| URL: | edge-consumer-static.azureedge.net | 
| Full analysis: | https://app.any.run/tasks/07e29242-e216-4d70-8114-1f5172e70f96 | 
| Verdict: | Malicious activity | 
| Analysis date: | January 16, 2024, 21:55:03 | 
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) | 
| Tags: | |
| Indicators: | |
| MD5: | A194EA2A42AD1455CAD9838954520ECD | 
| SHA1: | 426B2E8848073CBC2D268C4209C6F41BC92D6758 | 
| SHA256: | 40D7CFE4CE70A22A4D3D964F65668F9B9D45C036AC72E901B61F9C2E725DAD01 | 
| SSDEEP: | 3:kD7QYb1ncn:kDkYb1nc | 
PID  | CMD  | Path  | Indicators  | Parent process  | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 480 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1180 --field-trial-handle=1136,i,3474016441220328974,16667434146352012409,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 680 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=2212 --field-trial-handle=1136,i,3474016441220328974,16667434146352012409,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 1308 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd4,0x6e558b38,0x6e558b48,0x6e558b54 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 1344 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1404 --field-trial-handle=1136,i,3474016441220328974,16667434146352012409,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 1608 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1548 --field-trial-handle=1136,i,3474016441220328974,16667434146352012409,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 1776 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "edge-consumer-static.azureedge.net" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 1816 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2028 --field-trial-handle=1136,i,3474016441220328974,16667434146352012409,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 1824 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2000 --field-trial-handle=1136,i,3474016441220328974,16667434146352012409,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 2184 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
  | |||||||||||||||
| 2372 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1172 --field-trial-handle=1136,i,3474016441220328974,16667434146352012409,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| (PID) Process: | (1776) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon | 
| Operation: | write | Name: | failed_count | 
Value: 0  | |||
| (PID) Process: | (1776) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon | 
| Operation: | write | Name: | state | 
Value: 1  | |||
| (PID) Process: | (1776) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty | 
| Operation: | write | Name: | StatusCodes | 
Value: 01000000  | |||
| (PID) Process: | (1776) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon | 
| Operation: | write | Name: | state | 
Value: 2  | |||
| (PID) Process: | (1776) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} | 
| Operation: | write | Name: | dr | 
Value: 1  | |||
| (PID) Process: | (1776) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics | 
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly | 
Value: 1  | |||
| (PID) Process: | (1776) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome | 
| Operation: | write | Name: | UsageStatsInSample | 
Value: 0  | |||
| (PID) Process: | (1776) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} | 
| Operation: | write | Name: | usagestats | 
Value: 0  | |||
| (PID) Process: | (1776) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} | 
| Operation: | write | Name: | metricsid_installdate | 
Value: 0  | |||
| (PID) Process: | (1776) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} | 
| Operation: | write | Name: | metricsid_enableddate | 
Value: 0  | |||
PID  | Process  | Filename  | Type  | |
|---|---|---|---|---|
| 1776 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RFdf6d4.TMP | — | |
MD5:—  | SHA256:—  | |||
| 1776 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:—  | SHA256:—  | |||
