URL:

mynextdns.io

Full analysis: https://app.any.run/tasks/31dcfb5c-2685-4f97-a659-8a9e0437e329
Verdict: Malicious activity
Analysis date: June 18, 2025, 22:55:20
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
obfuscated-js
possible-phishing
arch-scr
Indicators:
MD5:

6E58A90A81B9A52165226096C558BD81

SHA1:

A589182C8283C17EF4E39163AA5FB372E2C1DCBE

SHA256:

35217CE987E41F7E1DC6FDE9A47AC605B6367F00FC89981BFBC543726D5C6C19

SSDEEP:

3:h5Ln:DLn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Possible Social Engineering Attempted

      • msedge.exe (PID: 5708)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 2044)
      • firefox.exe (PID: 5716)
      • msedge.exe (PID: 7324)
      • firefox.exe (PID: 2648)
    • Checks supported languages

      • identity_helper.exe (PID: 4864)
      • identity_helper.exe (PID: 1208)
      • identity_helper.exe (PID: 3388)
      • identity_helper.exe (PID: 7780)
    • Reads Environment values

      • identity_helper.exe (PID: 4864)
      • identity_helper.exe (PID: 1208)
      • identity_helper.exe (PID: 3388)
      • identity_helper.exe (PID: 7780)
    • Reads the computer name

      • identity_helper.exe (PID: 4864)
      • identity_helper.exe (PID: 1208)
      • identity_helper.exe (PID: 3388)
      • identity_helper.exe (PID: 7780)
    • Checks proxy server information

      • slui.exe (PID: 7060)
    • Reads the software policy settings

      • slui.exe (PID: 7060)
    • Manual execution by a user

      • WINWORD.EXE (PID: 7368)
      • firefox.exe (PID: 2648)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 5716)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
245
Monitored processes
102
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs winword.exe ai.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs svchost.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
320"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=27 --always-read-main-dll --field-trial-handle=6572,i,8251350364006948671,3644607698828369273,262144 --variations-seed-version --mojo-platform-channel-handle=7060 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
760"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4040,i,8251350364006948671,3644607698828369273,262144 --variations-seed-version --mojo-platform-channel-handle=5560 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1208"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5548,i,8251350364006948671,3644607698828369273,262144 --variations-seed-version --mojo-platform-channel-handle=7824 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\bcrypt.dll
1332"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3104 -prefsLen 36996 -prefMapHandle 3188 -prefMapSize 272997 -jsInitHandle 3192 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3200 -initialChannelId {59a9b649-564c-4d74-a00d-877e44ea0af0} -parentPid 5716 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5716" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
1488"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5128 -prefsLen 39068 -prefMapHandle 5112 -prefMapSize 272997 -jsInitHandle 5156 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5176 -initialChannelId {d4a32546-b88b-44b6-8863-d472505c1d47} -parentPid 5716 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5716" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 8 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1512"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6132 -prefsLen 39388 -prefMapHandle 6136 -prefMapSize 272997 -jsInitHandle 6140 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 2600 -initialChannelId {b399f17d-ef69-40f1-a0bd-542e564b5718} -parentPid 5716 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5716" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 11 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
1560"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=40 --always-read-main-dll --field-trial-handle=7984,i,8251350364006948671,3644607698828369273,262144 --variations-seed-version --mojo-platform-channel-handle=6988 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1816"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 1988 -prefsLen 36520 -prefMapHandle 1992 -prefMapSize 272997 -ipcHandle 1956 -initialChannelId {2e65afa9-1fa5-4d87-9660-cd7702cee9ab} -parentPid 5716 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5716" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
1984"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5268 -prefsLen 39388 -prefMapHandle 5140 -prefMapSize 272997 -jsInitHandle 2300 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 6108 -initialChannelId {140ff834-cfd2-4713-aeb7-631d8e777b8a} -parentPid 5716 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5716" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 14 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
2044"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "mynextdns.io"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
40 368
Read events
40 026
Write events
318
Delete events
24

Modification events

(PID) Process:(2044) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2044) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2044) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2044) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(2044) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
03F430CF76962F00
(PID) Process:(2044) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\263014
Operation:writeName:WindowTabManagerFileMappingId
Value:
{A1775E9C-287B-42DB-B86E-50B2FCCB7E10}
(PID) Process:(2044) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\263014
Operation:writeName:WindowTabManagerFileMappingId
Value:
{8B90D49D-155E-486F-A7B6-50B5CB6559DB}
(PID) Process:(2044) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\263014
Operation:writeName:WindowTabManagerFileMappingId
Value:
{A2C51240-650F-43D4-A762-90FC9A0B1B94}
(PID) Process:(2044) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\263014
Operation:writeName:WindowTabManagerFileMappingId
Value:
{84334A57-17BF-4BE5-91EC-CCB8BDECE08A}
(PID) Process:(2044) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\263014
Operation:writeName:WindowTabManagerFileMappingId
Value:
{79E5FE3D-98CB-40F5-ABD6-C9FB9C500A5C}
Executable files
22
Suspicious files
655
Text files
125
Unknown types
4

Dropped files

PID
Process
Filename
Type
2044msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF17754f.TMP
MD5:
SHA256:
2044msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
2044msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF17754f.TMP
MD5:
SHA256:
2044msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF17754f.TMP
MD5:
SHA256:
2044msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF17754f.TMP
MD5:
SHA256:
2044msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
2044msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
2044msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF17754f.TMP
MD5:
SHA256:
2044msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
2044msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF17755f.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
98
TCP/UDP connections
318
DNS requests
502
Threats
22

