File name:

setup.exe

Full analysis: https://app.any.run/tasks/7ae73afa-c2b6-411c-8cd1-0b5dc72fbce7
Verdict: Malicious activity
Analysis date: February 01, 2024, 16:05:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

32B7EC50313C4AE18E64A482897282F6

SHA1:

FED5F91B4F2257501E0C0EB8DE47E4400F3A6467

SHA256:

12EB6FC247B9DE069541EA646FE289FC2D231A01D79035F05AA1BCBA08F0089D

SSDEEP:

98304:rSM4ADOmrcLRM3T+fUZMBk3upzCvf8lwQuNNVnjzXD56B8gTj5eMrgFhcXHVlI2Q:vJ9dth

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • setup.exe (PID: 532)
      • setup.exe (PID: 1288)
      • setup.tmp (PID: 2088)
    • Creates a writable file in the system directory

      • setup.tmp (PID: 2088)
    • Registers / Runs the DLL via REGSVR32.EXE

      • setup.tmp (PID: 2088)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setup.exe (PID: 532)
      • setup.exe (PID: 1288)
      • setup.tmp (PID: 2088)
    • Process drops legitimate windows executable

      • setup.tmp (PID: 2088)
    • Process drops SQLite DLL files

      • setup.tmp (PID: 2088)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 1028)
      • regsvr32.exe (PID: 3244)
    • Reads the Internet Settings

      • load.exe (PID: 3084)
      • setup.exe (PID: 2768)
    • Reads the Windows owner or organization settings

      • setup.tmp (PID: 2088)
    • Reads Microsoft Outlook installation path

      • setup.exe (PID: 2768)
    • Reads Internet Explorer settings

      • setup.exe (PID: 2768)
    • Uses TASKKILL.EXE to kill process

      • setup.exe (PID: 2768)
  • INFO

    • Checks supported languages

      • setup.tmp (PID: 268)
      • setup.exe (PID: 1288)
      • setup.exe (PID: 532)
      • setup.tmp (PID: 2088)
      • load.exe (PID: 3084)
      • setup.exe (PID: 2768)
      • Printer.exe (PID: 3024)
      • Printer.exe (PID: 3704)
      • Appdata.exe (PID: 3412)
      • Appdata.exe (PID: 3244)
      • vict.exe (PID: 2948)
    • Create files in a temporary directory

      • setup.exe (PID: 532)
      • setup.tmp (PID: 2088)
      • setup.exe (PID: 1288)
      • load.exe (PID: 3084)
      • Printer.exe (PID: 3024)
      • setup.exe (PID: 2768)
      • Appdata.exe (PID: 3412)
      • Printer.exe (PID: 3704)
      • Appdata.exe (PID: 3244)
    • Reads the computer name

      • setup.tmp (PID: 268)
      • setup.tmp (PID: 2088)
      • load.exe (PID: 3084)
      • setup.exe (PID: 2768)
      • Appdata.exe (PID: 3412)
      • Printer.exe (PID: 3024)
      • Appdata.exe (PID: 3244)
      • Printer.exe (PID: 3704)
    • Reads mouse settings

      • regsvr32.exe (PID: 3244)
      • regsvr32.exe (PID: 2784)
      • setup.exe (PID: 2768)
    • Reads the machine GUID from the registry

      • load.exe (PID: 3084)
      • Printer.exe (PID: 3024)
      • setup.exe (PID: 2768)
      • Printer.exe (PID: 3704)
      • Appdata.exe (PID: 3244)
      • Appdata.exe (PID: 3412)
    • Creates files in the program directory

      • setup.tmp (PID: 2088)
    • Application launched itself

      • msedge.exe (PID: 3380)
      • chrome.exe (PID: 984)
      • msedge.exe (PID: 1220)
    • Manual execution by a user

      • msedge.exe (PID: 1220)
      • chrome.exe (PID: 984)
      • notepad.exe (PID: 120)
      • explorer.exe (PID: 2112)
    • Creates files or folders in the user directory

