File name:

MALWAREBYTES 2 REAL.7z

Full analysis: https://app.any.run/tasks/734d1ba2-1407-4007-b093-64448593f6de
Verdict: Malicious activity
Analysis date: May 10, 2025, 11:08:24
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

C863BDBE35966D070FEFE57EFA4A4432

SHA1:

3E72B91365815F966B25B1E759EA3F86127DAD84

SHA256:

40D6C9477FDEE105BBC2046D8160FDD8819F19876EE1A2C12A02CB683E001490

SSDEEP:

98304:YJrgQcnep6GIA0SbM8sU+PFeZdg3INfcsW26ESdRr+gnmfhVDkI+yAEdquBz8n77:KPnUvzkO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7420)
    • Starts NET.EXE to view/add/change user profiles

      • MALWAREBYTES 2.exe (PID: 8112)
      • net.exe (PID: 8180)
      • net.exe (PID: 6620)
      • net.exe (PID: 4608)
      • net.exe (PID: 7052)
      • net.exe (PID: 7324)
      • net.exe (PID: 7740)
      • net.exe (PID: 496)
      • net.exe (PID: 7640)
      • net.exe (PID: 5436)
      • net.exe (PID: 7204)
      • cmd.exe (PID: 8588)
      • cmd.exe (PID: 14928)
      • net.exe (PID: 13704)
      • net.exe (PID: 8648)
    • Starts NET.EXE to view/change users localgroup

      • net.exe (PID: 7252)
      • net.exe (PID: 1272)
      • MALWAREBYTES 2.exe (PID: 8112)
      • net.exe (PID: 2600)
      • net.exe (PID: 6244)
      • net.exe (PID: 6036)
      • net.exe (PID: 6268)
      • net.exe (PID: 632)
      • net.exe (PID: 8100)
      • net.exe (PID: 7256)
      • net.exe (PID: 7848)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • MALWAREBYTES 2.exe (PID: 8112)
    • Reads security settings of Internet Explorer

      • MALWAREBYTES 2.exe (PID: 8112)
    • SQL CE related mutex has been found

      • MALWAREBYTES 2.exe (PID: 8112)
    • There is functionality for taking screenshot (YARA)

      • MALWAREBYTES 2.exe (PID: 8112)
    • Starts CMD.EXE for commands execution

      • MALWAREBYTES 2.exe (PID: 8112)
    • Start notepad (likely ransomware note)

      • MALWAREBYTES 2.exe (PID: 8112)
    • Starts POWERSHELL.EXE for commands execution

      • MALWAREBYTES 2.exe (PID: 8112)
    • The process executes via Task Scheduler

      • explorer.exe (PID: 12752)
    • The system shut down or reboot

      • MALWAREBYTES 2.exe (PID: 8112)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 12224)
  • INFO

    • Manual execution by a user

      • MALWAREBYTES 2.exe (PID: 8112)
      • MALWAREBYTES 2.exe (PID: 8064)
      • msedge.exe (PID: 1912)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7420)
    • Checks supported languages

      • MALWAREBYTES 2.exe (PID: 8112)
      • identity_helper.exe (PID: 7764)
    • Reads the computer name

      • MALWAREBYTES 2.exe (PID: 8112)
      • identity_helper.exe (PID: 7764)
    • Reads the machine GUID from the registry

      • MALWAREBYTES 2.exe (PID: 8112)
    • Process checks computer location settings

      • MALWAREBYTES 2.exe (PID: 8112)
    • Creates files or folders in the user directory

      • MALWAREBYTES 2.exe (PID: 8112)
    • Creates files in the program directory

      • MALWAREBYTES 2.exe (PID: 8112)
    • Checks proxy server information

      • MALWAREBYTES 2.exe (PID: 8112)
    • Application launched itself

      • msedge.exe (PID: 7760)
      • msedge.exe (PID: 1912)
    • Reads Environment values

      • identity_helper.exe (PID: 7764)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2025:05:04 18:19:39+00:00
ArchivedFileName: Release
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
527
Monitored processes
382
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
208C:\WINDOWS\system32\net1 user KORNA8 korna /addC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
232"C:\Windows\System32\cmd.exe" C:\Windows\System32\cmd.exeMALWAREBYTES 2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winbrand.dll
236\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
444"C:\Program Files\Internet Explorer\iexplore.exe" C:\Program Files\Internet Explorer\iexplore.exeMALWAREBYTES 2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
11.00.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
496"C:\Windows\System32\net.exe" user KORNA10 korna /addC:\Windows\System32\net.exeMALWAREBYTES 2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
552"C:\Windows\System32\Taskmgr.exe" C:\Windows\System32\Taskmgr.exeMALWAREBYTES 2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
632"C:\Windows\System32\net.exe" localgroup Administrators KORNA7 /addC:\Windows\System32\net.exeMALWAREBYTES 2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
632"C:\Windows\explorer.exe" C:\Windows\explorer.exeMALWAREBYTES 2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
668"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5172 --field-trial-handle=2424,i,13638713902643717457,16246164568272538562,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
824"C:\Windows\System32\mspaint.exe" C:\Windows\System32\mspaint.exeMALWAREBYTES 2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Paint
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mspaint.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
176 088
Read events
175 115
Write events
945
Delete events
28

