URL:

Roblox.com

Full analysis: https://app.any.run/tasks/e1bfac4a-e85c-4521-9abe-359c23c65351
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: April 22, 2026, 13:21:49
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
Indicators:
MD5:

29744A57B4FC7DDC4AFEBA94FFED3287

SHA1:

6A98EAB246D8504CD4E2E3D3EBE76BDD9213A2A2

SHA256:

2CC694E82769CAD6026E72CF1FA9F474ED682F07C73DC93C324B3798E5E5979A

SSDEEP:

3:X3In:on

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • setup.exe (PID: 9296)
    • Executing a file with an untrusted certificate

      • FileSyncConfig.exe (PID: 11652)
      • OneDrive.exe (PID: 11780)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • FirstLogonAnim.exe (PID: 5460)
    • Application launched itself

      • ie4uinit.exe (PID: 6812)
      • setup.exe (PID: 9296)
      • setup.exe (PID: 9352)
      • setup.exe (PID: 9472)
      • setup.exe (PID: 10684)
      • setup.exe (PID: 10592)
      • OneDriveSetup.exe (PID: 11688)
    • Changes internet zones settings

      • ie4uinit.exe (PID: 6812)
    • Write to the desktop.ini file (may be used to cloak folders)

      • ie4uinit.exe (PID: 6812)
      • fsquirt.exe (PID: 7660)
      • FileSyncConfig.exe (PID: 11652)
    • Reads Internet Explorer settings

      • FirstLogonAnim.exe (PID: 5460)
    • Uses RUNDLL32.EXE to load library

      • ie4uinit.exe (PID: 1088)
    • Reads the date of Windows installation

      • SearchApp.exe (PID: 10728)
      • StartMenuExperienceHost.exe (PID: 10712)
    • Executable content was dropped or overwritten

      • OneDriveSetup.exe (PID: 11804)
    • The process drops C-runtime libraries

      • OneDriveSetup.exe (PID: 11804)
    • The process creates files with name similar to system file names

      • OneDriveSetup.exe (PID: 11804)
    • Creates/Modifies COM task schedule object

      • OneDriveSetup.exe (PID: 11804)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 7340)
      • setup.exe (PID: 9296)
      • setup.exe (PID: 9316)
      • setup.exe (PID: 9368)
      • setup.exe (PID: 9352)
      • setup.exe (PID: 9472)
      • setup.exe (PID: 9504)
      • setup.exe (PID: 10628)
      • setup.exe (PID: 10712)
      • setup.exe (PID: 10684)
      • TextInputHost.exe (PID: 10504)
      • setup.exe (PID: 10592)
      • SearchApp.exe (PID: 10728)
      • wab.exe (PID: 11796)
      • StartMenuExperienceHost.exe (PID: 10712)
      • WinStore.App.exe (PID: 11176)
      • FileSyncConfig.exe (PID: 11652)
      • OneDrive.exe (PID: 11780)
      • WinStore.App.exe (PID: 3044)
    • Reads Environment values

      • identity_helper.exe (PID: 7340)
      • SearchApp.exe (PID: 10728)
      • WinStore.App.exe (PID: 11176)
      • WinStore.App.exe (PID: 3044)
    • Reads the computer name

      • identity_helper.exe (PID: 7340)
      • setup.exe (PID: 9296)
      • setup.exe (PID: 9352)
      • setup.exe (PID: 9472)
      • setup.exe (PID: 10684)
      • TextInputHost.exe (PID: 10504)
      • StartMenuExperienceHost.exe (PID: 10712)
      • setup.exe (PID: 10592)
      • SearchApp.exe (PID: 10728)
      • WinStore.App.exe (PID: 11176)
      • OneDrive.exe (PID: 11780)
      • WinStore.App.exe (PID: 3044)
    • Manual execution by a user

      • FirstLogonAnim.exe (PID: 5460)
      • unregmp2.exe (PID: 8264)
      • ie4uinit.exe (PID: 6812)
      • unregmp2.exe (PID: 4872)
      • chrmstp.exe (PID: 8712)
      • setup.exe (PID: 9296)
      • fsquirt.exe (PID: 7660)
      • OneDriveSetup.exe (PID: 11688)
      • msedge.exe (PID: 11780)
      • wab.exe (PID: 11796)
    • Application launched itself

      • msedge.exe (PID: 7224)
      • chrmstp.exe (PID: 8712)
      • chrmstp.exe (PID: 6792)
      • msedge.exe (PID: 9540)
    • Reads security settings of Internet Explorer

      • ie4uinit.exe (PID: 1088)
      • ie4uinit.exe (PID: 6812)
      • FirstLogonAnim.exe (PID: 5460)
      • StartMenuExperienceHost.exe (PID: 10712)
      • WWAHost.exe (PID: 11460)
      • OneDriveSetup.exe (PID: 11688)
      • OneDriveSetup.exe (PID: 11804)
      • ApplicationFrameHost.exe (PID: 7212)
      • WinStore.App.exe (PID: 11176)
      • WinStore.App.exe (PID: 3044)
    • Process checks computer location settings

      • setup.exe (PID: 9352)
      • setup.exe (PID: 10684)
      • StartMenuExperienceHost.exe (PID: 10712)
      • SearchApp.exe (PID: 10728)
      • WinStore.App.exe (PID: 11176)
      • WinStore.App.exe (PID: 3044)
    • Reads Microsoft Office registry keys

      • setup.exe (PID: 9296)
      • setup.exe (PID: 10592)
    • Reads the machine GUID from the registry

      • SearchApp.exe (PID: 10728)
      • WinStore.App.exe (PID: 11176)
      • OneDrive.exe (PID: 11780)
      • WinStore.App.exe (PID: 3044)
    • The sample compiled with english language support

      • OneDriveSetup.exe (PID: 11804)
    • The sample compiled with chinese language support

      • OneDriveSetup.exe (PID: 11804)
    • The sample compiled with portuguese language support

      • OneDriveSetup.exe (PID: 11804)
    • Creates a software uninstall entry

      • OneDriveSetup.exe (PID: 11804)
    • Reads CPU info

      • OneDrive.exe (PID: 11780)
    • Reads the time zone

      • OneDrive.exe (PID: 11780)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
306
Monitored processes
95
Malicious processes
1
Suspicious processes
5

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firstlogonanim.exe no specs unregmp2.exe no specs ie4uinit.exe no specs ie4uinit.exe no specs rundll32.exe no specs rundll32.exe no specs unregmp2.exe no specs chrmstp.exe no specs chrmstp.exe no specs chrmstp.exe no specs chrmstp.exe no specs setup.exe setup.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs msedge.exe no specs User OOBE Create Elevated Object Server no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs textinputhost.exe no specs startmenuexperiencehost.exe no specs searchapp.exe wwahost.exe no specs msedge.exe no specs User OOBE Create Elevated Object Server no specs fsquirt.exe no specs msedge.exe no specs mobsync.exe no specs onedrivesetup.exe no specs onedrivesetup.exe msedge.exe no specs wab.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs applicationframehost.exe no specs winstore.app.exe filesyncconfig.exe no specs onedrive.exe no specs msedge.exe no specs winstore.app.exe msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
488"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5880,i,10586795080809274343,8015114583876526257,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5860 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
488"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --string-annotations --subproc-heap-profiling --always-read-main-dll --field-trial-handle=5488,i,7995830195112569121,8545624445043971085,262144 --variations-seed-version --mojo-platform-channel-handle=4140 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
Administrator
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1088C:\Windows\System32\ie4uinit.exe -ClearIconCacheC:\Windows\System32\ie4uinit.exeie4uinit.exe
User:
Administrator
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IE Per-User Initialization Utility
Exit code:
0
Version:
11.00.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\ie4uinit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1116C:\WINDOWS\system32\RunDll32.exe C:\WINDOWS\system32\migration\WininetPlugin.dll,MigrateCacheForUser /m /0C:\Windows\System32\rundll32.exeie4uinit.exe
User:
Administrator
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1116"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=14 --always-read-main-dll --field-trial-handle=3712,i,7995830195112569121,8545624445043971085,262144 --variations-seed-version --mojo-platform-channel-handle=3848 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
Administrator
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1504"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3692,i,10586795080809274343,8015114583876526257,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=3612 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1780"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --disable-quic --onnx-enabled-for-ee --string-annotations --always-read-main-dll --field-trial-handle=5896,i,10586795080809274343,8015114583876526257,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5936 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2428"C:\Program Files\Google\Chrome\Application\133.0.6943.127\Installer\chrmstp.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=133.0.6943.127 --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x7ff7156ebed8,0x7ff7156ebee4,0x7ff7156ebef0C:\Program Files\Google\Chrome\Application\133.0.6943.127\Installer\chrmstp.exechrmstp.exe
User:
Administrator
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\133.0.6943.127\installer\chrmstp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2432"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x294,0x298,0x29c,0x28c,0x2a4,0x7ffe2392f208,0x7ffe2392f214,0x7ffe2392f220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3044"C:\Program Files\WindowsApps\Microsoft.WindowsStore_11707.1001.23.0_x64__8wekyb3d8bbwe\WinStore.App.exe" -ServerName:App.AppXc75wvwned5vhz4xyxxecvgdjhdkgsdza.mcaC:\Program Files\WindowsApps\Microsoft.WindowsStore_11707.1001.23.0_x64__8wekyb3d8bbwe\WinStore.App.exe
svchost.exe
User:
Administrator
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Store
Version:
11707.1001.23.0
Modules
Images
c:\program files\windowsapps\microsoft.windowsstore_11707.1001.23.0_x64__8wekyb3d8bbwe\winstore.app.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files\windowsapps\microsoft.windowsstore_11707.1001.23.0_x64__8wekyb3d8bbwe\winstore.app.dll
c:\program files\windowsapps\microsoft.net.native.runtime.1.6_1.6.24903.0_x64__8wekyb3d8bbwe\mrt100_app.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
Total events
39 716
Read events
38 505
Write events
1 161
Delete events
50

Modification events

(PID) Process:(6812) ie4uinit.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}
Operation:writeName:IsInstalled
Value:
1
(PID) Process:(6812) ie4uinit.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo
Operation:writeName:IconsVisible
Value:
1
(PID) Process:(6812) ie4uinit.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents
Operation:writeName:IEAccess
Value:
1
(PID) Process:(6812) ie4uinit.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Capabilities
Operation:writeName:Hidden
Value:
0
(PID) Process:(6812) ie4uinit.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:DisableFirstRunCustomize
Value:
1
(PID) Process:(6812) ie4uinit.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder
Operation:writeName:Attributes
Value:
1048576
(PID) Process:(6812) ie4uinit.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394
Operation:writeName:DisplayName
Value:
windows_ie_ac_001
(PID) Process:(6812) ie4uinit.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\BrowserEmulation
Operation:writeName:CVListTTL
Value:
0
(PID) Process:(6812) ie4uinit.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021493-0000-0000-C000-000000000046}\Enum
Operation:writeName:Implementing
Value:
000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6812) ie4uinit.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021494-0000-0000-C000-000000000046}\Enum
Operation:writeName:Implementing
Value:
000000000000000000000000000000000000000000000000000000000000
Executable files
209
Suspicious files
400
Text files
1 047
Unknown types
54

Dropped files

PID
Process
Filename
Type
7224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFdfb48.TMP
MD5:
SHA256:
7224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RFdfb39.TMP
MD5:
SHA256:
7224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
7224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFdfb48.TMP
MD5:
SHA256:
7224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFdfb58.TMP
MD5:
SHA256:
7224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFdfb77.TMP
MD5:
SHA256:
7224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RFdfb77.TMP
MD5:
SHA256:
7224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
490
TCP/UDP connections
147
DNS requests
146
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4112
msedge.exe
GET
308
128.116.5.3:443
https://roblox.com/
US
unknown
4112
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:GeVZsnlXmP-dZ24Op6oO6pcQ-f2mKkUFvwerfx4tkAs&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
97 b
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
959 b
whitelisted
4112
msedge.exe
GET
200
128.116.21.3:443
https://www.roblox.com/
US
text
59.0 Kb
unknown
4112
msedge.exe
GET
307
128.116.5.3:80
http://roblox.com/
US
unknown
4112
msedge.exe
GET
200
52.123.243.77:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=67&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1776864115&lafgdate=0
US
text
4.37 Kb
whitelisted
4112
msedge.exe
GET
200
150.171.28.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
US
text
132 b
whitelisted
4112
msedge.exe
GET
200
13.107.253.44:443
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appId=edge-extensions&country=US
US
binary
82 b
whitelisted
4112
msedge.exe
GET
200
128.116.21.3:443
https://www.roblox.com/js/utilities/bundleVerifier.js?v=91dceb4978eda412b09842312dd6cbaa
US
text
11.0 Kb
unknown
5532
SearchApp.exe
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
NL
binary
314 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5276
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8140
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
23.36.162.69:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
5532
SearchApp.exe
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4112
msedge.exe
52.123.243.77:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
4112
msedge.exe
128.116.5.3:80
roblox.com
ROBLOX-PRODUCTION
US
whitelisted

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 192.178.183.102
  • 192.178.183.101
  • 192.178.183.139
  • 192.178.183.138
  • 192.178.183.100
  • 192.178.183.113
whitelisted
www.bing.com
  • 23.36.162.69
  • 23.36.162.85
  • 23.36.162.71
  • 23.36.162.68
  • 23.36.162.73
  • 23.36.162.76
  • 23.36.162.74
  • 23.36.162.78
  • 23.36.162.84
  • 2.16.241.220
  • 2.16.241.217
  • 2.16.241.213
  • 2.16.241.208
  • 2.16.241.214
  • 2.16.241.215
  • 2.16.241.219
  • 2.16.241.212
  • 2.16.241.209
  • 23.36.162.86
  • 23.36.162.75
  • 23.36.162.83
  • 23.36.162.77
  • 23.36.162.82
  • 23.36.162.79
  • 23.36.162.87
whitelisted
ocsp.digicert.com
  • 23.11.41.157
  • 162.159.142.9
  • 172.66.2.5
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 52.123.243.77
  • 52.123.243.84
  • 52.123.243.196
  • 52.123.243.210
  • 150.171.22.17
whitelisted
roblox.com
  • 128.116.5.3
  • 128.116.21.3
whitelisted
api.edgeoffer.microsoft.com
  • 13.107.253.44
  • 13.107.226.44
whitelisted
copilot.microsoft.com
  • 104.18.23.222
  • 104.18.22.222
whitelisted

Threats

No threats detected
No debug info