      • Appdata.exe (PID: 3412)
      • setup.exe (PID: 2768)
      • vict.exe (PID: 2948)
      • Appdata.exe (PID: 3244)
    • Checks proxy server information

      • setup.exe (PID: 2768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (81.5)
.exe | Win32 Executable Delphi generic (10.5)
.exe | Win32 Executable (generic) (3.3)
.exe | Win16/32 Executable Delphi generic (1.5)
.exe | Generic Win/DOS Executable (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 189440
UninitializedDataSize: -
EntryPoint: 0x9c40
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion:
LegalCopyright:
ProductName:
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
107
Monitored processes
61
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start setup.exe setup.tmp no specs setup.exe setup.tmp regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs load.exe no specs setup.exe no specs printer.exe no specs msedge.exe no specs appdata.exe no specs msedge.exe no specs printer.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs taskkill.exe no specs appdata.exe no specs notepad.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs explorer.exe no specs vict.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Windows\system32\notepad.exe" C:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
268"C:\Users\admin\AppData\Local\Temp\is-DC70C.tmp\setup.tmp" /SL5="$F0184,3968520,228352,C:\Users\admin\AppData\Local\Temp\setup.exe" C:\Users\admin\AppData\Local\Temp\is-DC70C.tmp\setup.tmpsetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-dc70c.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
532"C:\Users\admin\AppData\Local\Temp\setup.exe" C:\Users\admin\AppData\Local\Temp\setup.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
668"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\6.ocx"C:\Windows\System32\regsvr32.exesetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
840"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2180 --field-trial-handle=1176,i,7274354115585057820,5251142874593928228,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
880"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3904 --field-trial-handle=1324,i,12904983657211228415,7582691034976135888,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
984"C:\Program Files\Google\Chrome\Application\chrome.exe" "--disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1028"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\msvbvm60.dll"C:\Windows\System32\regsvr32.exesetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1112"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1612 --field-trial-handle=1176,i,7274354115585057820,5251142874593928228,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1220"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate http://www.ematrixsoft.com/data/down/welcome.phpC:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 280
Read events
10 040
Write events
156
Delete events
84

Modification events

(PID) Process:(2088) setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\MSCOMCTL.OCX
Value:
1
(PID) Process:(3248) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(3248) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(3248) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(3248) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(3248) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE3-47EB-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(3248) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE7-47EB-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(2784) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B09DE715-87C1-11D1-8BE3-0000F8754DA1}
Operation:delete keyName:(default)
Value:
(PID) Process:(2784) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{586A6352-87C8-11D1-8BE3-0000F8754DA1}
Operation:delete keyName:(default)
Value:
(PID) Process:(2784) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{603C7E80-87C2-11D1-8BE3-0000F8754DA1}
Operation:delete keyName:(default)
Value:
Executable files
27
Suspicious files
259
Text files
130
Unknown types
0

