| URL: | http://edgedl.me |
| Full analysis: | https://app.any.run/tasks/efb237ff-e8c4-43be-b121-14e8b660621e |
| Verdict: | Malicious activity |
| Analysis date: | June 19, 2025, 12:38:40 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | B72CE515B66328CDED4AB37991205E8E |
| SHA1: | B8150A3FBF38D18FA38F8FF949F03D34A02EA223 |
| SHA256: | 329B05BF22C791B95AA3CC365EAEE5003B27CB32E3F8F5E73C6848B25826E585 |
| SSDEEP: | 3:N1Kb0HA:CP |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 432 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4308,i,5442097285758423310,12513405968438185005,262144 --variations-seed-version --mojo-platform-channel-handle=4312 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2848 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2236,i,5442097285758423310,12513405968438185005,262144 --variations-seed-version --mojo-platform-channel-handle=2428 /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 3980 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2156,i,5442097285758423310,12513405968438185005,262144 --variations-seed-version --mojo-platform-channel-handle=2284 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 4104 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3636,i,5442097285758423310,12513405968438185005,262144 --variations-seed-version --mojo-platform-channel-handle=3724 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 4104 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5032,i,5442097285758423310,12513405968438185005,262144 --variations-seed-version --mojo-platform-channel-handle=6876 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 4380 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=6932,i,5442097285758423310,12513405968438185005,262144 --variations-seed-version --mojo-platform-channel-handle=6684 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 6472 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=7024,i,5442097285758423310,12513405968438185005,262144 --variations-seed-version --mojo-platform-channel-handle=6992 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 6528 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3624,i,5442097285758423310,12513405968438185005,262144 --variations-seed-version --mojo-platform-channel-handle=3648 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 6532 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "http://edgedl.me" | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 6828 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2756,i,5442097285758423310,12513405968438185005,262144 --variations-seed-version --mojo-platform-channel-handle=2124 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| (PID) Process: | (6532) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (6532) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (6532) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (6532) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (6532) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: 3F61824F82962F00 | |||
| (PID) Process: | (6532) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\787138 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {02D41BC5-855A-4236-88BC-E9C3CEAA44BC} | |||
| (PID) Process: | (6532) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\787138 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {86440CD5-430B-402D-B867-2746FF331B43} | |||
| (PID) Process: | (6532) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\787138 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {B31C54AE-74BB-41CE-AAF4-A213C6492E64} | |||
| (PID) Process: | (6532) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\787138 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {E3F881F5-CD10-4B1C-8C04-B2AEEFF9E270} | |||
| (PID) Process: | (6532) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\787138 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {AF361492-A868-4DF6-9F89-B69AF043A421} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6532 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF176b5c.TMP | — | |
MD5:— | SHA256:— | |||
| 6532 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6532 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF176b5c.TMP | — | |
MD5:— | SHA256:— | |||
| 6532 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6532 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF176b6c.TMP | — | |
MD5:— | SHA256:— | |||
| 6532 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6532 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF176b8b.TMP | — | |
MD5:— | SHA256:— | |||
| 6532 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6532 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF176b8b.TMP | — | |
MD5:— | SHA256:— | |||
| 6532 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2848 | msedge.exe | GET | 200 | 150.171.28.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:XisNf8XMGQmNeF3AAeHwhZ2dqnJ6IcZTH5WYKepmdx0&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | unknown | — | — | whitelisted |
2848 | msedge.exe | GET | 200 | 103.224.182.206:80 | http://cuyuzu.com/jscheck.php?enc=%2FrhsUbSnoannay%2F4I%2Fz1pn49fjF6OXQyMWY0Wkx5cGRYMWI0dUpEVjNSckJOTDFFMTgzMzFYNitpcWFmck5OdlZtYkVTN2hXb3NrbExUN2x5YlRnN2dVSDNVdkNxRHJFc0FOaEVSOHJlb1BnWEQydVZzaS9SVSsyVktmcUppK0g1NHova09lTGpsZ01EKzcvWFBaWklQQmJIOU5iOUYrWHlFM0JBWDQzSUNxUGJKMXBKNnVONlBpQUdqTTBTYmtYc0ZQeWg3alpjdlBoTkFiUkdYR2RwdFBqcjJWSlEzUHJESTVxSE94VnMzbVVZTnlnbDBkQXNlK3VpNGp2ZStiUFZIeU5DY25WMkVrWFhKR3RBK1RYbjN2dlhPVWgvUjB5d3FlSG5FN1ljaDI3aHZCc2t6WlJrR3VuWE10Ti9BVkJLeWtRMjZ3czZwN3FBVDRIS2h2dU9yWFN4MkM1a0M3TnhNQXVXNi9aVXZaL3hDRG9aVnlkY3RLZVdtWUVwZzYyRm1mQ1M4Njl1U0ZhcjRjVSsySlpjWEJFcXVQWWZjanIrSWdMaWxUVkluUklEM0x1ZGNmV1daclBRa1lCNzFXQmthMThKYW1UY0ZpRUh6QTA2eWEraWwxNU9TWWgvaUJZM1VDRGQvcG8wWC9say82bVI5SktJZGdJbWYxaEJ3VmZnVmY2NW90YXQ0YmhPbjBLYlpkWTBsYUM0Y1JJYzZ4LzRSMU5HKzAvSHQ2dSs5cmplYkh2REhjU0N2cEV2TlBQWk5peGdhZjVqWFBrUGxJdjN1MmlNbUxyd3dIZDBOQUJ1RVU0MXFUWDRiUDV5aFB2ZFpjVUZUNDQ3SDhhbFd4NnhrRk5BeTArRldBT3hBNEs5eit0UmJjSVN5NW4zWUJYQk8zbmVpcXliNTQ5eG84R0lPdWlHd1pRbTl0TG1BWmNTb2wrNUF5VktkMEdVYjlabWZ6ZFp4anZHdkMzR2xlWklTYUQvaGY5cEtjenRnVC9wejVncGlGaU9DSjNEcUpzNXdaTmVENG5Fa1FuOEdwa2tnUTBDdkFUVDlFVFJONVJ2czlYclV4bHA5eGpHREh0bVB5U2JHQy8vazhsUWpxdDA2bWRZZTZxb1VzTEd4bjFrWXZCVHZLcndsR0hNS0swdXdDRUg3VS9rWFlkanRDZUlsYU5QcTMrOWVUQzh5czJuakhNeWVFVjAzMWNhOFRWOXg3QnlGSkE0NUVXdEhyYUZyUlFBRm5qRFNJRjhlV2hiVWhWN0xiVEwwMktmQTFRbGl5K0U0cGVNS3VveFMwcXlvOEFkeXl6WDFlMXhIUWlxUXJ0VjYyV1ZJNCtRWmVCc1hPZlN3UWZuQ054eEZvM0x0am9qZlBLOXdNNEFoa3RZdEhBdGowVDBER0ZpbDd4Vitzc0pNdCtRPT0%3D&rand=0.007825032195896142&vs=1272:602&ds=1280:720&sl=0:0&os=f&nos=f&if=f&sc=f&gpu=Google%20Inc.%20(Google)%20-%20ANGLE%20(Google,%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE)),%20SwiftShader%20driver)&fp=-1 | unknown | — | — | unknown |
2848 | msedge.exe | GET | 200 | 103.224.182.206:80 | http://cuyuzu.com/xr.php?e=KXQgE88zYzlG5nLRCjBUCH49fmQ3U2V1SGNFUGxlQ0prZWVkcXRWT1dvcFQ2c1UrVXhOSElKN0M1TFN6a1FubFFRZkxucmRHRmpZdmxnZ21yV3VPZXlpZG1PNzR1Y0RlL3B6Vnh4WUxYd3MxczhycmFZNTBKS01iR1ZSakNmQVpqU1BBVWJVa2VKaFRsZTg0TlN1bHl4czZiVStDOGswWmYvbnptWWFoTzRkS25jK24rblhqN0RTTk5ZVnQ3aDB5WWxjdXR3OHNDRjg3ajRURk1rYVRqOVJUbUxFVzZDd0V0N3duelc5a0RYV2c5azdpWlVHNFJQYWJpcFIrSmhhVXpmK21oU3IyMStKczNNM0RVcEU2SjFvcE5DVmxSV3hzK1BUL042dkVQY2xMaVZLeWJRcUNMdVd2N3BYQ2xsL09uS2xjWUZtb0NNSU9GeFZTSkNRZWdoMEhOSXdEUEFXanhlMmJVN0JpcU1sWXlCSmxqWW1NZVN6R2djUmVtRStWNGw3RGRmZHF4ejhNRldkNnBVeXMrZUMxWWhQUXM4bTZaSG8vRmlPN29vNVBha0IvS1FYRlZjZHlRZzA4b3JIQW04L1ZieVhyTGt4WTVaOTZlRkNKUE5ldFcwa3dRV2Znc0tyK2Vtc2tWdkdQYzRneFVRM2ZTWEYxVUN4anUyK3FUNkJmbUFTTkl5d3BqalRYL2tQYXFJREI0Y3ZPdlRvdTBiQ3NhbWJVUGtybHk3YjlvWUVlb3JydmtMUnhmVWRRY0FNMEJzeXlYaWNhc281ZCtQeXRZcVl2cEhVYlEzR244cTBwanNlckkrOFlsVUZPdUVrNXZmckQzVm5LbXY0NElvOHVoNFRRSS9aSldIbCtJOWVxYm9rL0kwMitCZkNpdXo1ZWIyN3FocjdRNGJzUVZncERYNkxMTXpWL3d3OERCNWdjWkdYS1RUMFg3WUtDR2c2UFByR0FYcGtTTFp1Nzlvc1RsNlZ2OXhXVERwZ3R5Sm8rV0Z4bnc1YzBuME93MitnWEFEV09mQ2JWOXViYXVoRWU5ZEVXcUZJY2ptRHRmcm9oYzEyQnV4TGJENVBXZnZCN2UraFcrWG5yZ09vUjluaUkvZzZLMStSL0Z2MU0wZmVYaFpIS0J3c01aOFlvcUNXZTMyKzJWaEc5WngwWUxSbzR6eWhMRGlGMkVqaDRSTkMvcXBqUEdLcFZnelU2dE1pSTZRNjdieFh4Unhkd3daZ3FlNFdHc2NCSnJaWlpobGdpdFJXa0lxUjIxOXpFci9LcUM4ZG8vZVZlcmR4dUswbQ%3D%3D | unknown | — | — | unknown |
2848 | msedge.exe | GET | — | 103.224.182.206:80 | http://cuyuzu.com/favicon.ico | unknown | — | — | unknown |
2848 | msedge.exe | GET | 302 | 103.224.182.206:80 | http://cuyuzu.com/r.php?u=https%3A%2F%2Frdsclick.com%2Fclick%3Fkey%3D7619439e413209bc813c%26c%3D0.042%26t1%3D758295385%26t2%3D4%26t3%3D0.042%26t4%3D1%26t5%3D1%26t6%3Ds&s=j&enc=%2FrhsUbSnoannay%2F4I%2Fz1pn49fjF6OXQyMWY0Wkx5cGRYMWI0dUpEVjNSckJOTDFFMTgzMzFYNitpcWFmck5OdlZtYkVTN2hXb3NrbExUN2x5YlRnN2dVSDNVdkNxRHJFc0FOaEVSOHJlb1BnWEQydVZzaS9SVSsyVktmcUppK0g1NHova09lTGpsZ01EKzcvWFBaWklQQmJIOU5iOUYrWHlFM0JBWDQzSUNxUGJKMXBKNnVONlBpQUdqTTBTYmtYc0ZQeWg3alpjdlBoTkFiUkdYR2RwdFBqcjJWSlEzUHJESTVxSE94VnMzbVVZTnlnbDBkQXNlK3VpNGp2ZStiUFZIeU5DY25WMkVrWFhKR3RBK1RYbjN2dlhPVWgvUjB5d3FlSG5FN1ljaDI3aHZCc2t6WlJrR3VuWE10Ti9BVkJLeWtRMjZ3czZwN3FBVDRIS2h2dU9yWFN4MkM1a0M3TnhNQXVXNi9aVXZaL3hDRG9aVnlkY3RLZVdtWUVwZzYyRm1mQ1M4Njl1U0ZhcjRjVSsySlpjWEJFcXVQWWZjanIrSWdMaWxUVkluUklEM0x1ZGNmV1daclBRa1lCNzFXQmthMThKYW1UY0ZpRUh6QTA2eWEraWwxNU9TWWgvaUJZM1VDRGQvcG8wWC9say82bVI5SktJZGdJbWYxaEJ3VmZnVmY2NW90YXQ0YmhPbjBLYlpkWTBsYUM0Y1JJYzZ4LzRSMU5HKzAvSHQ2dSs5cmplYkh2REhjU0N2cEV2TlBQWk5peGdhZjVqWFBrUGxJdjN1MmlNbUxyd3dIZDBOQUJ1RVU0MXFUWDRiUDV5aFB2ZFpjVUZUNDQ3SDhhbFd4NnhrRk5BeTArRldBT3hBNEs5eit0UmJjSVN5NW4zWUJYQk8zbmVpcXliNTQ5eG84R0lPdWlHd1pRbTl0TG1BWmNTb2wrNUF5VktkMEdVYjlabWZ6ZFp4anZHdkMzR2xlWklTYUQvaGY5cEtjenRnVC9wejVncGlGaU9DSjNEcUpzNXdaTmVENG5Fa1FuOEdwa2tnUTBDdkFUVDlFVFJONVJ2czlYclV4bHA5eGpHREh0bVB5U2JHQy8vazhsUWpxdDA2bWRZZTZxb1VzTEd4bjFrWXZCVHZLcndsR0hNS0swdXdDRUg3VS9rWFlkanRDZUlsYU5QcTMrOWVUQzh5czJuakhNeWVFVjAzMWNhOFRWOXg3QnlGSkE0NUVXdEhyYUZyUlFBRm5qRFNJRjhlV2hiVWhWN0xiVEwwMktmQTFRbGl5K0U0cGVNS3VveFMwcXlvOEFkeXl6WDFlMXhIUWlxUXJ0VjYyV1ZJNCtRWmVCc1hPZlN3UWZuQ054eEZvM0x0am9qZlBLOXdNNEFoa3RZdEhBdGowVDBER0ZpbDd4Vitzc0pNdCtRPT0%3D&vs=1272:602&ds=1280:720&sl=0:0&os=f&nos=f&if=f&sc=f&gpu=Google%20Inc.%20(Google)%20-%20ANGLE%20(Google,%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE)),%20SwiftShader%20driver)&fp=-1 | unknown | — | — | unknown |
3944 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 2.18.121.147:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4864 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
4864 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
984 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1268 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2848 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2848 | msedge.exe | 150.171.28.11:80 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2848 | msedge.exe | 150.171.28.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2848 | msedge.exe | 2.16.241.224:443 | copilot.microsoft.com | Akamai International B.V. | DE | whitelisted |
2848 | msedge.exe | 103.224.182.239:443 | edgedl.me | Trellian Pty. Limited | AU | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edgedl.me |
| unknown |
copilot.microsoft.com |
| whitelisted |
cuyuzu.com |
| unknown |
client.wns.windows.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2848 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Suspected Phishing Domain (securecarthub .com) |
2848 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Suspected Phishing Domain (securecarthub .com) |