URL:

https://github.com/Babyhamsta/Aimmy/releases/download/v2.4.1/AimmyV2.4.1.zip

Full analysis: https://app.any.run/tasks/dab832eb-6080-45b3-ac90-9be958595a01
Verdict: Malicious activity
Analysis date: December 26, 2025, 21:36:14
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
arch-exec
auto
generic
Indicators:
MD5:

E955B5CDF95A173F64BDCE8206EBA27E

SHA1:

256A6F2AD80994C851D8C9EF723D196FDA0E6D9B

SHA256:

3454593E61F281DCE2BC1D6D5B1951C2E8CAC73149BBC50A7C4742B3DABDEA3B

SSDEEP:

3:N8tEdU8N7hKcMkCFTkMWpwU:2uyc75MLR4L

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
    • GENERIC has been found (auto)

      • msiexec.exe (PID: 5520)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 8444)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 7520)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 8976)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
      • msiexec.exe (PID: 5520)
    • Reads security settings of Internet Explorer

      • CouldBeAimmyV2.exe (PID: 2144)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 8976)
      • CouldBeAimmyV2.exe (PID: 8480)
    • Starts a Microsoft application from unusual location

      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 8976)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
    • Executable content was dropped or overwritten

      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 7520)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 8976)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
    • Searches for installed software

      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 8976)
    • Starts itself from another location

      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 8976)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 5520)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 5520)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 5520)
    • Executes application which crashes

      • CouldBeAimmyV2.exe (PID: 8480)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 7440)
      • CouldBeAimmyV2.exe (PID: 2144)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 7520)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 8976)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
      • msiexec.exe (PID: 7492)
      • msiexec.exe (PID: 5520)
      • msiexec.exe (PID: 7556)
      • msiexec.exe (PID: 8128)
      • msiexec.exe (PID: 8504)
      • CouldBeAimmyV2.exe (PID: 8480)
    • Reads Environment values

      • identity_helper.exe (PID: 7440)
    • Application launched itself

      • msedge.exe (PID: 7612)
      • msedge.exe (PID: 1868)
    • Reads the computer name

      • identity_helper.exe (PID: 7440)
      • CouldBeAimmyV2.exe (PID: 2144)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 8976)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
      • msiexec.exe (PID: 7492)
      • msiexec.exe (PID: 5520)
      • msiexec.exe (PID: 8504)
      • msiexec.exe (PID: 7556)
      • msiexec.exe (PID: 8128)
      • CouldBeAimmyV2.exe (PID: 8480)
    • Manual execution by a user

      • WinRAR.exe (PID: 8444)
      • CouldBeAimmyV2.exe (PID: 2144)
      • CouldBeAimmyV2.exe (PID: 8480)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 8444)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 7520)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 8976)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
      • msiexec.exe (PID: 5520)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 8444)
      • msedge.exe (PID: 7612)
      • msiexec.exe (PID: 5520)
    • Create files in a temporary directory

      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 7520)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 8976)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
    • Process checks computer location settings

      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 8976)
    • Launching a file from a Registry key

      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
    • Creates files in the program directory

      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
      • CouldBeAimmyV2.exe (PID: 8480)
    • Creates a software uninstall entry

      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
      • msiexec.exe (PID: 5520)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 5520)
      • windowsdesktop-runtime-8.0.22-win-x64.exe (PID: 5104)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 1092)
      • WerFault.exe (PID: 8388)
      • WerFault.exe (PID: 1524)
      • WerFault.exe (PID: 9104)
      • WerFault.exe (PID: 5448)
    • Checks proxy server information