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5708
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:O4poNLJAYUjlVyWKiGs4Gj0B3UgUvhob1G6S9C6rsGA&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1268
svchost.exe
GET
200
2.18.121.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5708
msedge.exe
GET
103.224.182.206:80
http://dizoab.com/favicon.ico
unknown
unknown
5708
msedge.exe
GET
200
103.224.182.206:80
http://dizoab.com/js/fingerprint/iife.min.js
unknown
unknown
5708
msedge.exe
GET
200
103.224.182.206:80
http://dizoab.com/f.php?e=jjYTmxrbOVcS1sFB8Lq6FH49fmhzd1NPUGpEUEJBME94OVJDcVMzakdkS2d1anZCc1Z6cHIrRXBieWJMUm5SQi9MUm5KTG12WUNCR1ljam84L3NmK25NcDBERVYwdmQ3U3RPTE0xZ2ZUbjRVQWx2bmFBWFMyNjhiRDdxMXlKWXA1WWZWZ0NhSlJOYVlDZlA2N28vMEpkRUNYV3F5VVdnSlVsemFpcndzQTROYU51RXRKc1B0cXVkZG1hS2FLOWpCNkNhZUdWRXFaZ1M3QUJWN2xUKzE1YWNnQmwxL0Z2R2s0Rkg0VXR5VHRzeE5RWXdSeUJlblhqTEg0VFEzNytORWkvblB6RmZYb2lkeE9EeTRCL3RJVmJ6YmZYVmhUWG1mQ2VxYjhyQWgrVG8rUytmMzh1UWF6ZE00UkIxVThCNUg2SHJSZ05lN3dmbS8xcStMdGthUDhnbDdIREprL3FIQXI2ZmtNdWovbVBnL1NNYTFYZHZRTFNkVWNaNEJmeTJCWjdOMjdhVGF1Q0tiQkxmY09sUXhnMkJydjArQm10RmdSTnI3b0VMVG9XSm5qcUY5TEx6UDZSM0JHUVpBMW51WGtFTmV6TEhEdll4Yjdtd0x4bDhFUVFybnhKWGZSR0RnUDdJOHM5R0w1R2g5MWx0QTRzNkxic1JyaFdXZE9TbnkzMjhJZ0E5S3ArdDdGZi94VVdx&fp=a11a9bd7a5599a4ff01d89847c22c389
unknown
unknown
5708
msedge.exe
GET
302
103.224.182.206:80
http://dizoab.com/f2.php?e=MtN6emNr%2Bh%2FLUDJ%2FtVN8xH49fmRXVVdHcFFxYkRGYTFMRUVHcituc3ZTRFBuMzFXbXk1NU9LUzVnL1Rkc3VnTzlzeWE5U3lkZDNON29aTUc2MXdCT3VxS2Z1TFQ3OG5LaWV0NWNLeGdYR2g3bWFCT29NOEtoT2hvcDFOWTZVZHRzN2xQMFFNRDZjcDFiOE00Q0tnS1RZdVdFL1Y5UjIydm05QTZQS3dnM1lRTmgvNHh5Tm1qd04zeTBtY2ltQlVaa3JyUEdrL2oxMXZxM2luRGY2NWpIbDh5QWEzLzFlMlR5bkl3MERZa1g3ZFpvR25DS3lIZDNPaHZpUmR4NWdQZ2N1aVgvcFk1Y1dSL3JmMHl3WjNxRXFZSXpuREN5MVJMNUsyeEw0Y01ZdVA5TWp3YTVOdHh0Nm1ZK3V3dTJ2ZEtQcU9yZlhRZ0d3c3ZWV25tTUI5RzBFeEtDeHZ4a0I0eVMrc25yUUxXdHRFVjIrcVVwNVZHMEVwMnpvUmdBVC9sd1ZQS1g1LzI2Y0dZaWRXVjJXZW5oSm85c0trT04wODNuRGxyeE9tdTlEcWk3TUczeHByaTZIaXJzWXRqYVZxVEIwemlXWVFlTG5mSk9DVHdiWjR5RzdScmdWUlZoV2JaZDZLTklFZDVMRGcvU0VGWkNSR29zc0U0UW44d3pnSVFFMnNXNFVZaW9Vck9XQXA5L2pvKzA5cUwwck1ObCtVRTZvRkwxam5aeWxJYXBSR3JvZW1ITkRwSXdueTI2bz0%3D&vs=1272:602&ds=1280:720&sl=0:0&os=f&nos=f
unknown
unknown
7516
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7516
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2764
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6828
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5708
msedge.exe
162.210.199.85:80
mynextdns.io
LEASEWEB-USA-WDC
US
unknown
5708
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5708
msedge.exe
150.171.28.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5708
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5708
msedge.exe
162.210.199.85:443
mynextdns.io
LEASEWEB-USA-WDC
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.46
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
mynextdns.io
  • 162.210.199.85
  • 37.48.65.154
unknown
copilot.microsoft.com
  • 2.16.241.224
  • 2.16.241.220
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
  • 2.16.241.218
  • 2.16.241.201
whitelisted
crl.microsoft.com
  • 2.18.121.139
  • 2.18.121.147
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.35.229.160
whitelisted
dizoab.com
  • 103.224.182.206
unknown

Threats

PID
Process
Class
Message
5708
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
5708
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
5708
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5708
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5708
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5708
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5708
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
5708
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
5708
msedge.exe
Possible Social Engineering Attempted
SUSPICIOUS [ANY.RUN] Possible Malicious CrossDomain (*adguard .co .in)
5708
msedge.exe
Possible Social Engineering Attempted
SUSPICIOUS [ANY.RUN] Possible Malicious CrossDomain (*adguard .co .in)
Process
Message
WINWORD.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
WINWORD.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
WINWORD.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.