| URL: | http://click.promote.weebly.com/ls/click?upn=u001.ght77-2B2byXY0-2Bvfk5IwG03-2FeXGA8-2FMyKJz6l69rvQ28-3Dglok_vLeE07ZAx4264xvk0rNfqqX1AhHARla-2F-2BvylwP-2BIUQMX8UpuqxlhTBoBn1U8N5edQu22zrQNEZHaO-2BjsxWxazvlUIrkj9H-2FMyXTPT5qhcyDzdW7I6ysLjTkUYh7agoQmYq-2FlRWJjavb-2BTjVDyiTGlRMz7IWFUceCYHg-2Bda7aG-2FRIOqXyf-2BSFmf-2FP-2BZ3lJF-2BKZU-2BeEJsHCEradlvkcOAiB0TdbWRm9ip7158vVyBkO3R4AipTNqEfDYwkYH1d8lvMX1bKJArIRcSTV3dHw9YZhtmrfAlRod3kcsAchIMJYY6NkxVnLo-2Bshbdm4LD9f3uguTxtD9ie7aihkTPl4CgBpxw4oT0VnmTdql-2Fc8P0uCmsawxdIL-2Bv3OC-2BHuDi9nFRuyvKwM58iatdRLSxjDQYJzQDWOwWStsOJLUFFmLYLUzw3G1itBoPt1-2FHqDMun6ZBtTwnYU1oBReqYjnzO-2F-2BnotpRWGva4hwBI23WafEUKFmw-3D |
| Full analysis: | https://app.any.run/tasks/1cf989d6-a94f-4892-8693-a887650b736b |
| Verdict: | Malicious activity |
| Analysis date: | October 16, 2024, 13:59:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | EEC5A38293D4E4DAA33FCF657CA1BED6 |
| SHA1: | 9059115E469A340964996C123423A326576E02B5 |
| SHA256: | 2693AF7F3157A1D5C188A751ED46FA91EC61B6550F444EA82924D54F668BA75D |
| SSDEEP: | 12:1SSxtwJgBSo4/56iar7cewA9pmCIccKr3O7ivg+rDd5NQ5hLiShncQm:1GKb256DYG/jhcEO635afhJm |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 660 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4064 --field-trial-handle=1372,i,14016615427776154470,14831081033531607693,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 964 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2188 --field-trial-handle=1372,i,14016615427776154470,14831081033531607693,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 980 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=3388 --field-trial-handle=1372,i,14016615427776154470,14831081033531607693,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1008 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1492 --field-trial-handle=1372,i,14016615427776154470,14831081033531607693,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1060 | C:\Windows\system32\svchost.exe -k NetworkService | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1916 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3580 --field-trial-handle=1372,i,14016615427776154470,14831081033531607693,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2272 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.PageScreenshotProcessor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=1192 --field-trial-handle=1372,i,14016615427776154470,14831081033531607693,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2500 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0x120,0x6e7ef598,0x6e7ef5a8,0x6e7ef5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2724 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2200 --field-trial-handle=1372,i,14016615427776154470,14831081033531607693,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2844 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" "http://click.promote.weebly.com/ls/click?upn=u001.ght77-2B2byXY0-2Bvfk5IwG03-2FeXGA8-2FMyKJz6l69rvQ28-3Dglok_vLeE07ZAx4264xvk0rNfqqX1AhHARla-2F-2BvylwP-2BIUQMX8UpuqxlhTBoBn1U8N5edQu22zrQNEZHaO-2BjsxWxazvlUIrkj9H-2FMyXTPT5qhcyDzdW7I6ysLjTkUYh7agoQmYq-2FlRWJjavb-2BTjVDyiTGlRMz7IWFUceCYHg-2Bda7aG-2FRIOqXyf-2BSFmf-2FP-2BZ3lJF-2BKZU-2BeEJsHCEradlvkcOAiB0TdbWRm9ip7158vVyBkO3R4AipTNqEfDYwkYH1d8lvMX1bKJArIRcSTV3dHw9YZhtmrfAlRod3kcsAchIMJYY6NkxVnLo-2Bshbdm4LD9f3uguTxtD9ie7aihkTPl4CgBpxw4oT0VnmTdql-2Fc8P0uCmsawxdIL-2Bv3OC-2BHuDi9nFRuyvKwM58iatdRLSxjDQYJzQDWOwWStsOJLUFFmLYLUzw3G1itBoPt1-2FHqDMun6ZBtTwnYU1oBReqYjnzO-2F-2BnotpRWGva4hwBI23WafEUKFmw-3D" | C:\Program Files\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (2844) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2844) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2844) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2844) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2844) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1060) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache\Intranet |
| Operation: | write | Name: | {4040CF00-1B3E-486A-B407-FA14C56B6FC0} |
Value: 525400363EFF | |||