      • CouldBeAimmyV2.exe (PID: 8480)
      • slui.exe (PID: 8368)
      • WerFault.exe (PID: 9104)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
205
Monitored processes
48
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe couldbeaimmyv2.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs windowsdesktop-runtime-8.0.22-win-x64.exe msedge.exe no specs windowsdesktop-runtime-8.0.22-win-x64.exe windowsdesktop-runtime-8.0.22-win-x64.exe #GENERIC msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs couldbeaimmyv2.exe werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
1068"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --edge-skip-compat-layer-relaunch --single-argument https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.16&gui=trueC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1092C:\WINDOWS\system32\WerFault.exe -u -p 8480 -s 3144C:\Windows\System32\WerFault.exeCouldBeAimmyV2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
1156"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=22 --always-read-main-dll --field-trial-handle=6792,i,6691921236443907774,14058194427317066353,262144 --variations-seed-version --mojo-platform-channel-handle=6268 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1524C:\WINDOWS\system32\WerFault.exe -u -p 8480 -s 3236C:\Windows\System32\WerFault.exeCouldBeAimmyV2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
1868"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.16&gui=trueC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeCouldBeAimmyV2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2144"C:\Users\admin\Downloads\AimmyV2.4.1\CouldBeAimmyV2.exe" C:\Users\admin\Downloads\AimmyV2.4.1\CouldBeAimmyV2.exe
explorer.exe
User:
admin
Company:
CouldBeAimmyV2
Integrity Level:
MEDIUM
Description:
CouldBeAimmyV2
Exit code:
2147516547
Version:
1.0.0.0
Modules
Images
c:\users\admin\downloads\aimmyv2.4.1\couldbeaimmyv2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2308"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=20 --always-read-main-dll --field-trial-handle=3112,i,6691921236443907774,14058194427317066353,262144 --variations-seed-version --mojo-platform-channel-handle=5508 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2356"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=8100,i,6691921236443907774,14058194427317066353,262144 --variations-seed-version --mojo-platform-channel-handle=7880 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2416"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6456,i,6691921236443907774,14058194427317066353,262144 --variations-seed-version --mojo-platform-channel-handle=6512 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
4404"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3616,i,6691921236443907774,14058194427317066353,262144 --variations-seed-version --mojo-platform-channel-handle=3748 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
25 526
Read events
24 601
Write events
881
Delete events
44

Modification events

(PID) Process:(8444) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(8444) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(8444) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(8444) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2144) CouldBeAimmyV2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(2144) CouldBeAimmyV2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2144) CouldBeAimmyV2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2144) CouldBeAimmyV2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5104) windowsdesktop-runtime-8.0.22-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{a3899eef-6164-4d42-b8c3-95ae6a844821}
Operation:writeName:BundleCachePath
Value:
C:\ProgramData\Package Cache\{a3899eef-6164-4d42-b8c3-95ae6a844821}\windowsdesktop-runtime-8.0.22-win-x64.exe
(PID) Process:(5104) windowsdesktop-runtime-8.0.22-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{a3899eef-6164-4d42-b8c3-95ae6a844821}
Operation:writeName:BundleUpgradeCode
Value:
{7F5F299F-5EB1-6FC0-6D86-FB7931E33C68}
Executable files
499
Suspicious files
166
Text files
340
Unknown types
3

Dropped files

PID
Process
Filename
Type
7612msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RFfdfe7.TMP
MD5:
SHA256:
7612msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7612msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFfdfe7.TMP
MD5:
SHA256:
7612msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7612msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFfdff7.TMP
MD5:
SHA256:
7612msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
7612msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RFfdff7.TMP
MD5:
SHA256:
7612msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFfdff7.TMP
MD5:
SHA256:
7612msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
7612msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
49
TCP/UDP connections
99
DNS requests
96
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7940
msedge.exe
GET
200
185.199.109.133:443
https://release-assets.githubusercontent.com/github-production-release-asset/702911793/d7a1790d-c691-4ba5-9d17-f3b5e92b003b?sp=r&sv=2018-11-09&sr=b&spr=https&se=2025-12-26T22%3A26%3A07Z&rscd=attachment%3B+filename%3DAimmyV2.4.1.zip&rsct=application%2Foctet-stream&skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0&sktid=398a6654-997b-47e9-b12b-9515b896b4de&skt=2025-12-26T21%3A26%3A00Z&ske=2025-12-26T22%3A26%3A07Z&sks=b&skv=2018-11-09&sig=7qlnl1brRyMk1QUK7feUfBwb3yAJlzxSyow4j14EneQ%3D&jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmVsZWFzZS1hc3NldHMuZ2l0aHVidXNlcmNvbnRlbnQuY29tIiwia2V5Ijoia2V5MSIsImV4cCI6MTc2Njc4NjY2MywibmJmIjoxNzY2Nzg0ODYzLCJwYXRoIjoicmVsZWFzZWFzc2V0cHJvZHVjdGlvbi5ibG9iLmNvcmUud2luZG93cy5uZXQifQ.cNC_py46HG_sULL9WMvBRiFQ-YHAE5O0m4BpyU2gW-s&response-content-disposition=attachment%3B%20filename%3DAimmyV2.4.1.zip&response-content-type=application%2Foctet-stream
unknown
whitelisted
7940
msedge.exe
GET
302
140.82.121.4:443
https://github.com/Babyhamsta/Aimmy/releases/download/v2.4.1/AimmyV2.4.1.zip
unknown
unknown
7940
msedge.exe
GET
304
150.171.28.11:443
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
unknown
whitelisted
7940
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=EdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=65&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1741678270&lafgdate=0
unknown
text
768 b
whitelisted
7940
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
unknown
text
311 b
whitelisted
7940
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:qwfbC5JPi-ay_4f_rHRtfCrWKVCRVcMcfS54yJluC-8&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
7940
msedge.exe
GET
200
104.18.23.222:443
https://copilot.microsoft.com/c/api/user/eligibility
unknown
text
25 b
whitelisted
7940
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-US&acceptformat=crx3,puff&x=id%3Djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3D1.2.1%26installedby%3Dother%26uc%26ping%3Dr%253D526%2526e%253D1
unknown
xml
413 b
whitelisted
7940
msedge.exe
GET
200
184.86.251.27:443
https://www.bing.com/api/shopping/v1/user/shoppingsettings?EnabledServiceFeaturesv2=edgeServerUX.shopping.msEdgeShoppingCashbackDismissTimeout2s
unknown
text
1.02 Kb
whitelisted
7940
msedge.exe
POST
200
142.250.185.227:443
https://update.googleapis.com/service/update2/json?cup2key=14:jEEKg2CDlAXO0EETQ1o9mNpmtaKoFwIpLyYhu8F2Mk0&cup2hreq=096b299c382200035e5bee558e181af8a1f82c297a08cab82278782f24d9fe2f
unknown
text
889 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6768
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
2680
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5768
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7940
msedge.exe
150.171.27.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7940
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7940
msedge.exe
140.82.121.4:443
github.com
GITHUB
US
whitelisted
7940
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7940
msedge.exe
104.18.23.222:443
copilot.microsoft.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.110
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
github.com
  • 140.82.121.4
whitelisted
copilot.microsoft.com
  • 104.18.23.222
  • 104.18.22.222
whitelisted
release-assets.githubusercontent.com
  • 185.199.109.133
  • 185.199.108.133
  • 185.199.110.133
  • 185.199.111.133
whitelisted
update.googleapis.com
  • 142.250.185.227
whitelisted
www.bing.com
  • 184.86.251.27
  • 184.86.251.19
  • 184.86.251.4
  • 184.86.251.31
  • 184.86.251.5
  • 184.86.251.23
  • 184.86.251.16
  • 184.86.251.25
  • 184.86.251.8
whitelisted
clients2.googleusercontent.com
  • 172.217.18.1
whitelisted

Threats

PID
Process
Class
Message
7940
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access release user assets on GitHub
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Process
Message
CouldBeAimmyV2.exe
You must install .NET to run this application. App: C:\Users\admin\Downloads\AimmyV2.4.1\CouldBeAimmyV2.exe Architecture: x64 App host version: 8.0.16 .NET location: Not found Learn more: https://aka.ms/dotnet/app-launch-failed Download the .NET runtime: https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.16