URL:

https://file.monsgeek.com/Akko_Cloud_setup_370.1.46(WIN2024126).zip

Full analysis: https://app.any.run/tasks/e4d64c7b-15bf-471a-9676-412f5e22e2fa
Verdict: Malicious activity
Analysis date: February 26, 2025, 04:39:47
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

287AE1F61B212EECF13103943A03DDAE

SHA1:

98E1D729C5BCE1FC08801E9E4903C02F3030D4B4

SHA256:

1E7A893DAD6033D169F2CE6EE6672F821F363A76A8BA43256F629CF3EA266260

SSDEEP:

3:N8vWDAPKUhU9+WSsEDArU:2vWDuzhqVIQU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
    • Executable content was dropped or overwritten

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
      • Akko Cloud Driver.exe (PID: 6452)
    • Starts CMD.EXE for commands execution

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
      • Akko Cloud Driver.exe (PID: 6452)
    • Drops 7-zip archiver for unpacking

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
    • The process drops C-runtime libraries

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
    • Creates a software uninstall entry

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
    • Get information on the list of running processes

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
      • cmd.exe (PID: 8084)
      • Akko Cloud Driver.exe (PID: 6452)
      • cmd.exe (PID: 7532)
    • Reads security settings of Internet Explorer

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
      • Akko Cloud Driver.exe (PID: 2284)
    • Process drops legitimate windows executable

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
    • Application launched itself

      • Akko Cloud Driver.exe (PID: 2284)
    • The process checks if it is being run in the virtual environment

      • iot_driver_v185.exe (PID: 7480)
    • Connects to unusual port

      • Akko Cloud Driver.exe (PID: 7852)
  • INFO

    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 660)
      • slui.exe (PID: 8000)
      • slui.exe (PID: 4188)
      • Akko Cloud Driver.exe (PID: 2284)
    • Reads Environment values

      • identity_helper.exe (PID: 6656)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 660)
      • BackgroundTransferHost.exe (PID: 5812)
      • BackgroundTransferHost.exe (PID: 4648)
      • BackgroundTransferHost.exe (PID: 5452)
      • BackgroundTransferHost.exe (PID: 684)
    • Checks supported languages

      • identity_helper.exe (PID: 6656)
      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
      • Akko Cloud Driver.exe (PID: 2284)
      • Akko Cloud Driver.exe (PID: 7852)
      • iot_driver_v185.exe (PID: 7480)
      • Akko Cloud Driver.exe (PID: 6452)
      • Akko Cloud Driver.exe (PID: 7408)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 660)
      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
      • Akko Cloud Driver.exe (PID: 2284)
      • Akko Cloud Driver.exe (PID: 6452)
      • iot_driver_v185.exe (PID: 7480)
      • Akko Cloud Driver.exe (PID: 7852)
    • Reads the computer name

      • identity_helper.exe (PID: 6656)
      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
      • Akko Cloud Driver.exe (PID: 2284)
      • Akko Cloud Driver.exe (PID: 7408)
      • Akko Cloud Driver.exe (PID: 7852)
      • iot_driver_v185.exe (PID: 7480)
    • Application launched itself

      • msedge.exe (PID: 5744)
    • Manual execution by a user

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
      • Akko Cloud Driver.exe (PID: 2284)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 5744)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 660)
      • Akko Cloud Driver.exe (PID: 2284)
      • slui.exe (PID: 4188)
    • The sample compiled with english language support

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
      • msedge.exe (PID: 8180)
    • Create files in a temporary directory

      • Akko Cloud_setup_370.1.46(WIN2024126).exe (PID: 5228)
      • Akko Cloud Driver.exe (PID: 2284)
    • Process checks computer location settings

      • Akko Cloud Driver.exe (PID: 2284)
      • Akko Cloud Driver.exe (PID: 6452)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 8180)
    • Reads the machine GUID from the registry