| (PID) Process: | (2844) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2844) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (2844) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1302019708-1500728564-335382590-1000 |
Value: 9759FAC42E832F00 | |||
| (PID) Process: | (2844) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\FirstNotDefault |
| Operation: | delete value | Name: | S-1-5-21-1302019708-1500728564-335382590-1000 |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2844 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF22ccc0.TMP | — | |
MD5:— | SHA256:— | |||
| 2844 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2844 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF22ccdf.TMP | — | |
MD5:— | SHA256:— | |||
| 2844 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2844 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF22ccef.TMP | — | |
MD5:— | SHA256:— | |||
| 2844 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF22cd5c.TMP | — | |
MD5:— | SHA256:— | |||
| 2844 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2844 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat | binary | |
MD5:04971D41DD7153DBC85E5C69CB344FE2 | SHA256:CBA076CE5E11A5D183814B8F4DAC266FAFD9CFC9E94F4BE28600BF9B35134157 | |||
| 2844 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Last Version | text | |
MD5:61FE7896F9494DCDF53480A325F4FB85 | SHA256:ACFD3CD36E0DFCF1DCB67C7F31F2A5B9BA0815528A0C604D4330DFAA9E683E51 | |||
| 2500 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\CrashpadMetrics.pma | binary | |
MD5:C612E96CBFAC63232FC2062E15600FB1 | SHA256:DB3C05D5EC0B6719A73E7F0BE84BCE9342772DA70567E7CE08CF6573480B38FF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3236 | msedge.exe | GET | 302 | 167.89.118.95:80 | http://click.promote.weebly.com/ls/click?upn=u001.ght77-2B2byXY0-2Bvfk5IwG03-2FeXGA8-2FMyKJz6l69rvQ28-3Dglok_vLeE07ZAx4264xvk0rNfqqX1AhHARla-2F-2BvylwP-2BIUQMX8UpuqxlhTBoBn1U8N5edQu22zrQNEZHaO-2BjsxWxazvlUIrkj9H-2FMyXTPT5qhcyDzdW7I6ysLjTkUYh7agoQmYq-2FlRWJjavb-2BTjVDyiTGlRMz7IWFUceCYHg-2Bda7aG-2FRIOqXyf-2BSFmf-2FP-2BZ3lJF-2BKZU-2BeEJsHCEradlvkcOAiB0TdbWRm9ip7158vVyBkO3R4AipTNqEfDYwkYH1d8lvMX1bKJArIRcSTV3dHw9YZhtmrfAlRod3kcsAchIMJYY6NkxVnLo-2Bshbdm4LD9f3uguTxtD9ie7aihkTPl4CgBpxw4oT0VnmTdql-2Fc8P0uCmsawxdIL-2Bv3OC-2BHuDi9nFRuyvKwM58iatdRLSxjDQYJzQDWOwWStsOJLUFFmLYLUzw3G1itBoPt1-2FHqDMun6ZBtTwnYU1oBReqYjnzO-2F-2BnotpRWGva4hwBI23WafEUKFmw-3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
2564 | svchost.exe | 239.255.255.250:3702 | — | — | — | whitelisted |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3236 | msedge.exe | 13.107.21.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2844 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3236 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3236 | msedge.exe | 167.89.118.95:80 | click.promote.weebly.com | SENDGRID | US | whitelisted |
3236 | msedge.exe | 104.21.17.75:443 | shh.rs | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
click.promote.weebly.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
shh.rs |
| unknown |
a.nel.cloudflare.com |
| whitelisted |
www.bing.com |
| whitelisted |
telegrambotcheck.duckdns.org |
| unknown |
_5001._https.telegrambotcheck.duckdns.org |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
3236 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
3236 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
3236 | msedge.exe | Misc activity | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain |
3236 | msedge.exe | Misc activity | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain |
3236 | msedge.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.duckdns .org Domain |
3236 | msedge.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.duckdns .org Domain |
3236 | msedge.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.duckdns .org Domain |
3236 | msedge.exe | Misc activity | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain |
3236 | msedge.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.duckdns .org Domain |
3236 | msedge.exe | Misc activity | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain |