URL:

https://www.zen-browser.app/release-notes/1.0.0-a.28

Full analysis: https://app.any.run/tasks/2aa3e78f-f1f6-4cff-8bec-677b53a57c43
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: August 26, 2024, 09:45:20
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
stealer
Indicators:
MD5:

6A03EFAF404D340EB68EF75DF2D790CA

SHA1:

61DB7847AD18B76B034A27C74A25B9FE7E1CBD4E

SHA256:

2327F6139FBE3BDFBB5F9D6A5975A7F9BF5868191F348D8E331E84433F24499C

SSDEEP:

3:N8DSLo83tXwCchoumULj:2OLoigiuz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • setup.exe (PID: 2804)
    • Actions looks like stealing of personal data

      • zen.exe (PID: 6428)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • zen.installer.exe (PID: 6160)
      • setup.exe (PID: 3812)
      • setup.exe (PID: 2804)
      • zen.exe (PID: 6428)
    • Drops the executable file immediately after the start

      • zen.installer.exe (PID: 6160)
      • setup.exe (PID: 3812)
      • setup.exe (PID: 2804)
      • zen.exe (PID: 6428)
    • The process drops C-runtime libraries

      • zen.installer.exe (PID: 6160)
      • setup.exe (PID: 2804)
    • Process drops legitimate windows executable

      • zen.installer.exe (PID: 6160)
      • setup.exe (PID: 2804)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 3812)
      • setup.exe (PID: 2804)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • setup.exe (PID: 3812)
      • setup.exe (PID: 2804)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 3812)
      • setup.exe (PID: 2804)
      • zen.exe (PID: 6428)
    • Reads the date of Windows installation

      • setup.exe (PID: 3812)
    • Application launched itself

      • setup.exe (PID: 3812)
      • zen.exe (PID: 7160)
      • zen.exe (PID: 6428)
      • zen.exe (PID: 5760)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 6288)
    • Searches for installed software

      • setup.exe (PID: 2804)
    • Creates a software uninstall entry

      • setup.exe (PID: 2804)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 2456)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 2456)
      • chrome.exe (PID: 7408)
    • Reads the computer name

      • zen.installer.exe (PID: 6160)
      • setup.exe (PID: 3812)
      • setup.exe (PID: 2804)
      • zen.exe (PID: 3972)
      • zen.exe (PID: 6428)
      • zen.exe (PID: 3880)
      • zen.exe (PID: 3424)
      • zen.exe (PID: 6152)
      • zen.exe (PID: 4196)
      • zen.exe (PID: 6320)
      • zen.exe (PID: 2684)
      • zen.exe (PID: 6984)
      • zen.exe (PID: 2904)
      • zen.exe (PID: 5072)
      • zen.exe (PID: 6240)
      • zen.exe (PID: 5172)
      • zen.exe (PID: 6332)
      • zen.exe (PID: 7768)
      • zen.exe (PID: 7972)
      • zen.exe (PID: 8000)
      • zen.exe (PID: 8128)
      • zen.exe (PID: 7964)
      • zen.exe (PID: 8148)
      • zen.exe (PID: 7920)
    • Create files in a temporary directory

      • zen.installer.exe (PID: 6160)
      • setup.exe (PID: 3812)
      • setup.exe (PID: 2804)
      • zen.exe (PID: 3972)
      • zen.exe (PID: 6428)
    • Checks supported languages

      • setup.exe (PID: 3812)
      • zen.installer.exe (PID: 6160)
      • setup.exe (PID: 2804)
      • zen.exe (PID: 3972)
      • zen.exe (PID: 5760)
      • zen.exe (PID: 6428)
      • zen.exe (PID: 7160)
      • zen.exe (PID: 3880)
      • zen.exe (PID: 3424)
      • zen.exe (PID: 6320)
      • zen.exe (PID: 6152)
      • zen.exe (PID: 4196)
      • zen.exe (PID: 2684)
      • zen.exe (PID: 6984)
      • zen.exe (PID: 2904)
      • zen.exe (PID: 5072)
      • zen.exe (PID: 6332)
      • zen.exe (PID: 7768)
      • zen.exe (PID: 7972)
      • zen.exe (PID: 8000)
      • zen.exe (PID: 5172)
      • zen.exe (PID: 8128)
      • zen.exe (PID: 7964)
      • zen.exe (PID: 8148)
      • zen.exe (PID: 7920)
      • zen.exe (PID: 6240)
    • Process checks whether UAC notifications are on

      • setup.exe (PID: 3812)
      • zen.exe (PID: 3972)
    • Reads Microsoft Office registry keys

      • chrome.exe (PID: 2456)
      • setup.exe (PID: 2804)
      • zen.exe (PID: 6428)
    • Process checks computer location settings

      • setup.exe (PID: 3812)
      • zen.exe (PID: 6428)
      • zen.exe (PID: 5072)
      • zen.exe (PID: 5172)
      • zen.exe (PID: 7768)
      • zen.exe (PID: 8000)
    • UPX packer has been detected

      • zen.installer.exe (PID: 6160)
    • Creates files in the program directory

      • setup.exe (PID: 2804)
      • zen.exe (PID: 3972)
      • zen.exe (PID: 6428)
    • Reads CPU info

      • zen.exe (PID: 3972)
      • zen.exe (PID: 6428)
      • zen.exe (PID: 6332)
      • zen.exe (PID: 7972)
    • Checks proxy server information

      • setup.exe (PID: 2804)
      • zen.exe (PID: 6428)
    • Creates files or folders in the user directory

      • zen.exe (PID: 6428)
    • Reads the machine GUID from the registry

      • zen.exe (PID: 6428)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
183
Monitored processes
47
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs THREAT zen.installer.exe setup.exe setup.exe chrome.exe no specs regsvr32.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs chrome.exe no specs chrome.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs chrome.exe no specs zen.exe no specs chrome.exe no specs chrome.exe zen.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2028"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4788 --field-trial-handle=1844,i,4630477637386876688,11471721055078428984,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2180"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=122.0.6261.70 --initial-client-data=0x220,0x224,0x228,0x1dc,0x22c,0x7fffd23fdc40,0x7fffd23fdc4c,0x7fffd23fdc58C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2456"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "https://www.zen-browser.app/release-notes/1.0.0-a.28"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2684"C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=4764 -childID 4 -isForBrowser -prefsHandle 4756 -prefMapHandle 4752 -prefsLen 24505 -prefMapSize 258296 -jsInitHandle 1180 -jsInitLen 234852 -parentBuildID 20240824161600 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {ce4f44fc-804d-4e45-bb0f-1cedf31d8a64} 6428 tabC:\Program Files\Zen Browser\zen.exezen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Zen Browser
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2804"C:\Users\admin\AppData\Local\Temp\7zS0188A7B3\setup.exe" /UAC:9029C /NCRCC:\Users\admin\AppData\Local\Temp\7zS0188A7B3\setup.exe
setup.exe
User:
admin
Company:
Zen HQ
Integrity Level:
HIGH
Description:
Zen Browser Installer
Exit code:
0
Version:
1.0.0-a.29
Modules
Images
c:\users\admin\appdata\local\temp\7zs0188a7b3\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2904"C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=3572 -childID 5 -isForBrowser -prefsHandle 4988 -prefMapHandle 4912 -prefsLen 26607 -prefMapSize 258296 -jsInitHandle 1180 -jsInitLen 234852 -parentBuildID 20240824161600 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {3f3f87b0-6fb7-4e4f-873b-fcac623983ef} 6428 tabC:\Program Files\Zen Browser\zen.exezen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Zen Browser
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3424"C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=2480 -parentBuildID 20240824161600 -prefsHandle 2472 -prefMapHandle 2468 -prefsLen 22121 -prefMapSize 258296 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {78990d02-0b92-4677-a0cf-5d5bb81c144c} 6428 socketC:\Program Files\Zen Browser\zen.exezen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Zen Browser
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3540"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=4932 --field-trial-handle=1844,i,4630477637386876688,11471721055078428984,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3652"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4516 --field-trial-handle=1844,i,4630477637386876688,11471721055078428984,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3812.\setup.exeC:\Users\admin\AppData\Local\Temp\7zS0188A7B3\setup.exe
zen.installer.exe
User:
admin
Company:
Zen HQ
Integrity Level:
MEDIUM
Description:
Zen Browser Installer
Exit code:
0
Version:
1.0.0-a.29
Modules
Images
c:\users\admin\appdata\local\temp\7zs0188a7b3\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
Total events
45 148
Read events
44 941
Write events
183
Delete events
24

