| URL: | https://urldefense.com/v3/__https://url.us.m.mimecastprotect.com/r/6q0U5vMPzyquzde35XDxcyKCh7AL2rP53MvVNFxZ6smhUg0MA7RUg2ye_3BTVzzM8fo_hVcf2CZH0KreeGhn5jg9KgMx4y2eIY31pMVN_cn2pBmihicM0aq8mxBgnkIq-5aQGElQai3tInqX9euUDVCvVaYBXqoQ8kXiiVrn3BtQkLNjHJlO9uQT1n0d8FbwYpXVRqgC18Mna-4vWkV3iqnfUzYQA2ZgYFWLlNyzkKdU49ovIIheEeygsouPEjlLHgKgWu3oZfHrmFs5wwJJl4afkkFljhbpQASz43eZPCjR2Y-YU_ORoeJ0U1M6RTXFNG2CEqLiBcIkdVmSUX9HHzhhK18mcFmDRKOTfvlXAobZZ9zOVQfiVv9hv3u5dMH4V-VLP3bot4PUS1-LG3QK5m_8yFjs-iDigf-9Ly0SQOTdDajpCtylmaGkHEIfY7tt1ILE_1kz2AJ2qsZ-Km6PsiHK-ZCNL_zO-zBDAvbxZku8o5HUWUm-FuIxk67ijfiSkghf8FyOEvbFM-DDWM-7xAVdKImAoTREx2Xz2kUljINBeqHxr0iuaIczrtISgnxlEEQIyx5*20kYPbV1j_JFhCq_jYUCY5wwIYRWdYu8qvmrifu7r98DbjN6zJgUa_X5bZ0unxLUxT81TYqufycl54birAKvQWtSv0Dn8-HWMA7HQLwzj1D0IPGbTsSFwdoMCuZ5ayYObEpih2fa5sS5L_Ge7mqE7KjMtsUDXhVg11Ih6Ah30zdYpupYPf6DbH9dfJilFhksbmnw5sDf2vhQqAIHS8Ya-cP1yrlG4y-w433mVmwFFpi0x94wKptXyzSPrK3U1pJ1Q46jO-hoEoNYvNipjmXZK1tXUjNTCyiop5z2QcB7kTTpAXP2ns0HR9uQllI5ca_GhO2xQPXOKgG1NJYO5N2rcG9bQyIoAhKUqzcHlxg4JuIVuF6EyoKuocRVxPq5frw5KifFRQcFGOUpxeH4LHSXgW-7RLtHYYLXHRarDpNZ6bODrQ9b49VbTKHVsUojsUrDXViZV9eiul8s6EsM4aLycrEJ-r-VaFDL90JKqnX_duKvWOIPo30awqxVIEyeewBRP1A_3mhG5HPlGKUpOqM0AaW-EUQ7OlRuYybwUyysvorleHmlUE6mhVj0CPM0i5vC4Sbc_8kmfcrcAxFTq4Z_aTBe1BtO7rGOifS401R_Ypvqt3sviF4aohimCXwGsX4ARAfOxOchUD1w7np73iBzzxa2g3itNhbsdpc021OeB0_87EtirY4OC75Lc_HSgrf6OKl2Ov-d_Fn6rrfXSyr9hHLDAU-JiQiokqJ3yv1NQeTWnCVvTiAdhDUp7fL8G57Uq7g0kefI6UUktWYXywR0mveipnV-70zUDh3yqF5sLiXMfIDcyCctzRy6z_jT00Y81ekIr4ZK37nvtHd0idXEi-I-1Fc58pfK7r3sUN3UaMyX9IjaFLggNONRUlkvMF7GC7BOzFk9na0cW87kSx0iRXkFKJVe_qWvpMFafR6zE83brEfbtKRH0dFCAkWESBORp7qVKWfE8RwXhk_eg07nHsflamHHNxLr2ncYMDX*20JFLn-Pk9AvlwoqVoXh5LvkqfBEh0_VVaz2yI_DZ2ZsfN8AWxStpTidespfJuKah8N58v9EUjyFHsrJ8jW2XUMLtysUeTon-SN3YRn5MdDg-cn1Sxa8arGnbITqnNc0BkdK6DEc3dxaKG2bfQCFm89hFvVZV484UoNDBR0R6ZFS_F1dCMif77hKxSdnhN96RICdvCzNNe9cR5L7ue_KKyFenHxmVoUtlfNu-Tt1pmPzNc6FMiAw15e2zbpvsz9b2KM4BAzT9ylnEsd3an66168cbAk_yYrfM5TZmyl8U6r12mW0Rb4Eja0BeD_IvUvydDTY8km-MJQ-MGhKVYdrCuhaJydESSn3lOqs9lFcISOSwJc41Im5q8tgEMFs4bf973mVsK3ubwBCXqiP05myP3c7OLrlBk1A2oVKk41WAcV1NivNiBIrXFuZVe1eVMVnZHwoWDk8tIbHPCWkWMlObB4aw3kuYtqc1nymLFvqQNmV22SzsNRkd1gvfH_9pFVRz0ScbCVRncpeX2RjiNVXqW8xaGU6f7NIj2g2lZc0eQRYejPyOOOpCesmbXDevrY99l0URRhxmpbKTHieRx2RDrhZfmNapeyRKhwd56L-zP-eu4veCSCYXjIXBUOzlHo2vLBGqBY0JiWip_YL1y3PDO5QxdSb67PYhyaS60SdCwy-vH9ysqtK527YgcjGnouwTHkOx48mZqM71XBthi7R5TVTy1XSGLLX48f2r8cl1FK584OlNh-1hgXobWFQY8G2XpUewJMCZxbFtw4m1GvDmThQBOosXGt6HsCqvkh1fa41MnX9hKWTJ8QUms2L9zYAv_PAEyIjAbz7dEISmvoDr7K4rpavguR9HqmdA5pjuQ41yI152QFVSWLQwWXbR_sP3RD4eXVvkb75VGfkVGcAsYqjHqo60K43aFmIWCYggNy4babWPVTnoSX64ILJut9QWVbwEIc1BO5gZ1CCHTLPaTjRNaKhcSBRzmsvNOQ*20IYNTnTyD2xIKIIsY2D6_ibC8Y0bg-ni29m6WmvuXwSXXGwqNdNHYPT8HoCPDvHt_mb2PWtDmdlQdolIF115nVIl5GEkQJzhA6km9rBUs9PtwI1Ddw3Gzu5ndf2z4kYdR19EpuJvMNb2rzvwvZHXPO87bhJ-L3oCbLyH4rUzeDxpGR5_0rHuQufzz08qRuXytfaVz7BuyKaPWM0b7qT1kCVA8qXIULZ3bwXwzupLFN0U1u-Mn2rK22NuXWtCm10oC5P6Q3_9n67_-DTqXFauGKFY6dT_PDSWkk_SKcwzAb9PdsiclpMcVHZQg42BeeVi7fONifH0ApKf2zgPs2dT4LSenn9cllvx0lwk7_NYc-XAtp6ID3-rL8_anZ76NijT7o6DQ4DpsnnS4vgjtQLJpa3yroc8zFEvRsyqiW-V55q59zSqzKWqpKqi95iO9SzdYEG98jlYZPtHjxbnqCW5ugZtt8ObMDKEJZhifeFAIzXcy_Lkkpn5hwmc2JleOLvBVZ52IvR7JOTZV7FqH20l8Ax3RHzHQueqxp15Ewtm2KdLi21P3AWwHIfqQ5zYELPuOqG5UHej8gIuVIGVwYXZ-wLiVKYIXVlXfunKxbSgqyHkF8lHpmfcSZ6K6UrSaMupmPTFhvKADwNm9HjhRVxBe7RL-kM9WuaLhXA29XYRPqn-DyHMevwAnRS76uGHRWk9cqOEaCEpqFq-D3iRaoCziEpTqkmGlKCZb6tcMZnMA2EUqvXhG7GTe2U8ZK-sy032cis85Ez_xAW8yREPIe1pQQig5-5T5523SMogeiI5PXjCQAsJp0LuAY9DlmQC5K4tQ5rCeZZr0hCURHYX6yToL4L7UBjzRj_yZtYQ4EaOrL-VK1C4uVb2MnBfMEBOlw-b9Eny39LgXG6byEajWZr9M9l43EQnnkpxH6c51d8KbsCJST_GtYiOdltEeqXpW-2TflZ_bPJn6wM0MU1TjMPTPi65l7oahZf88gWLyP*200VAvkw_2Y8QENeh8wCX_uydt-LlVL5FPztH6Wo7I28fAkBpqIXuQJQoEYz_8qrvfokYs5hb_tlK0uhd0ZsRPemO7W3HwvM8L604q3v858q7EobC8xG4A9I_7onvnsWOJbqoCVDHipskifLqQGsJauQ4EHVNmHrxkgFNWHbWC2h55oVQ2LDWCpgFvoyfJOHDDTgW83bUTMgE3w9j6cujpcG5U64itJ6DM4jPrBjRtQWnmNCM9VH_O7ueGKpAWLZFI8q4bAP-19ngym4L7qWdQ3E-tIWNH4NZM9kkz1cB_0tfoXjxKWUBlCr9Q_5wya0JCYCibvfhWEJjlkVypiTVOUTZg-TjP6t9FDE4upTsf-7O_Ieu8ga37Inw_65BTHEepwLz9uoGX02nA7NJNgF_NpBgp-2wBOSwzaRamyiClzTb21sVuq6GFswSwqeMujS56p4rSsuA_bLXoFR3JykSCy4uSmgFn4-5TzHa2-LZO_bEWtJVQBDan8hTeDMpE1bdf52F8av2upS4KXN48nuc5nQZeYIMbJpXoyFNC-2c98HksZDMkwQuNyZFCk5fLrdFJ10G2ZkYF3zrllWiKdY8Nyo0A5IUo2B5_qG0WRuPIdLikESw3fwXXki8-wZ0ijA12H9dI3EcMsYVzJiTB2G9gFe1IWiTm1nj1_Ku7ydwNEDJvFv6lQ34N2Wril5APJn-g0GzvjFMvGMqL1RZ26SldD5m2Ri__-NSLI5j3s3vwhsYJQ-gA0Rdzor_qYn9fI7AtCVPGUcHi5XCc2UdxkB9Q8dkqC1uhDAHG4tA4KHr_ithYDg_xiAtY2gQGdpAFminrAtTaF4UCfphbUpha_Q7Vu2jIK00LRrMDFqdpE9YKhH20NNnSDO0BAcwekkATJL7Z8IISFeihe_JWz7JOJk9sCT7BJ4OtEzKr-DcRmF32szK-gw_1eoHBxTypM3kKtGAGmNyDkHcVyp45865D8Ly9pM9LDyhOQMwoQ-cff*20gEH6fq61ZLtD1NSy6jS0b0JfC4V9WPLgRLsZsqvsuPifrDkX4PEplirMBdBsCxFRGgdRWpmMlus-7K0daboAAKpx9WaMHrD_L3wJEhz7Ylq6GksIdbFhEU_9-ovpPX4dWCziT8Z8WoI6aH9dRGps3_nGWJ1ECRFf16BR6U_gn_osZA8fusIjfdOMLD5F5Ze7cgzX9RIcM9EaKxvjJBZi4XFQZw2utep3H4_PMrJuB7BXl0BQnzHitla66tUsekoJ5QDz3Qof7T8ZYQixN9u-t69-qCalFqgGLHfOZhp6ZS7PGvnCVysEvuyBB6MezNiOs43vxBKjlIuICRFryaKMGKgDj_LxjtzYeRh6mnvQ72oXn6TOhL-GM7XTmng__;JSUlJSU!!OCETVpHz5yeZTQ!2vAuHL0_MOCA4kswO6-M2Y4jNq12orP9bMOp0E8mPjmB0jGh4oDntAP3x9nwBj7N2gCncUC380sN9M36v_yy2IWFi9Fx$ |
| Full analysis: | https://app.any.run/tasks/d90f9a68-6972-4a4e-9a49-b1e96c305209 |
| Verdict: | Malicious activity |
| Threats: | Sneaky 2FA is an Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts. Distributed as a Phishing-as-a-Service (PhaaS) through a Telegram bot, this malware bypasses two-factor authentication (2FA) to steal credentials and session cookies, posing a significant threat to individuals and organizations. |
| Analysis date: | February 23, 2026, 13:50:43 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 88B4156AE5E3016DA130BDD022A73A97 |
| SHA1: | 7CCEA2B845CBBC9A760191B79195E5715C69C6AB |
| SHA256: | 2D019312A8F03912DC8A50B9487D6AAA909462AF793A2D6B9100D155B83B7082 |
| SSDEEP: | 96:eUZVV0SLkai3nGo6LhhPZTbcgLzeMC82rKmtptcJO5Uiz4jfs:eyTRYaiWvPZTogW2mtTcUWizS0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1520 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --string-annotations --gpu-preferences=UAAAAAAAAADoAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAABCAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=3280,i,1237823707929661658,1123351627549376153,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=3632 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2052 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=16 --always-read-main-dll --field-trial-handle=6796,i,1237823707929661658,1123351627549376153,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6788 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2248 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3640,i,1237823707929661658,1123351627549376153,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=2356 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2620 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4700,i,1237823707929661658,1123351627549376153,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5224 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2976 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5712,i,1237823707929661658,1123351627549376153,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5692 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 3088 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2280,i,1237823707929661658,1123351627549376153,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=2272 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 3236 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3648,i,1237823707929661658,1123351627549376153,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=3568 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 3644 | "C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5888,i,1237823707929661658,1123351627549376153,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=2716 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: PWA Identity Proxy Host Exit code: 3221226029 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 3700 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4012,i,1237823707929661658,1123351627549376153,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=7068 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 4216 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6212,i,1237823707929661658,1123351627549376153,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6276 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7256 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1e5050.TMP | — | |
MD5:— | SHA256:— | |||
| 7256 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1e5050.TMP | — | |
MD5:— | SHA256:— | |||
| 7256 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1e5050.TMP | — | |
MD5:— | SHA256:— | |||
| 7256 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7256 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1e5060.TMP | — | |
MD5:— | SHA256:— | |||
| 7256 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7256 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7256 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7256 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1e5060.TMP | — | |
MD5:— | SHA256:— | |||
| 7256 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6596 | msedge.exe | GET | 302 | 52.71.28.102:443 | https://urldefense.com/v3/__https://url.us.m.mimecastprotect.com/r/6q0U5vMPzyquzde35XDxcyKCh7AL2rP53MvVNFxZ6smhUg0MA7RUg2ye_3BTVzzM8fo_hVcf2CZH0KreeGhn5jg9KgMx4y2eIY31pMVN_cn2pBmihicM0aq8mxBgnkIq-5aQGElQai3tInqX9euUDVCvVaYBXqoQ8kXiiVrn3BtQkLNjHJlO9uQT1n0d8FbwYpXVRqgC18Mna-4vWkV3iqnfUzYQA2ZgYFWLlNyzkKdU49ovIIheEeygsouPEjlLHgKgWu3oZfHrmFs5wwJJl4afkkFljhbpQASz43eZPCjR2Y-YU_ORoeJ0U1M6RTXFNG2CEqLiBcIkdVmSUX9HHzhhK18mcFmDRKOTfvlXAobZZ9zOVQfiVv9hv3u5dMH4V-VLP3bot4PUS1-LG3QK5m_8yFjs-iDigf-9Ly0SQOTdDajpCtylmaGkHEIfY7tt1ILE_1kz2AJ2qsZ-Km6PsiHK-ZCNL_zO-zBDAvbxZku8o5HUWUm-FuIxk67ijfiSkghf8FyOEvbFM-DDWM-7xAVdKImAoTREx2Xz2kUljINBeqHxr0iuaIczrtISgnxlEEQIyx5*20kYPbV1j_JFhCq_jYUCY5wwIYRWdYu8qvmrifu7r98DbjN6zJgUa_X5bZ0unxLUxT81TYqufycl54birAKvQWtSv0Dn8-HWMA7HQLwzj1D0IPGbTsSFwdoMCuZ5ayYObEpih2fa5sS5L_Ge7mqE7KjMtsUDXhVg11Ih6Ah30zdYpupYPf6DbH9dfJilFhksbmnw5sDf2vhQqAIHS8Ya-cP1yrlG4y-w433mVmwFFpi0x94wKptXyzSPrK3U1pJ1Q46jO-hoEoNYvNipjmXZK1tXUjNTCyiop5z2QcB7kTTpAXP2ns0HR9uQllI5ca_GhO2xQPXOKgG1NJYO5N2rcG9bQyIoAhKUqzcHlxg4JuIVuF6EyoKuocRVxPq5frw5KifFRQcFGOUpxeH4LHSXgW-7RLtHYYLXHRarDpNZ6bODrQ9b49VbTKHVsUojsUrDXViZV9eiul8s6EsM4aLycrEJ-r-VaFDL90JKqnX_duKvWOIPo30awqxVIEyeewBRP1A_3mhG5HPlGKUpOqM0AaW-EUQ7OlRuYybwUyysvorleHmlUE6mhVj0CPM0i5vC4Sbc_8kmfcrcAxFTq4Z_aTBe1BtO7rGOifS401R_Ypvqt3sviF4aohimCXwGsX4ARAfOxOchUD1w7np73iBzzxa2g3itNhbsdpc021OeB0_87EtirY4OC75Lc_HSgrf6OKl2Ov-d_Fn6rrfXSyr9hHLDAU-JiQiokqJ3yv1NQeTWnCVvTiAdhDUp7fL8G57Uq7g0kefI6UUktWYXywR0mveipnV-70zUDh3yqF5sLiXMfIDcyCctzRy6z_jT00Y81ekIr4ZK37nvtHd0idXEi-I-1Fc58pfK7r3sUN3UaMyX9IjaFLggNONRUlkvMF7GC7BOzFk9na0cW87kSx0iRXkFKJVe_qWvpMFafR6zE83brEfbtKRH0dFCAkWESBORp7qVKWfE8RwXhk_eg07nHsflamHHNxLr2ncYMDX*20JFLn-Pk9AvlwoqVoXh5LvkqfBEh0_VVaz2yI_DZ2ZsfN8AWxStpTidespfJuKah8N58v9EUjyFHsrJ8jW2XUMLtysUeTon-SN3YRn5MdDg-cn1Sxa8arGnbITqnNc0BkdK6DEc3dxaKG2bfQCFm89hFvVZV484UoNDBR0R6ZFS_F1dCMif77hKxSdnhN96RICdvCzNNe9cR5L7ue_KKyFenHxmVoUtlfNu-Tt1pmPzNc6FMiAw15e2zbpvsz9b2KM4BAzT9ylnEsd3an66168cbAk_yYrfM5TZmyl8U6r12mW0Rb4Eja0BeD_IvUvydDTY8km-MJQ-MGhKVYdrCuhaJydESSn3lOqs9lFcISOSwJc41Im5q8tgEMFs4bf973mVsK3ubwBCXqiP05myP3c7OLrlBk1A2oVKk41WAcV1NivNiBIrXFuZVe1eVMVnZHwoWDk8tIbHPCWkWMlObB4aw3kuYtqc1nymLFvqQNmV22SzsNRkd1gvfH_9pFVRz0ScbCVRncpeX2RjiNVXqW8xaGU6f7NIj2g2lZc0eQRYejPyOOOpCesmbXDevrY99l0URRhxmpbKTHieRx2RDrhZfmNapeyRKhwd56L-zP-eu4veCSCYXjIXBUOzlHo2vLBGqBY0JiWip_YL1y3PDO5QxdSb67PYhyaS60SdCwy-vH9ysqtK527YgcjGnouwTHkOx48mZqM71XBthi7R5TVTy1XSGLLX48f2r8cl1FK584OlNh-1hgXobWFQY8G2XpUewJMCZxbFtw4m1GvDmThQBOosXGt6HsCqvkh1fa41MnX9hKWTJ8QUms2L9zYAv_PAEyIjAbz7dEISmvoDr7K4rpavguR9HqmdA5pjuQ41yI152QFVSWLQwWXbR_sP3RD4eXVvkb75VGfkVGcAsYqjHqo60K43aFmIWCYggNy4babWPVTnoSX64ILJut9QWVbwEIc1BO5gZ1CCHTLPaTjRNaKhcSBRzmsvNOQ*20IYNTnTyD2xIKIIsY2D6_ibC8Y0bg-ni29m6WmvuXwSXXGwqNdNHYPT8HoCPDvHt_mb2PWtDmdlQdolIF115nVIl5GEkQJzhA6km9rBUs9PtwI1Ddw3Gzu5ndf2z4kYdR19EpuJvMNb2rzvwvZHXPO87bhJ-L3oCbLyH4rUzeDxpGR5_0rHuQufzz08qRuXytfaVz7BuyKaPWM0b7qT1kCVA8qXIULZ3bwXwzupLFN0U1u-Mn2rK22NuXWtCm10oC5P6Q3_9n67_-DTqXFauGKFY6dT_PDSWkk_SKcwzAb9PdsiclpMcVHZQg42BeeVi7fONifH0ApKf2zgPs2dT4LSenn9cllvx0lwk7_NYc-XAtp6ID3-rL8_anZ76NijT7o6DQ4DpsnnS4vgjtQLJpa3yroc8zFEvRsyqiW-V55q59zSqzKWqpKqi95iO9SzdYEG98jlYZPtHjxbnqCW5ugZtt8ObMDKEJZhifeFAIzXcy_Lkkpn5hwmc2JleOLvBVZ52IvR7JOTZV7FqH20l8Ax3RHzHQueqxp15Ewtm2KdLi21P3AWwHIfqQ5zYELPuOqG5UHej8gIuVIGVwYXZ-wLiVKYIXVlXfunKxbSgqyHkF8lHpmfcSZ6K6UrSaMupmPTFhvKADwNm9HjhRVxBe7RL-kM9WuaLhXA29XYRPqn-DyHMevwAnRS76uGHRWk9cqOEaCEpqFq-D3iRaoCziEpTqkmGlKCZb6tcMZnMA2EUqvXhG7GTe2U8ZK-sy032cis85Ez_xAW8yREPIe1pQQig5-5T5523SMogeiI5PXjCQAsJp0LuAY9DlmQC5K4tQ5rCeZZr0hCURHYX6yToL4L7UBjzRj_yZtYQ4EaOrL-VK1C4uVb2MnBfMEBOlw-b9Eny39LgXG6byEajWZr9M9l43EQnnkpxH6c51d8KbsCJST_GtYiOdltEeqXpW-2TflZ_bPJn6wM0MU1TjMPTPi65l7oahZf88gWLyP*200VAvkw_2Y8QENeh8wCX_uydt-LlVL5FPztH6Wo7I28fAkBpqIXuQJQoEYz_8qrvfokYs5hb_tlK0uhd0ZsRPemO7W3HwvM8L604q3v858q7EobC8xG4A9I_7onvnsWOJbqoCVDHipskifLqQGsJauQ4EHVNmHrxkgFNWHbWC2h55oVQ2LDWCpgFvoyfJOHDDTgW83bUTMgE3w9j6cujpcG5U64itJ6DM4jPrBjRtQWnmNCM9VH_O7ueGKpAWLZFI8q4bAP-19ngym4L7qWdQ3E-tIWNH4NZM9kkz1cB_0tfoXjxKWUBlCr9Q_5wya0JCYCibvfhWEJjlkVypiTVOUTZg-TjP6t9FDE4upTsf-7O_Ieu8ga37Inw_65BTHEepwLz9uoGX02nA7NJNgF_NpBgp-2wBOSwzaRamyiClzTb21sVuq6GFswSwqeMujS56p4rSsuA_bLXoFR3JykSCy4uSmgFn4-5TzHa2-LZO_bEWtJVQBDan8hTeDMpE1bdf52F8av2upS4KXN48nuc5nQZeYIMbJpXoyFNC-2c98HksZDMkwQuNyZFCk5fLrdFJ10G2ZkYF3zrllWiKdY8Nyo0A5IUo2B5_qG0WRuPIdLikESw3fwXXki8-wZ0ijA12H9dI3EcMsYVzJiTB2G9gFe1IWiTm1nj1_Ku7ydwNEDJvFv6lQ34N2Wril5APJn-g0GzvjFMvGMqL1RZ26SldD5m2Ri__-NSLI5j3s3vwhsYJQ-gA0Rdzor_qYn9fI7AtCVPGUcHi5XCc2UdxkB9Q8dkqC1uhDAHG4tA4KHr_ithYDg_xiAtY2gQGdpAFminrAtTaF4UCfphbUpha_Q7Vu2jIK00LRrMDFqdpE9YKhH20NNnSDO0BAcwekkATJL7Z8IISFeihe_JWz7JOJk9sCT7BJ4OtEzKr-DcRmF32szK-gw_1eoHBxTypM3kKtGAGmNyDkHcVyp45865D8Ly9pM9LDyhOQMwoQ-cff*20gEH6fq61ZLtD1NSy6jS0b0JfC4V9WPLgRLsZsqvsuPifrDkX4PEplirMBdBsCxFRGgdRWpmMlus-7K0daboAAKpx9WaMHrD_L3wJEhz7Ylq6GksIdbFhEU_9-ovpPX4dWCziT8Z8WoI6aH9dRGps3_nGWJ1ECRFf16BR6U_gn_osZA8fusIjfdOMLD5F5Ze7cgzX9RIcM9EaKxvjJBZi4XFQZw2utep3H4_PMrJuB7BXl0BQnzHitla66tUsekoJ5QDz3Qof7T8ZYQixN9u-t69-qCalFqgGLHfOZhp6ZS7PGvnCVysEvuyBB6MezNiOs43vxBKjlIuICRFryaKMGKgDj_LxjtzYeRh6mnvQ72oXn6TOhL-GM7XTmng__;JSUlJSU!!OCETVpHz5yeZTQ!2vAuHL0_MOCA4kswO6-M2Y4jNq12orP9bMOp0E8mPjmB0jGh4oDntAP3x9nwBj7N2gCncUC380sN9M36v_yy2IWFi9Fx$ | unknown | — | — | unknown |
6596 | msedge.exe | GET | 307 | 207.211.31.113:443 | https://url.us.m.mimecastprotect.com/r/6q0U5vMPzyquzde35XDxcyKCh7AL2rP53MvVNFxZ6smhUg0MA7RUg2ye_3BTVzzM8fo_hVcf2CZH0KreeGhn5jg9KgMx4y2eIY31pMVN_cn2pBmihicM0aq8mxBgnkIq-5aQGElQai3tInqX9euUDVCvVaYBXqoQ8kXiiVrn3BtQkLNjHJlO9uQT1n0d8FbwYpXVRqgC18Mna-4vWkV3iqnfUzYQA2ZgYFWLlNyzkKdU49ovIIheEeygsouPEjlLHgKgWu3oZfHrmFs5wwJJl4afkkFljhbpQASz43eZPCjR2Y-YU_ORoeJ0U1M6RTXFNG2CEqLiBcIkdVmSUX9HHzhhK18mcFmDRKOTfvlXAobZZ9zOVQfiVv9hv3u5dMH4V-VLP3bot4PUS1-LG3QK5m_8yFjs-iDigf-9Ly0SQOTdDajpCtylmaGkHEIfY7tt1ILE_1kz2AJ2qsZ-Km6PsiHK-ZCNL_zO-zBDAvbxZku8o5HUWUm-FuIxk67ijfiSkghf8FyOEvbFM-DDWM-7xAVdKImAoTREx2Xz2kUljINBeqHxr0iuaIczrtISgnxlEEQIyx5%20kYPbV1j_JFhCq_jYUCY5wwIYRWdYu8qvmrifu7r98DbjN6zJgUa_X5bZ0unxLUxT81TYqufycl54birAKvQWtSv0Dn8-HWMA7HQLwzj1D0IPGbTsSFwdoMCuZ5ayYObEpih2fa5sS5L_Ge7mqE7KjMtsUDXhVg11Ih6Ah30zdYpupYPf6DbH9dfJilFhksbmnw5sDf2vhQqAIHS8Ya-cP1yrlG4y-w433mVmwFFpi0x94wKptXyzSPrK3U1pJ1Q46jO-hoEoNYvNipjmXZK1tXUjNTCyiop5z2QcB7kTTpAXP2ns0HR9uQllI5ca_GhO2xQPXOKgG1NJYO5N2rcG9bQyIoAhKUqzcHlxg4JuIVuF6EyoKuocRVxPq5frw5KifFRQcFGOUpxeH4LHSXgW-7RLtHYYLXHRarDpNZ6bODrQ9b49VbTKHVsUojsUrDXViZV9eiul8s6EsM4aLycrEJ-r-VaFDL90JKqnX_duKvWOIPo30awqxVIEyeewBRP1A_3mhG5HPlGKUpOqM0AaW-EUQ7OlRuYybwUyysvorleHmlUE6mhVj0CPM0i5vC4Sbc_8kmfcrcAxFTq4Z_aTBe1BtO7rGOifS401R_Ypvqt3sviF4aohimCXwGsX4ARAfOxOchUD1w7np73iBzzxa2g3itNhbsdpc021OeB0_87EtirY4OC75Lc_HSgrf6OKl2Ov-d_Fn6rrfXSyr9hHLDAU-JiQiokqJ3yv1NQeTWnCVvTiAdhDUp7fL8G57Uq7g0kefI6UUktWYXywR0mveipnV-70zUDh3yqF5sLiXMfIDcyCctzRy6z_jT00Y81ekIr4ZK37nvtHd0idXEi-I-1Fc58pfK7r3sUN3UaMyX9IjaFLggNONRUlkvMF7GC7BOzFk9na0cW87kSx0iRXkFKJVe_qWvpMFafR6zE83brEfbtKRH0dFCAkWESBORp7qVKWfE8RwXhk_eg07nHsflamHHNxLr2ncYMDX%20JFLn-Pk9AvlwoqVoXh5LvkqfBEh0_VVaz2yI_DZ2ZsfN8AWxStpTidespfJuKah8N58v9EUjyFHsrJ8jW2XUMLtysUeTon-SN3YRn5MdDg-cn1Sxa8arGnbITqnNc0BkdK6DEc3dxaKG2bfQCFm89hFvVZV484UoNDBR0R6ZFS_F1dCMif77hKxSdnhN96RICdvCzNNe9cR5L7ue_KKyFenHxmVoUtlfNu-Tt1pmPzNc6FMiAw15e2zbpvsz9b2KM4BAzT9ylnEsd3an66168cbAk_yYrfM5TZmyl8U6r12mW0Rb4Eja0BeD_IvUvydDTY8km-MJQ-MGhKVYdrCuhaJydESSn3lOqs9lFcISOSwJc41Im5q8tgEMFs4bf973mVsK3ubwBCXqiP05myP3c7OLrlBk1A2oVKk41WAcV1NivNiBIrXFuZVe1eVMVnZHwoWDk8tIbHPCWkWMlObB4aw3kuYtqc1nymLFvqQNmV22SzsNRkd1gvfH_9pFVRz0ScbCVRncpeX2RjiNVXqW8xaGU6f7NIj2g2lZc0eQRYejPyOOOpCesmbXDevrY99l0URRhxmpbKTHieRx2RDrhZfmNapeyRKhwd56L-zP-eu4veCSCYXjIXBUOzlHo2vLBGqBY0JiWip_YL1y3PDO5QxdSb67PYhyaS60SdCwy-vH9ysqtK527YgcjGnouwTHkOx48mZqM71XBthi7R5TVTy1XSGLLX48f2r8cl1FK584OlNh-1hgXobWFQY8G2XpUewJMCZxbFtw4m1GvDmThQBOosXGt6HsCqvkh1fa41MnX9hKWTJ8QUms2L9zYAv_PAEyIjAbz7dEISmvoDr7K4rpavguR9HqmdA5pjuQ41yI152QFVSWLQwWXbR_sP3RD4eXVvkb75VGfkVGcAsYqjHqo60K43aFmIWCYggNy4babWPVTnoSX64ILJut9QWVbwEIc1BO5gZ1CCHTLPaTjRNaKhcSBRzmsvNOQ%20IYNTnTyD2xIKIIsY2D6_ibC8Y0bg-ni29m6WmvuXwSXXGwqNdNHYPT8HoCPDvHt_mb2PWtDmdlQdolIF115nVIl5GEkQJzhA6km9rBUs9PtwI1Ddw3Gzu5ndf2z4kYdR19EpuJvMNb2rzvwvZHXPO87bhJ-L3oCbLyH4rUzeDxpGR5_0rHuQufzz08qRuXytfaVz7BuyKaPWM0b7qT1kCVA8qXIULZ3bwXwzupLFN0U1u-Mn2rK22NuXWtCm10oC5P6Q3_9n67_-DTqXFauGKFY6dT_PDSWkk_SKcwzAb9PdsiclpMcVHZQg42BeeVi7fONifH0ApKf2zgPs2dT4LSenn9cllvx0lwk7_NYc-XAtp6ID3-rL8_anZ76NijT7o6DQ4DpsnnS4vgjtQLJpa3yroc8zFEvRsyqiW-V55q59zSqzKWqpKqi95iO9SzdYEG98jlYZPtHjxbnqCW5ugZtt8ObMDKEJZhifeFAIzXcy_Lkkpn5hwmc2JleOLvBVZ52IvR7JOTZV7FqH20l8Ax3RHzHQueqxp15Ewtm2KdLi21P3AWwHIfqQ5zYELPuOqG5UHej8gIuVIGVwYXZ-wLiVKYIXVlXfunKxbSgqyHkF8lHpmfcSZ6K6UrSaMupmPTFhvKADwNm9HjhRVxBe7RL-kM9WuaLhXA29XYRPqn-DyHMevwAnRS76uGHRWk9cqOEaCEpqFq-D3iRaoCziEpTqkmGlKCZb6tcMZnMA2EUqvXhG7GTe2U8ZK-sy032cis85Ez_xAW8yREPIe1pQQig5-5T5523SMogeiI5PXjCQAsJp0LuAY9DlmQC5K4tQ5rCeZZr0hCURHYX6yToL4L7UBjzRj_yZtYQ4EaOrL-VK1C4uVb2MnBfMEBOlw-b9Eny39LgXG6byEajWZr9M9l43EQnnkpxH6c51d8KbsCJST_GtYiOdltEeqXpW-2TflZ_bPJn6wM0MU1TjMPTPi65l7oahZf88gWLyP%200VAvkw_2Y8QENeh8wCX_uydt-LlVL5FPztH6Wo7I28fAkBpqIXuQJQoEYz_8qrvfokYs5hb_tlK0uhd0ZsRPemO7W3HwvM8L604q3v858q7EobC8xG4A9I_7onvnsWOJbqoCVDHipskifLqQGsJauQ4EHVNmHrxkgFNWHbWC2h55oVQ2LDWCpgFvoyfJOHDDTgW83bUTMgE3w9j6cujpcG5U64itJ6DM4jPrBjRtQWnmNCM9VH_O7ueGKpAWLZFI8q4bAP-19ngym4L7qWdQ3E-tIWNH4NZM9kkz1cB_0tfoXjxKWUBlCr9Q_5wya0JCYCibvfhWEJjlkVypiTVOUTZg-TjP6t9FDE4upTsf-7O_Ieu8ga37Inw_65BTHEepwLz9uoGX02nA7NJNgF_NpBgp-2wBOSwzaRamyiClzTb21sVuq6GFswSwqeMujS56p4rSsuA_bLXoFR3JykSCy4uSmgFn4-5TzHa2-LZO_bEWtJVQBDan8hTeDMpE1bdf52F8av2upS4KXN48nuc5nQZeYIMbJpXoyFNC-2c98HksZDMkwQuNyZFCk5fLrdFJ10G2ZkYF3zrllWiKdY8Nyo0A5IUo2B5_qG0WRuPIdLikESw3fwXXki8-wZ0ijA12H9dI3EcMsYVzJiTB2G9gFe1IWiTm1nj1_Ku7ydwNEDJvFv6lQ34N2Wril5APJn-g0GzvjFMvGMqL1RZ26SldD5m2Ri__-NSLI5j3s3vwhsYJQ-gA0Rdzor_qYn9fI7AtCVPGUcHi5XCc2UdxkB9Q8dkqC1uhDAHG4tA4KHr_ithYDg_xiAtY2gQGdpAFminrAtTaF4UCfphbUpha_Q7Vu2jIK00LRrMDFqdpE9YKhH20NNnSDO0BAcwekkATJL7Z8IISFeihe_JWz7JOJk9sCT7BJ4OtEzKr-DcRmF32szK-gw_1eoHBxTypM3kKtGAGmNyDkHcVyp45865D8Ly9pM9LDyhOQMwoQ-cff%20gEH6fq61ZLtD1NSy6jS0b0JfC4V9WPLgRLsZsqvsuPifrDkX4PEplirMBdBsCxFRGgdRWpmMlus-7K0daboAAKpx9WaMHrD_L3wJEhz7Ylq6GksIdbFhEU_9-ovpPX4dWCziT8Z8WoI6aH9dRGps3_nGWJ1ECRFf16BR6U_gn_osZA8fusIjfdOMLD5F5Ze7cgzX9RIcM9EaKxvjJBZi4XFQZw2utep3H4_PMrJuB7BXl0BQnzHitla66tUsekoJ5QDz3Qof7T8ZYQixN9u-t69-qCalFqgGLHfOZhp6ZS7PGvnCVysEvuyBB6MezNiOs43vxBKjlIuICRFryaKMGKgDj_LxjtzYeRh6mnvQ72oXn6TOhL-GM7XTmng | unknown | — | — | unknown |
6596 | msedge.exe | GET | 304 | 150.171.27.11:443 | https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist | unknown | — | — | whitelisted |
— | — | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D | unknown | — | — | whitelisted |
6596 | msedge.exe | GET | 200 | 150.171.27.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:gmywNEoiNF9FgkARAS7UpVeLJ6D2U6o4XSrbWZvgLys&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | unknown | — | — | whitelisted |
6596 | msedge.exe | GET | 200 | 150.171.22.17:443 | https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=66&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0 | unknown | text | 4.47 Kb | whitelisted |
6596 | msedge.exe | GET | 200 | 150.171.27.11:443 | https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0 | unknown | binary | 295 b | whitelisted |
6596 | msedge.exe | GET | 200 | 13.107.246.44:443 | https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appId=edge-extensions&country=US | unknown | binary | 82 b | whitelisted |
6596 | msedge.exe | GET | 200 | 104.18.22.222:443 | https://copilot.microsoft.com/c/api/user/eligibility | unknown | — | 25 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3656 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
5412 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5568 | SearchApp.exe | 92.123.104.52:443 | www.bing.com | AKAMAI-ASN1 | NL | whitelisted |
— | — | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
— | — | 204.79.197.203:80 | oneocsp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3412 | svchost.exe | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
6596 | msedge.exe | 150.171.27.11:80 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
oneocsp.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
urldefense.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6596 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
6596 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
6596 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge |
6596 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge |
6596 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge |
6596 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Sneaky2FA activity observed related HTTP GET request |
6596 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Sneaky2FA activity observed related JS |
6596 | msedge.exe | Possible Social Engineering Attempted | ET PHISHING Suspicious HTML Decimal Obfuscated Title - Possible Phishing Landing Apr 19 2017 |
6596 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com) |
6596 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com) |