File name:

striata-reader (2).vir

Full analysis: https://app.any.run/tasks/4d975f6b-9598-424f-8525-455527060f83
Verdict: Malicious activity
Analysis date: July 04, 2025, 12:27:22
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

334D397FD7AEC4F4474EA696D78DCE92

SHA1:

47BDC95DE9484907533AE08A956E2A9FD2260B8D

SHA256:

2D0029ACD8B2A299839EB5ECF0C738294E54BE50016339E6D4A6C84273217200

SSDEEP:

49152:6nm0Z3MmWT9FbPMbeOgNZzA/ube6ZBlxA5+5jCJn+gXudcZxfgpD9in06JQFu0oG:6n/STfbPMbeBZM/9MBlxA5tR+gXuQxf4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • striata-reader (2).vir.exe (PID: 2220)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • striata-reader (2).vir.exe (PID: 3100)
    • Process drops legitimate windows executable

      • striata-reader (2).vir.exe (PID: 3100)
    • The process drops C-runtime libraries

      • striata-reader (2).vir.exe (PID: 3100)
  • INFO

    • The sample compiled with english language support

      • striata-reader (2).vir.exe (PID: 3100)
    • Manual execution by a user

      • msedge.exe (PID: 6652)
    • Application launched itself

      • msedge.exe (PID: 6652)
    • Checks supported languages

      • identity_helper.exe (PID: 7600)
    • Reads Environment values

      • identity_helper.exe (PID: 7600)
    • Reads the computer name

      • identity_helper.exe (PID: 7600)
    • Checks proxy server information

      • slui.exe (PID: 756)
    • Reads the software policy settings

      • slui.exe (PID: 756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2021:04:01 07:29:32+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.16
CodeSize: 96256
InitializedDataSize: 1291776
UninitializedDataSize: -
EntryPoint: 0x213c
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 2.31.2.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (1C09)
CharacterSet: Unicode
CompanyName: Doxim LLC
Internet: http://www.striata.com
E-mail: info@striata.com
FileDescription: Striata Reader
FileVersion: 2.31-2
LegalCopyright: Copyright Doxim LLC, 2020-2021
OriginalFileName: striata-reader
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
193
Monitored processes
41
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start striata-reader (2).vir.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs striata-reader (2).vir.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
756C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
864"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2476,i,6375473861261050331,8369604294792136948,262144 --variations-seed-version --mojo-platform-channel-handle=2468 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2220"C:\Users\admin\Desktop\striata-reader (2).vir.exe" C:\Users\admin\Desktop\striata-reader (2).vir.exeexplorer.exe
User:
admin
Company:
Doxim LLC
Integrity Level:
MEDIUM
Description:
Striata Reader
Exit code:
3221226540
Version:
2.31-2
Modules
Images
c:\users\admin\desktop\striata-reader (2).vir.exe
c:\windows\system32\ntdll.dll
2464"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x304,0x308,0x30c,0x2fc,0x314,0x7ffc44faf208,0x7ffc44faf214,0x7ffc44faf220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2952"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=7948,i,6375473861261050331,8369604294792136948,262144 --variations-seed-version --mojo-platform-channel-handle=7904 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3100"C:\Users\admin\Desktop\striata-reader (2).vir.exe" C:\Users\admin\Desktop\striata-reader (2).vir.exe
explorer.exe
User:
admin
Company:
Doxim LLC
Integrity Level:
HIGH
Description:
Striata Reader
Exit code:
0
Version:
2.31-2
3196"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2792,i,6375473861261050331,8369604294792136948,262144 --variations-seed-version --mojo-platform-channel-handle=2784 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3624"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=4912,i,6375473861261050331,8369604294792136948,262144 --variations-seed-version --mojo-platform-channel-handle=7760 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3672"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3632,i,6375473861261050331,8369604294792136948,262144 --variations-seed-version --mojo-platform-channel-handle=3656 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4264"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --always-read-main-dll --field-trial-handle=7228,i,6375473861261050331,8369604294792136948,262144 --variations-seed-version --mojo-platform-channel-handle=7212 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
9 290
Read events
9 198
Write events
90
Delete events
2

Modification events

(PID) Process:(6652) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6652) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6652) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6652) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6652) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
B8F32EE7AF972F00
(PID) Process:(6652) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
B51934E7AF972F00
(PID) Process:(6652) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\393932
Operation:writeName:WindowTabManagerFileMappingId
Value:
{DE69DD6F-BD0F-464D-A0E0-59A75311C519}
(PID) Process:(6652) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\393932
Operation:writeName:WindowTabManagerFileMappingId
Value:
{7B88840E-BCAC-458D-BC8E-A2647D0242D8}
(PID) Process:(6652) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\393932
Operation:writeName:WindowTabManagerFileMappingId
Value:
{EA3EC358-2B3E-48F6-9CD2-2A14D55F90CB}
(PID) Process:(6652) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
62D0C6E7AF972F00
Executable files
129
Suspicious files
817
Text files
158
Unknown types
45

Dropped files

PID
Process
Filename
Type
3100striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174d26\striata-reader.runtime\dll4D26.tmpcompressed
MD5:D38DBE54A48CE0E5942C2DA9366423A2
SHA256:71505888D2C184BB9E40BC433F578D71D0A30513F1FD80DA4DE5BB00096F6451
3100striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174d26\striata-reader.runtime\dll4D59.tmpcompressed
MD5:82D319390B13690D8DD04EF2F689554D
SHA256:23415A152B78BA723E4B4CFDCC2E00BC8EB223F5996D34A4637CD78AD6CB34BC
3100striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174d26\striata-reader.runtime\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:5A75A7940BC8762E41DAFCCE9C07628B
SHA256:4AAF273C4CB1D93B8C8686843FFBC577D31E1C010E02AE8E72478C5B52DDA06D
3100striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174d26\striata-reader.runtime\dll4D36.tmpcompressed
MD5:48C48773CD43C3F161FAAD6B9720C259
SHA256:48215C3C0A405F0B4C4D85349CEF0CC83F0BC96DBBD8ADC235C3364C4C3A15AC
3100striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174d26\striata-reader.runtime\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:B65D571875079332C81963FF98E62AB3
SHA256:B83A794600A47BE935CC562ACE7A4D531083C76FCC8AC6424D008F1034EEDF96
3100striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174d26\striata-reader.runtime\dll4D7B.tmpcompressed
MD5:151C40552E289C18D465556EC5DB2571
SHA256:7187CD39321008A2A94AD5B6B68B2F5585A662F21D8ED71A8795FD3FF8EC5E2C
3100striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174d26\striata-reader.runtime\dll4D38.tmpcompressed
MD5:99F0D17656472D6838E61F1C6E6DCA31
SHA256:6D951E4F12E37287FD99D5B12CD15D6B515ED86348EEB6D24A76BD33C99B3390
3100striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174d26\striata-reader.runtime\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:B9A429A9FFB3C3309222E6A8FC7A0ADA
SHA256:D62E2DCB011F08B416ADDAA11D07FC295427F57CA31B0098A71CC7ED6FE2E95E
3100striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174d26\striata-reader.runtime\dll4D69.tmpcompressed
MD5:D57C4325B509403B1A307D65B4355ED9
SHA256:ED49A97AFE7D3EDA08DD78B9B7C649BD1427CC7B3837330F5010A81C6CF644D7
3100striata-reader (2).vir.exeC:\Users\admin\AppData\Local\Temp\kmtempinstall\174d26\striata-reader.runtime\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:CB34F8D3A8C9038E14172E2B09C5A91B
SHA256:3975CA725AE8F6F635560329EE00E214F58D6A2C9E8D355756481F92C068CD43
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
151
DNS requests
149
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6472
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6260
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:ug7dXdLeaOepqru5806zu_am34p_uEXw18o6jcgI7ZA&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
8000
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8000
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8156
svchost.exe
HEAD
200
23.50.131.74:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1751855207&P2=404&P3=2&P4=hJ50iuNEByOmqJekG63zVHlMoN%2fbKjGmc8%2b%2bIzJOxM4dtgtRAmfudlSmfCFfvg4KoSzWllFoMx5COmgDYoSOhg%3d%3d
unknown
whitelisted
8156
svchost.exe
GET
206
23.50.131.74:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1751855207&P2=404&P3=2&P4=hJ50iuNEByOmqJekG63zVHlMoN%2fbKjGmc8%2b%2bIzJOxM4dtgtRAmfudlSmfCFfvg4KoSzWllFoMx5COmgDYoSOhg%3d%3d
unknown
whitelisted
8156
svchost.exe
GET
206
23.50.131.74:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1751855207&P2=404&P3=2&P4=hJ50iuNEByOmqJekG63zVHlMoN%2fbKjGmc8%2b%2bIzJOxM4dtgtRAmfudlSmfCFfvg4KoSzWllFoMx5COmgDYoSOhg%3d%3d
unknown
whitelisted
2940
svchost.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
2.16.168.114:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
6472
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6472
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6260
msedge.exe
204.79.197.203:443
ntp.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6260
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.110
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.130
  • 40.126.31.131
  • 40.126.31.1
  • 20.190.159.4
  • 20.190.159.129
  • 40.126.31.0
  • 20.190.159.23
  • 20.190.160.130
  • 40.126.32.76
  • 20.190.160.2
  • 20.190.160.17
  • 20.190.160.132
  • 20.190.160.67
  • 20.190.160.66
  • 40.126.32.134
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
ntp.msn.com
  • 204.79.197.203
whitelisted
copilot.microsoft.com
  • 2.16.241.224
  • 2.16.241.220
whitelisted

Threats

PID
Process
Class
Message
6260
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
6260
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
6260
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
6260
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info