Modification events

(PID) Process:(2456) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2456) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2456) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2456) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2456) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2456) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2456) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(2456) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2456) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(2456) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:metricsid
Value:
Executable files
78
Suspicious files
1 260
Text files
1 292
Unknown types
15

Dropped files

PID
Process
Filename
Type
2456chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
2456chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF12b3d7.TMP
MD5:
SHA256:
2456chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
2456chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
2456chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
2456chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
2456chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF12b406.TMP
MD5:
SHA256:
2456chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
2456chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.oldtext
MD5:4B26172585D38A3DD6697E274D0608AC
SHA256:85899A7AF1BD1939EA8264009EC427930FC5C092C8C3193984D6391526319268
2456chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old~RF12b4f0.TMPtext
MD5:602C51DB8380F8CD0A961D9A46AF1186
SHA256:84F716E38017F52138A76222524A3152DB8D3A7FBE30E94067458568B14DC36D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
194
DNS requests
184
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5612
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1184
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
208
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
1184
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
208
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
208
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
208
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
208
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
208
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
208
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6612
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7156
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2456
chrome.exe
239.255.255.250:1900
whitelisted
6520
chrome.exe
76.76.21.123:443
www.zen-browser.app
AMAZON-02
US
malicious
6520
chrome.exe
142.250.110.84:443
accounts.google.com
GOOGLE
US
whitelisted
2456
chrome.exe
224.0.0.251:5353
unknown
6520
chrome.exe
142.250.186.132:443
www.google.com
GOOGLE
US
whitelisted
6520
chrome.exe
151.101.129.229:443
cdn.jsdelivr.net
FASTLY
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 74.125.21.113
  • 74.125.21.102
  • 74.125.21.101
  • 74.125.21.100
  • 74.125.21.138
  • 74.125.21.139
whitelisted
www.zen-browser.app
  • 76.76.21.123
  • 76.76.21.61
  • 76.76.21.98
malicious
accounts.google.com
  • 142.250.110.84
  • 2a00:1450:400c:c09::54
  • 173.194.79.84
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
  • 4.231.128.59
whitelisted
www.google.com
  • 142.250.186.132
  • 2a00:1450:4001:80f::2004
  • 216.58.206.36
whitelisted
cdn.jsdelivr.net
  • 151.101.129.229
  • 151.101.193.229
  • 151.101.1.229
  • 151.101.65.229
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.64
  • 20.190.159.4
  • 20.190.159.75
  • 40.126.31.73
  • 20.190.159.0
  • 40.126.31.67
  • 20.190.159.73
  • 40.126.31.71
  • 20.190.159.2
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
github.com
  • 140.82.121.4
shared

Threats

PID
Process
Class
Message
6520
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6520
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloud infrastructure to build app (vercel .app)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloud infrastructure to build app (vercel .app)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Canva designs and to share platform (static .canva .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Canva designs and to share platform (static .canva .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloud infrastructure to build app (vercel .app)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Canva designs and to share platform (static .canva .com)
No debug info