Modification events

(PID) Process:(7420) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7420) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7420) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7420) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MALWAREBYTES 2 REAL.7z
(PID) Process:(7420) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7420) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7420) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7420) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7420) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(7420) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
37
Suspicious files
1 245
Text files
308
Unknown types
0

Dropped files

PID
Process
Filename
Type
7420WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7420.12402\Release\MALWAREBYTES 2.exeexecutable
MD5:0A78C904D76454238F3D10A48E0C580C
SHA256:73EA77F1DB265AD86674661E2F051EEC60FF5D99E7BE4DFD436EDE8F3EDA9668
7420WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7420.12402\Release\mp3\korna3.mp3binary
MD5:0DDD1628023C599C15CB36D9C67BA261
SHA256:86C33B8E0B811D2E8DDC989A2611F86FB4EBB2930CF0B7C4F6AC2946778DC425
8112MALWAREBYTES 2.exeC:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XMLtext
MD5:5433EAB10C6B5C6D55B7CBD302426A39
SHA256:23DBF7014E99E93AF5F2760F18EE1370274F06A453145C8D539B66D798DAD131
1912msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF111049.TMP
MD5:
SHA256:
1912msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF111049.TMP
MD5:
SHA256:
1912msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF111049.TMP
MD5:
SHA256:
1912msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
1912msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
1912msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF111049.TMP
MD5:
SHA256:
1912msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
23
TCP/UDP connections
293
DNS requests
243
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
4692
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
4692
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
9404
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1747344196&P2=404&P3=2&P4=hI1kVlNNWLnjVwHP1pjKoWWvtq2tkR6cezOA8c2cC7s%2b%2fAQT%2biHH5gNlxtOluWm0LUcMTN5E9YydDGUCV%2bM4EA%3d%3d
US
whitelisted
9404
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1747344196&P2=404&P3=2&P4=hI1kVlNNWLnjVwHP1pjKoWWvtq2tkR6cezOA8c2cC7s%2b%2fAQT%2biHH5gNlxtOluWm0LUcMTN5E9YydDGUCV%2bM4EA%3d%3d
US
binary
1.16 Kb
whitelisted
9404
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1747344196&P2=404&P3=2&P4=hI1kVlNNWLnjVwHP1pjKoWWvtq2tkR6cezOA8c2cC7s%2b%2fAQT%2biHH5gNlxtOluWm0LUcMTN5E9YydDGUCV%2bM4EA%3d%3d
US
binary
272 b
whitelisted
9404
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1747344196&P2=404&P3=2&P4=hI1kVlNNWLnjVwHP1pjKoWWvtq2tkR6cezOA8c2cC7s%2b%2fAQT%2biHH5gNlxtOluWm0LUcMTN5E9YydDGUCV%2bM4EA%3d%3d
US
binary
7.73 Kb
whitelisted
9404
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1747344196&P2=404&P3=2&P4=hI1kVlNNWLnjVwHP1pjKoWWvtq2tkR6cezOA8c2cC7s%2b%2fAQT%2biHH5gNlxtOluWm0LUcMTN5E9YydDGUCV%2bM4EA%3d%3d
US
compressed
12.0 Kb
whitelisted
9404
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/cd4e6fbf-c0e9-4dc2-9e3d-7f538bc7435a?P1=1747344197&P2=404&P3=2&P4=WY2fOUc1GxXyZb7w3IIUoHLH%2fm6Fs4AmMcj1Ug6Yi0cQ8Xq5n8NLrORmYrgcIwPg2KKgKxPeaQGLoFUhPeaWsA%3d%3d
US
compressed
12.0 Kb
whitelisted
9404
svchost.exe
GET
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/cd4e6fbf-c0e9-4dc2-9e3d-7f538bc7435a?P1=1747344197&P2=404&P3=2&P4=WY2fOUc1GxXyZb7w3IIUoHLH%2fm6Fs4AmMcj1Ug6Yi0cQ8Xq5n8NLrORmYrgcIwPg2KKgKxPeaQGLoFUhPeaWsA%3d%3d
US
binary
7.68 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1912
msedge.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.48.23.178
  • 23.48.23.192
  • 23.48.23.190
  • 23.48.23.180
  • 23.48.23.177
  • 23.48.23.185
  • 23.48.23.188
  • 23.48.23.181
  • 23.48.23.193
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.64
  • 20.190.160.65
  • 20.190.160.66
  • 20.190.160.131
  • 20.190.160.22
  • 40.126.32.133
  • 40.126.32.140
  • 40.126.32.136
  • 20.190.160.3
  • 20.190.160.67
  • 20.190.160.20
  • 20.190.160.17
  • 20.190.160.2
  • 40.126.32.76
  • 40.126.32.72
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.253.45
whitelisted

Threats

No threats detected
No debug info