URL:

https://github.com/CFX-Finder/ScreenshareTool/releases/tag/ScreenShare

Full analysis: https://app.any.run/tasks/0b755600-4bad-4173-96e9-ac87373b0ddf
Verdict: Malicious activity
Analysis date: October 12, 2024, 08:14:36
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
pyinstaller
Indicators:
MD5:

90CA7DECC4382DF3CAEF46C0013710E7

SHA1:

6DD6ED597235707150D34DE0EAACF59602240EF9

SHA256:

474E01EF7327A32776CEEC7DC2AEFA2FE76B7A25C0CEB70C5044FEFECEA25B56

SSDEEP:

3:N8tEdkdwtzN+VXhrqK2l5NEQn:2uGmtzQVxrx25Vn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Web Browser History Viewer utility (NirSoft) is detected

      • BrowsingHistoryView.exe (PID: 7876)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • CFX Finder SS Tool.exe (PID: 2588)
      • CFX Finder SS Tool.exe (PID: 8100)
    • Application launched itself

      • CFX Finder SS Tool.exe (PID: 8100)
    • The process drops C-runtime libraries

      • CFX Finder SS Tool.exe (PID: 8100)
    • Using 'findstr.exe' to search for text patterns in files and output

      • powershell.exe (PID: 6300)
      • cmd.exe (PID: 7756)
      • cmd.exe (PID: 7240)
      • cmd.exe (PID: 6204)
      • cmd.exe (PID: 6628)
      • cmd.exe (PID: 8160)
    • Process drops python dynamic module

      • CFX Finder SS Tool.exe (PID: 8100)
    • Process drops legitimate windows executable

      • CFX Finder SS Tool.exe (PID: 8100)
    • Starts CMD.EXE for commands execution

      • CFX Finder SS Tool.exe (PID: 2588)
    • Starts POWERSHELL.EXE for commands execution

      • CFX Finder SS Tool.exe (PID: 2588)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3864)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7056)
      • msedge.exe (PID: 7644)
    • Manual execution by a user

      • WinRAR.exe (PID: 7056)
      • CFX Finder SS Tool.exe (PID: 6308)
      • CFX Finder SS Tool.exe (PID: 8100)
      • EXCEL.EXE (PID: 824)
      • EXCEL.EXE (PID: 4680)
    • NirSoft software is detected

      • AppReadWriteCounter.exe (PID: 7820)
      • AppCompatibilityView.exe (PID: 7240)
      • AlternateStreamView.exe (PID: 7076)
      • ChromeCookiesView.exe (PID: 7568)
      • BrowserDownloadsView.exe (PID: 7764)
      • ExecutedProgramsList.exe (PID: 3960)
      • ImageCacheViewer.exe (PID: 3860)
      • MUICacheView.exe (PID: 7792)
      • FolderTimeUpdate.exe (PID: 3944)
      • ChromeCacheView.exe (PID: 7752)
      • EventLogChannelsView.exe (PID: 2376)
      • LastActivityView.exe (PID: 4556)
      • NetworkUsageView.exe (PID: 6416)
      • MZCacheView.exe (PID: 7568)
      • MyLastSearch.exe (PID: 7252)
      • PreviousFilesRecovery.exe (PID: 7948)
      • RecentFilesView.exe (PID: 7876)
      • RegScanner.exe (PID: 8160)
      • ShellBagsView.exe (PID: 7176)
      • FileAccessErrorView.exe (PID: 6240)
      • LoadedDllsView.exe (PID: 7800)
      • WhatInStartup.exe (PID: 7172)
      • WebCacheImageInfo.exe (PID: 7268)
      • WinDefLogView.exe (PID: 4316)
      • WinDefThreatsView.exe (PID: 6416)
      • WinPrefetchView.exe (PID: 7512)
      • SimpleWMIView.exe (PID: 7784)
      • UninstallView.exe (PID: 6776)
      • USBDeview.exe (PID: 7928)
      • USBDriveLog.exe (PID: 3960)
      • UserAssistView.exe (PID: 7852)
      • VideoCacheView.exe (PID: 3432)
    • Reads the computer name

      • identity_helper.exe (PID: 7944)
    • Reads Environment values

      • identity_helper.exe (PID: 7944)
    • Checks supported languages

      • identity_helper.exe (PID: 7944)
    • Application launched itself

      • msedge.exe (PID: 5756)
      • msedge.exe (PID: 6196)
    • PyInstaller has been detected (YARA)