| 1776 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old~RFdf954.TMP | text | |
MD5:B36B68CE4A71A5BFAF89A4D1CC07893F  | SHA256:6422CC04455EF100D67FD9F299AACFEF3BA4F77D0FA1D2440D89E7D1CF65EBBC  | |||
| 1776 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Variations | binary | |
MD5:961E3604F228B0D10541EBF921500C86  | SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED  | |||
| 1776 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old | text | |
MD5:AD0DB8476493577A67FA94A162B646C4  | SHA256:304FB5B4FD83D4A9FF1EF4CF20232A1783169C148297BFE37ED24A1D22A74F2B  | |||
| 1776 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old~RFdf993.TMP | text | |
MD5:0272AD43ECEA4DC6C694BE6D918B5BA7  | SHA256:530F5A3F46B293038FEBEF2035CFA622F05B202363ABFAF9E40E105BD1472432  | |||
| 1776 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RFdfed3.TMP | — | |
MD5:—  | SHA256:—  | |||
| 1776 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:—  | SHA256:—  | |||
| 1776 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old | text | |
MD5:E53573A93829681410D5E7DBB1B61C78  | SHA256:A82D28F2C1E22A2AE0ABC5F5AF0CC8EE7AD913BAB3A0BF84CE6D8D23F67E06A3  | |||
| 1776 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old~RFe0ae8.TMP | — | |
MD5:—  | SHA256:—  | |||
PID  | Process  | Method  | HTTP Code  | IP  | URL  | CN  | Type  | Size  | Reputation  | 
|---|---|---|---|---|---|---|---|---|---|
856  | svchost.exe  | GET  | —  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/bt7w5q27qqv6c2bf7astfivvii_832/efniojlnjndmcbiieegkicadnoecjjef_832_all_advssjtxajygsus4fevnypa2aiaq.crx3  | unknown  |  —   | —  | unknown  | 
856  | svchost.exe  | GET  | 206  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/bt7w5q27qqv6c2bf7astfivvii_832/efniojlnjndmcbiieegkicadnoecjjef_832_all_advssjtxajygsus4fevnypa2aiaq.crx3  | unknown  | binary  | 5.89 Kb  | unknown  | 
1344  | chrome.exe  | GET  | 404  | 13.107.246.45:80  | http://edge-consumer-static.azureedge.net/  | unknown  | html  | 1.05 Kb  | unknown  | 
856  | svchost.exe  | HEAD  | 200  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/bt7w5q27qqv6c2bf7astfivvii_832/efniojlnjndmcbiieegkicadnoecjjef_832_all_advssjtxajygsus4fevnypa2aiaq.crx3  | unknown  |  —   | —  | unknown  | 
PID  | Process  | IP  | Domain  | ASN  | CN  | Reputation  | 
|---|---|---|---|---|---|---|
4  | System  | 192.168.100.255:137  | —  | —  | —  | whitelisted  | 
1080  | svchost.exe  | 224.0.0.252:5355  | —  | —  | —  | unknown  | 
4  | System  | 192.168.100.255:138  | —  | —  | —  | whitelisted  | 
1776  | chrome.exe  | 239.255.255.250:1900  | —  | —  | —  | whitelisted  | 
1344  | chrome.exe  | 13.107.246.45:80  | edge-consumer-static.azureedge.net  | MICROSOFT-CORP-MSN-AS-BLOCK  | US  | unknown  | 
1344  | chrome.exe  | 142.250.27.84:443  | accounts.google.com  | GOOGLE  | US  | unknown  | 
1344  | chrome.exe  | 13.107.246.45:443  | edge-consumer-static.azureedge.net  | MICROSOFT-CORP-MSN-AS-BLOCK  | US  | unknown  | 
1344  | chrome.exe  | 142.250.186.68:443  | www.google.com  | GOOGLE  | US  | whitelisted  | 
1776  | chrome.exe  | 224.0.0.251:5353  | —  | —  | —  | unknown  | 
1344  | chrome.exe  | 40.126.31.67:443  | login.microsoftonline.com  | MICROSOFT-CORP-MSN-AS-BLOCK  | IE  | whitelisted  | 
Domain  | IP  | Reputation  | 
|---|---|---|
edge-consumer-static.azureedge.net  | 
  | unknown  | 
accounts.google.com  | 
  | shared  | 
azurefrontdoorpages.azureedge.net  | 
  | unknown  | 
azure.microsoft.com  | 
  | whitelisted  | 
portal.azure.com  | 
  | unknown  | 
www.google.com  | 
  | whitelisted  | 
login.microsoftonline.com  | 
  | whitelisted  | 
aadcdn.msauth.net  | 
  | whitelisted  | 
safebrowsing.googleapis.com  | 
  | whitelisted  | 
identity.nel.measure.office.net  | 
  | whitelisted  | 
PID  | Process  | Class  | Message  | 
|---|---|---|---|
1344  | chrome.exe  | Possible Social Engineering Attempted  | PHISHING [ANY.RUN] Suspicious message detected (saved from)  |