      • Akko Cloud Driver.exe (PID: 2284)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
214
Monitored processes
72
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs Set Network Location Elevated Virtual Factory no specs sppextcomobj.exe no specs identity_helper.exe no specs slui.exe identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe no specs winrar.exe no specs winrar.exe no specs rundll32.exe no specs msedge.exe no specs msedge.exe no specs akko cloud_setup_370.1.46(win2024126).exe cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs akko cloud driver.exe no specs msedge.exe no specs akko cloud driver.exe no specs akko cloud driver.exe akko cloud driver.exe cmd.exe no specs conhost.exe no specs tasklist.exe no specs iot_driver_v185.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
660"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
684"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
1152"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7608 --field-trial-handle=2068,i,16218504614234653975,7179833942635520394,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1268"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x2f8,0x304,0x308,0x2fc,0x310,0x7ffc88e15fd8,0x7ffc88e15fe4,0x7ffc88e15ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2272"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7732 --field-trial-handle=2068,i,16218504614234653975,7179833942635520394,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2284"C:\Users\admin\AppData\Local\Programs\Akko Cloud Driver\Akko Cloud Driver.exe" C:\Users\admin\AppData\Local\Programs\Akko Cloud Driver\Akko Cloud Driver.exeexplorer.exe
User:
admin
Company:
ROYUAN
Integrity Level:
MEDIUM
Description:
Akko Cloud Driver
Version:
370.1.46
Modules
Images
c:\users\admin\appdata\local\programs\akko cloud driver\akko cloud driver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2344"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5476 --field-trial-handle=2068,i,16218504614234653975,7179833942635520394,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2504"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5488 --field-trial-handle=2068,i,16218504614234653975,7179833942635520394,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2600"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=7508 --field-trial-handle=2068,i,16218504614234653975,7179833942635520394,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3008"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3452 --field-trial-handle=2068,i,16218504614234653975,7179833942635520394,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Total events
23 617
Read events
23 514
Write events
72
Delete events
31

Modification events

(PID) Process:(5744) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(5744) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(5744) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(5744) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(5744) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
54279C729A8D2F00
(PID) Process:(5744) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:MicrosoftEdgeAutoLaunch_29EBC4579851B72EE312C449CF839B1A
Value:
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start
(PID) Process:(5744) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\Commands\on-logon-autolaunch
Operation:writeName:Enabled
Value:
0
(PID) Process:(5744) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\Profiles
Operation:writeName:EnhancedLinkOpeningDefault
Value:
Default
(PID) Process:(5744) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\131812
Operation:writeName:WindowTabManagerFileMappingId
Value:
{A904F109-ED78-448E-92E1-1AA471F2292C}
(PID) Process:(5812) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
41
Suspicious files
1 407
Text files
176
Unknown types
0

Dropped files

PID
Process
Filename
Type
5744msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF129572.TMP
MD5:
SHA256:
5744msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF129572.TMP
MD5:
SHA256:
5744msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
5744msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
5744msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF129581.TMP
MD5:
SHA256:
5744msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
5744msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF129591.TMP
MD5:
SHA256:
5744msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
5744msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1295b0.TMP
MD5:
SHA256:
5744msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
50
TCP/UDP connections
70
DNS requests
64
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7516
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7524
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7396
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1741005478&P2=404&P3=2&P4=NIyKrI25gm2nxidJr1qmpw%2f37V7lcEvIN4C2nAuhmU6ktRqp%2fObVQ5kO%2bvkmlXI6SM1qrVwvT6OBW7eM1R7Wzg%3d%3d
unknown
whitelisted
7396
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1741005478&P2=404&P3=2&P4=NIyKrI25gm2nxidJr1qmpw%2f37V7lcEvIN4C2nAuhmU6ktRqp%2fObVQ5kO%2bvkmlXI6SM1qrVwvT6OBW7eM1R7Wzg%3d%3d
unknown
whitelisted
7500
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7396
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1741005478&P2=404&P3=2&P4=NIyKrI25gm2nxidJr1qmpw%2f37V7lcEvIN4C2nAuhmU6ktRqp%2fObVQ5kO%2bvkmlXI6SM1qrVwvT6OBW7eM1R7Wzg%3d%3d
unknown
whitelisted
7396
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1741005478&P2=404&P3=2&P4=NIyKrI25gm2nxidJr1qmpw%2f37V7lcEvIN4C2nAuhmU6ktRqp%2fObVQ5kO%2bvkmlXI6SM1qrVwvT6OBW7eM1R7Wzg%3d%3d
unknown
whitelisted
5544
SIHClient.exe
GET
200
104.119.109.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7396
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1741005478&P2=404&P3=2&P4=NIyKrI25gm2nxidJr1qmpw%2f37V7lcEvIN4C2nAuhmU6ktRqp%2fObVQ5kO%2bvkmlXI6SM1qrVwvT6OBW7eM1R7Wzg%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2924
SearchApp.exe
2.23.227.215:443
edgeservices.bing.com
Ooredoo Q.S.C.
QA
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6712
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
239.255.255.250:1900
whitelisted
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
13.107.6.158:443
business.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
13.107.246.60:443
edge-mobile-static.azureedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 20.73.194.208
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
file.monsgeek.com
  • 96.126.126.251
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.60
whitelisted
bzib.nelreports.net
  • 2.22.242.105
  • 2.22.242.11
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
update.googleapis.com
  • 142.250.184.227
whitelisted

Threats

No threats detected
No debug info