      • CFX Finder SS Tool.exe (PID: 8100)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
330
Monitored processes
182
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs sppextcomobj.exe no specs slui.exe rundll32.exe no specs winrar.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs cfx finder ss tool.exe no specs THREAT cfx finder ss tool.exe conhost.exe no specs cfx finder ss tool.exe cmd.exe no specs cmd.exe no specs powershell.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs findstr.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs appcompatibilityview.exe no specs browserdownloadsview.exe no specs appreadwritecounter.exe no specs cmd.exe no specs chromecacheview.exe no specs browsinghistoryview.exe no specs alternatestreamview.exe no specs chromecookiesview.exe no specs eventlogchannelsview.exe no specs cmd.exe no specs executedprogramslist.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs imagecacheviewer.exe no specs foldertimeupdate.exe no specs fileaccesserrorview.exe no specs cmd.exe no specs cmd.exe no specs lastactivityview.exe no specs loadeddllsview.exe no specs cmd.exe no specs muicacheview.exe no specs cmd.exe no specs mylastsearch.exe no specs cmd.exe no specs mzcacheview.exe no specs cmd.exe no specs networkusageview.exe no specs cmd.exe no specs previousfilesrecovery.exe no specs vssvc.exe no specs cmd.exe no specs recentfilesview.exe no specs cmd.exe no specs regscanner.exe no specs cmd.exe no specs shellbagsview.exe no specs cmd.exe no specs simplewmiview.exe no specs cmd.exe no specs uninstallview.exe no specs cmd.exe no specs usbdeview.exe no specs cmd.exe no specs usbdrivelog.exe no specs cmd.exe no specs userassistview.exe no specs cmd.exe no specs videocacheview.exe no specs cmd.exe no specs webcacheimageinfo.exe no specs cmd.exe no specs whatinstartup.exe no specs cmd.exe no specs windeflogview.exe no specs cmd.exe no specs cmd.exe no specs windefthreatsview.exe no specs winprefetchview.exe no specs cmd.exe no specs fsutil.exe no specs findstr.exe no specs findstr.exe no specs cmd.exe no specs fsutil.exe no specs findstr.exe no specs findstr.exe no specs cmd.exe no specs fsutil.exe no specs findstr.exe no specs findstr.exe no specs cmd.exe no specs fsutil.exe no specs findstr.exe no specs findstr.exe no specs cmd.exe no specs fsutil.exe no specs findstr.exe no specs findstr.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe excel.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs excel.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
204C:\WINDOWS\system32\cmd.exe /c "C:\Users\tools\FolderTimeUpdate.exe /scomma data/FolderTimeUpdate.csv"C:\Windows\System32\cmd.exeCFX Finder SS Tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
616fsutil usn readjournal c: csv C:\Windows\System32\fsutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
fsutil.exe
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\fsutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
692"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4896 --field-trial-handle=2324,i,10583202204420595384,15553521748303965831,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
824"C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\admin\Downloads\data\result\Suspicious_USBDeview.csv"C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\excel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
948C:\WINDOWS\system32\cmd.exe /c "C:\Users\tools\WinPrefetchView.exe /scomma data/WinPrefetchView.csv"C:\Windows\System32\cmd.exeCFX Finder SS Tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
2056fsutil usn readjournal c: csv C:\Windows\System32\fsutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
fsutil.exe
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\fsutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2140"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2320 --field-trial-handle=2324,i,10583202204420595384,15553521748303965831,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2376C:\Users\tools\EventLogChannelsView.exe /scomma data/EventLogChannelsView.csvC:\Users\tools\EventLogChannelsView.execmd.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
EventLogChannelsView
Exit code:
0
Version:
1.36
Modules
Images
c:\users\tools\eventlogchannelsview.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2376"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3868 --field-trial-handle=2388,i,11615560949798801916,9049589784558005843,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2416C:\WINDOWS\system32\cmd.exe /c "C:\Users\tools\ChromeCacheView.exe /scomma data/ChromeCacheView.csv"C:\Windows\System32\cmd.exeCFX Finder SS Tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
Total events
34 827
Read events
34 375
Write events
391
Delete events
61

Modification events

(PID) Process:(5756) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(5756) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(5756) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(5756) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(5756) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
FC069C7AD9822F00
(PID) Process:(5756) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
21A8A37AD9822F00
(PID) Process:(5756) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262746
Operation:writeName:WindowTabManagerFileMappingId
Value:
{0EEFF839-E8B6-4890-98C9-178F3BE9C9CA}
(PID) Process:(5756) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262746
Operation:writeName:WindowTabManagerFileMappingId
Value:
{8D38472F-FE12-4F62-8CB0-5B6B572AFEC5}
(PID) Process:(5756) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262746
Operation:writeName:WindowTabManagerFileMappingId
Value:
{8EFB21E1-ED82-42F0-994D-2FA58A7AD2B3}
(PID) Process:(5756) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262746
Operation:writeName:WindowTabManagerFileMappingId
Value:
{91C43972-CBD3-4437-A5BA-6773EA4EA0BF}
Executable files
86
Suspicious files
464
Text files
221
Unknown types
0

