK4gkuCsMcS8jmU74Iri86zRXVXrKd0_abAttAJFA2mSpb2JijuV2nK9ULzrXpQDhFy0Pi53VMzy7-_qXQWpwQQdzceSEwZE9DNnb47FJGedCxkA3sBPBsdg-akDsfHPfeEWpwIXxWOKVzrKuEmgVMFQJ9PBj_G6cE_DXsOu4wzfcjpdOU7bHEVt_5eagUvJIhU0cd3U9kinWTjsDCujMu51bIjIKFpaMh8x4Oy3GfKrozMBO9gLh8m_RHGzG2X8wSs0Y95r5T34raLnvJWEfXdrVSmHguUwdCjHpfrCYBfAWbpKsnVXc8MsJg8VAw8MY81-xRaCH5FZqbmkskQ86eYtebm4mFZ2Rfxq5m_EkPK9r6KHQ8NBJYeX6qqh__liXs-6nRC3PmpkEFK2qrKhAe_szuCvSc8d0ExNBRspBaKne64G4axMlrnwlVEZuJTH2Zqq2kqdkzWPervJzuYaNpIlGUQdFqs8AjHpHJ7Rralwc_d4mHmbUaDpXMRNI-2zG5aaD8Mw1SWxmHjEYbBJ1H6fua7S9aRSez5YcEBo7a1YMfu1s2lPG9jAQLZ0XllciFZmFAtSW9Nt_J7KorReL6WcWrwVi6Y-j494GKzGs0_HfOslfhOiKm7I2RqX3hdnoCGdoPI-1yEEhCJxPcWbOtxdQmNVZqY80AI_OHPYooSJKr26PJBI247W093bM5T57CfwfJAg85KHT7TFSjvGbN1KgW8427pvBMb47ZHnKPsalT9fhGHxe6ytKaqz8AgvqfY8O5tGCu7s-oHKxHfzhuQxbvVUcbgemqRYuLf5ZMIv66lbQ5CXnTlbuG-crL9xavQl0Xfy7dp6vOCSpsH1lEWHRoLfPX-O3ydgziWR1eu1b2Aj0mmTfH1eljOGuwhAmRSAOROXEF9pa-FSXH5flsPkcGSSNJayTLyXJtruQ-cWvxNqegxxNWkfV-ChkxatkYEpefLREOHrYDmB_PpJTKx-8DSsPEFr_-jSsERUhjQBy1mehvOBenQPWxdQ3r3vBXeBv-hg97ez8F3Fw-FSLAlAX5a7Pabo701hPXm4ueJS2_mk-trmhiLBlGKPDnSb-6khNfjXHx8yh1olVXzyapvF9vaERBVtiqHi8oGbzib9urJI8h8dSdzvnuA5kcjMRcrpj4d9HQ9x8QDRVnixOIl-iwOsJ7ENgoSe8-DGaN_fLgFoYZcQ_uQPPdaaqvNjoombtGyUaor-Zt2cDngdc6VksQtRyB274sgeYGcMzqIyfWYOZrTosCMruX1jCEAYXtT29cMnHC-yYM89t5E65mckB8vn0abYwt0R00dUj8mxxVnbXS8qIf2ZE48-ozKQm4CNAvYiueVAGisITv3bN_5fYFSZ8n3Iu7OrBRZlt_FEI1ZH69sBNUfb47pjqOgv2zaWAW7-G1DgS0igm9FYaUkBKScHAg2Ulbb463ARo09r55A053xwiJ8PRANRnb6eR9ruz5TjoijAes31kYJl1n5zRx4ooRZeWsumM35Payerm8_LGntPYAw4NOFPqClCdO9x9ThM30p5f45ncY7fQGwHiazM87Fudd8wws4gnpfKPxK8GxGnWsWLHkef8mkhXr2V6ghrmcDtPH25KUCkL8oSVrrdAAsDKieUUvum8au47F-JHlI_xCtT3RliM5fiIaQulsJREFu419Qm2Q9ldiEjOdM_32ZSc6AGlCXL5fbIq7-UMgsx4vp0kEvt4ZRmiTsHHJZfwb2-UIHMU0rsYqOaTOnktmb7VgJgL18ZTqsj1F2BeUBn7NQkSHuIkBoslomequKOgzSNJKgVzmK9l1FEtbwUnxJacHl-DtAFSJV5ERtHoLigkTTQfXd679xJRXyFmLyNsGxOha2PxAWkh-PQdwTEn1EQJ2MSOsI5V1sGn1Nlwn6OF6psoU4shHdAwNFtFQ5XEv6nQY8txTcrztmzbOPwRkF5fs_AHpjhMGCFb01Zh0wqRtI6CMvYxV52s8rXSC5p2yCGgZlr-aY57MHY8PcEDxbCw-jZ8qjc9GCBRiSCX5mmMS_CFftS4beQgVv7qMoQ49_YhCQhdDqzw19GEELxBN6HLduVFzv9G4s0TzlMIUBQbXVkSuCdX8dlCl9ME6Vu6hH7naVb8tRehOif3quszwK5ijSeQ3paP4E_vktNaGTHYL2cefbznQRAEiJbTSmvnsuqHoL0Iyk4pdCcZEgEqGFv3gGMlr10sQ6cxeiOUasyptMehyorpaeo4aPe2NV03YVUjxbUa6u2shosHzFwnM8y7U9uePSwi5THi4RV9cvAbyvWxqSUTZ1U1LC_dwRnCZggOC9o_RW35I4HyWw5aTaZzaiENoZgI4CuxXTtQioLlT4tnN_gHsp9eVMH-AUioBcZCY-QSjD-p16GnSDl7j7ONdD1LPEmNx4uLLa1nCWg5Fh5S9yy1aQz7hJ1W9M_5S5zRTsmY3LdZupEwG3YgyzWeDjAmq-u0lbRXMDgS9KbQ3xUW_jVc29UTYs75oeu_WA0Op_hiaKM2Q0uHA3neQXIbttYXfX0c2JREBz_LxKveCMLFb9KYP-5eWFxPCQlMoRPi42XDK2_3SVSs-4WdKIuv--qTMkzWXdqCGPnUkRZG_Eo4VGgRIH1J6aVaq3Lo5yF8a5NPs2PEvx1QEvkLhgdu22fIHsONu2ikgfxj6ufXMFAxElN6D5NFbN29PpaCfpOKTKAyi0UrQzDVbymt-xktUrm7T96mG5wSeOBzd1lsT4a_28qjrRmTXG7xhA8HzZhd_VF2dhS2c4Z03k4ngrg5bru3pyMb9Vd30fgwHbRm-WqCGt2uHX14RvlzKezT4-HV3zETetGqod-tq8b_wKR0B32VDDH4WjibEA&c=E,1,8gl1dzy_GH3A8V3bcp0iqKLSEZS9k1Yx_vJitul9dMxxSyvMvpmn8URshl5XDXzdCc1L3JaDQvXW6cZtxh56zThg4ANTaVYWXuboQNgYnoI203NokvbB0Rdwz4M,&typo=1 |
| Full analysis: | https://app.any.run/tasks/4019fd06-92c1-495c-8ab7-40d7b9a19cb2 |
| Verdict: | Malicious activity |
| Analysis date: | August 01, 2025, 04:38:06 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 35932786910F3819248AE4E2614F4BA5 |
| SHA1: | 53D621A6EBC8EEDB36B33F5440378952BDBD5A46 |
| SHA256: | 12CDA625AF02ED2CBECA18D516117CD0A387B19ADDBCB16C83E683B34C9E3D2D |
| SSDEEP: | 192:8jvxPGN7r0GFO/vdGvRYB0MNxIR6RGUQphcbGvQYRAF9qN:8RI7vFO/lMRYB0MTVZFKPywN |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1800 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3512,i,1690645231552070525,17662747694465136553,262144 --variations-seed-version --mojo-platform-channel-handle=3688 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1944 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --always-read-main-dll --field-trial-handle=3740,i,1690645231552070525,17662747694465136553,262144 --variations-seed-version --mojo-platform-channel-handle=6180 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2612 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=22 --always-read-main-dll --field-trial-handle=5660,i,1690645231552070525,17662747694465136553,262144 --variations-seed-version --mojo-platform-channel-handle=7152 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2728 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2216,i,1690645231552070525,17662747694465136553,262144 --variations-seed-version --mojo-platform-channel-handle=2204 