Dropped files

PID
Process
Filename
Type
2088setup.tmpC:\Program Files\PW2\unins000.exeexecutable
MD5:A67E2F570703C107CBC3127C7D42DE47
SHA256:5790D1ACA138FC4FF2FDB8CBFC6EFD858F2CD2FE0C9BE4ED7E6E397B351C5554
532setup.exeC:\Users\admin\AppData\Local\Temp\is-DC70C.tmp\setup.tmpexecutable
MD5:A939D892E31F5696436400F2C54CC12D
SHA256:6BE1E7F5AF06BDC69438C4DB7BC6951D529679234D9BDB7C32538A752ED55A10
2088setup.tmpC:\Program Files\PW2\is-6NEBK.tmpexecutable
MD5:A67E2F570703C107CBC3127C7D42DE47
SHA256:5790D1ACA138FC4FF2FDB8CBFC6EFD858F2CD2FE0C9BE4ED7E6E397B351C5554
2088setup.tmpC:\Windows\system32\is-1I6L4.tmpexecutable
MD5:DE6255DC762181DED0F98230815E79D4
SHA256:154F8A4B89FF922BCA9D9D5A1A240A25F4E507FC89B824A4E629672205601440
2088setup.tmpC:\Program Files\PW2\is-R1HEM.tmpexecutable
MD5:4D328694BB516E46D2D184950D94433F
SHA256:8199452AF9E5289C126D0FF9D99F2302C52861EC49008702B7F95D64D316383C
2088setup.tmpC:\Windows\System32\6.ocxexecutable
MD5:DE6255DC762181DED0F98230815E79D4
SHA256:154F8A4B89FF922BCA9D9D5A1A240A25F4E507FC89B824A4E629672205601440
2088setup.tmpC:\Program Files\PW2\is-P4QJ4.tmpexecutable
MD5:9F9AC63EA20E1E52EC69DCB627EE0B08
SHA256:6F39BC231354F1A0F49B1B94458CA3CC35FA653B0703745B0032CD37FAC35265
2088setup.tmpC:\Program Files\PW2\is-F9GV2.tmphtml
MD5:F9A6A183F333C3C5432B1B3EFE4CB7FA
SHA256:7D5A6AA6A34546C970F61FF26BF163C83FBBA3D6DECA06A8AF1A52F76F4E2119
2088setup.tmpC:\Windows\System32\comdlg32.ocxexecutable
MD5:AB412429F1E5FB9708A8CDEA07479099
SHA256:E32D8BBE8E6985726742B496520FA47827F3B428648FA1BC34ECFFDD9BDAC240
2088setup.tmpC:\Windows\system32\is-HM3G9.tmpexecutable
MD5:AE47A8A5FE8193BB84FFCD338115D8EF
SHA256:160B0CEF5E9ED57C024E9B3A278E6456E849DAA85D46F2B6D1450BF19FCA72DD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
54
DNS requests
61
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3916
msedge.exe
GET
301
45.55.63.209:80
http://www.ematrixsoft.com/data/down/welcome.php
unknown
html
257 b
unknown
856
svchost.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYTBmQUFZUHRkSkgtb01uSGNvRHZ2Tm5HQQ/1.0.0.15_llkgjffcdpffmhiakmfcdcblohccpfmo.crx
unknown
binary
3.07 Kb
unknown
856
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYTBmQUFZUHRkSkgtb01uSGNvRHZ2Tm5HQQ/1.0.0.15_llkgjffcdpffmhiakmfcdcblohccpfmo.crx
unknown
unknown
2792
chrome.exe
GET
204
142.250.186.35:80
http://www.gstatic.com/generate_204
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3916
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1220
msedge.exe
239.255.255.250:1900
unknown
3916
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3916
msedge.exe
45.55.63.209:80
www.ematrixsoft.com
DIGITALOCEAN-ASN
US
unknown
3916
msedge.exe
45.55.63.209:443
www.ematrixsoft.com
DIGITALOCEAN-ASN
US
unknown
3916
msedge.exe
104.126.37.171:443
www.bing.com
Akamai International B.V.
DE
unknown
1220
msedge.exe
224.0.0.251:5353
unknown

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.ematrixsoft.com
  • 45.55.63.209
malicious
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
spysoftware4u.com
  • 45.55.63.209
unknown
www.bing.com
  • 104.126.37.171
  • 104.126.37.163
  • 104.126.37.155
  • 104.126.37.146
  • 104.126.37.161
  • 104.126.37.162
  • 104.126.37.147
  • 104.126.37.153
  • 104.126.37.154
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted
clientservices.googleapis.com
  • 142.250.185.67
whitelisted
accounts.google.com
  • 172.253.116.84
shared
www.google.com
  • 142.250.186.36
whitelisted
www.gstatic.com
  • 142.250.186.35
whitelisted

Threats

No threats detected
No debug info