Dropped files

PID
Process
Filename
Type
5756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF8b658.TMP
MD5:
SHA256:
5756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
5756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF8b658.TMP
MD5:
SHA256:
5756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF8b678.TMP
MD5:
SHA256:
5756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
5756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
5756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF8b687.TMP
MD5:
SHA256:
5756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF8b687.TMP
MD5:
SHA256:
5756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
5756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
45
TCP/UDP connections
133
DNS requests
108
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8024
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c54934e3-c996-4c82-b272-35f0b26d0e32?P1=1729296290&P2=404&P3=2&P4=Scc0h9Vm3mnZlM84fvvTbWl10dB14HQqFVE2ge8GdAzKncK%2fC2mCxsNd73zhCcTXoqV29%2bdcLnqkNEPZyRjrkA%3d%3d
unknown
whitelisted
6944
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6996
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
8024
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c54934e3-c996-4c82-b272-35f0b26d0e32?P1=1729296290&P2=404&P3=2&P4=Scc0h9Vm3mnZlM84fvvTbWl10dB14HQqFVE2ge8GdAzKncK%2fC2mCxsNd73zhCcTXoqV29%2bdcLnqkNEPZyRjrkA%3d%3d
unknown
whitelisted
8024
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/1490e18b-fab2-4eb0-b0f5-6785c3507d46?P1=1729296290&P2=404&P3=2&P4=L%2f%2b6sErSN6u6M5kaRSLS4KC22kik7SplJmNJ9ezR6pZd5axCAz%2b1PdvPXWnY1%2fw6Uw5Qc8x4r35t2ujQulx7nw%3d%3d
unknown
whitelisted
8024
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c54934e3-c996-4c82-b272-35f0b26d0e32?P1=1729296290&P2=404&P3=2&P4=Scc0h9Vm3mnZlM84fvvTbWl10dB14HQqFVE2ge8GdAzKncK%2fC2mCxsNd73zhCcTXoqV29%2bdcLnqkNEPZyRjrkA%3d%3d
unknown
whitelisted
8024
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c54934e3-c996-4c82-b272-35f0b26d0e32?P1=1729296290&P2=404&P3=2&P4=Scc0h9Vm3mnZlM84fvvTbWl10dB14HQqFVE2ge8GdAzKncK%2fC2mCxsNd73zhCcTXoqV29%2bdcLnqkNEPZyRjrkA%3d%3d
unknown
whitelisted
8024
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c54934e3-c996-4c82-b272-35f0b26d0e32?P1=1729296290&P2=404&P3=2&P4=Scc0h9Vm3mnZlM84fvvTbWl10dB14HQqFVE2ge8GdAzKncK%2fC2mCxsNd73zhCcTXoqV29%2bdcLnqkNEPZyRjrkA%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4836
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5756
msedge.exe
239.255.255.250:1900
whitelisted
2576
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2576
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2576
msedge.exe
140.82.121.3:443
github.com
GITHUB
US
shared
2576
msedge.exe
13.107.246.44:443
edge-mobile-static.azureedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.78
  • 142.250.185.142
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
github.com
  • 140.82.121.3
shared
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.44
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
bzib.nelreports.net
  • 2.19.126.152
  • 2.19.126.145
  • 23.48.23.26
  • 23.48.23.51
whitelisted
www.bing.com
  • 2.23.209.149
  • 2.23.209.140
  • 2.23.209.135
  • 2.23.209.141
  • 2.23.209.161
  • 2.23.209.144
  • 2.23.209.160
  • 2.23.209.158
  • 2.23.209.150
  • 2.23.209.130
  • 2.23.209.143
  • 2.23.209.154
  • 104.126.37.128
  • 104.126.37.178
  • 104.126.37.171
  • 104.126.37.177
  • 104.126.37.163
  • 104.126.37.176
  • 104.126.37.170
  • 104.126.37.179
  • 104.126.37.186
whitelisted
github.githubassets.com
  • 185.199.108.154
  • 185.199.110.154
  • 185.199.109.154
  • 185.199.111.154
whitelisted

Threats

No threats detected
No debug info