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 3840 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3620,i,1690645231552070525,17662747694465136553,262144 --variations-seed-version --mojo-platform-channel-handle=3776 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 4172 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x304,0x308,0x30c,0x2fc,0x314,0x7ffc4321f208,0x7ffc4321f214,0x7ffc4321f220 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 4916 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2004,i,1690645231552070525,17662747694465136553,262144 --variations-seed-version --mojo-platform-channel-handle=2356 /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 5504 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6196,i,1690645231552070525,17662747694465136553,262144 --variations-seed-version --mojo-platform-channel-handle=6412 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 6304 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4344,i,1690645231552070525,17662747694465136553,262144 --variations-seed-version --mojo-platform-channel-handle=4336 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 6376 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2684,i,1690645231552070525,17662747694465136553,262144 --variations-seed-version --mojo-platform-channel-handle=2700 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| (PID) Process: | (6492) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (6492) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (6492) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (6492) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (6492) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (6492) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: B52DEB9BDC992F00 | |||
| (PID) Process: | (6492) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\394002 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {74277A54-9B5B-4E3E-AC49-4789D4D44DFE} | |||
| (PID) Process: | (6492) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (6492) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\394002 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {70A3343C-4088-41C4-A4A9-0057E85D3827} | |||
| (PID) Process: | (6492) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\394002 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {8DCA6E21-B5F0-4462-AC4E-CBCDAFB8C235} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6492 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF18d4ef.TMP | — | |
MD5:— | SHA256:— | |||
| 6492 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6492 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF18d4fe.TMP | — | |
MD5:— | SHA256:— | |||
| 6492 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6492 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF18d52d.TMP | — | |
MD5:— | SHA256:— | |||
| 6492 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF18d52d.TMP | — | |
MD5:— | SHA256:— | |||
| 6492 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6492 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6492 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF18d51d.TMP | — | |
MD5:— | SHA256:— | |||
| 6492 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4916 | msedge.exe | GET | 200 | 150.171.28.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:pI4jzzD4H_fwZ1V_YONM637d6RCL8NsauCkCv6PE21o&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | unknown | — | — | whitelisted |
6216 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7576 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7576 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1268 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6356 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4916 | msedge.exe | 150.171.22.17:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4916 | msedge.exe | 150.171.28.11:80 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4916 | msedge.exe | 18.192.77.43:443 | linkprotect.cudasvc.com | AMAZON-02 | DE | whitelisted |
4916 | msedge.exe | 150.171.28.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4916 | msedge.exe | 92.123.104.53:443 | copilot.microsoft.com | Akamai International B.V. | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
linkprotect.cudasvc.com |
| whitelisted |
copilot.microsoft.com |
| whitelisted |
url.us.m.mimecastprotect.com |
| whitelisted |
url.emailprotection.link |
| whitelisted |
www.bing.com |
| whitelisted |
xpaywalletcdn.azureedge.net |
| whitelisted |