URL: | https://www.mywatchseries.cyou |
Full analysis: | https://app.any.run/tasks/93b1d8ea-c151-4d20-ab0d-bee073fc1e4d |
Verdict: | Malicious activity |
Analysis date: | April 12, 2024, 11:56:55 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | DF5A434C471168400CF78FCF2E975AF4 |
SHA1: | 1685D2812DE55BA9BFB279E55AD8EE6A61256AF0 |
SHA256: | 499E3CD0EB6E7189B7B374619F7141C8806E6264AC236BF7D6965F68AD01AD1F |
SSDEEP: | 3:N8DSL6NHxMLL:2OL6NRMv |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
116 | "C:\Program Files\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:amazon-new-ids=on --with-feature:cashback=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:extended-unstoppable-domains=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-maker-studio-integration=on --with-feature:gaming-api=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:personalized-speeddials=on --with-feature:premium-valve-in=on --with-feature:proxy-switcher-ui-default-visible=on --with-feature:sd-suggestions-external=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=off --with-feature:installer-one-version-one-subfolder=off --mojo-platform-channel-handle=5992 --field-trial-handle=1156,i,7396179613548773581,13781110346699848130,131072 /prefetch:8 | C:\Program Files\Opera\opera.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 95.0.4635.90 Modules
| |||||||||||||||
332 | "C:\Users\admin\Downloads\Opera_95.0.4635.90_Setup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --launchopera=1 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --pin-additional-shortcuts=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --initial-pid=2936 --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20240412125957" --session-guid=1b2a9537-4954-4e54-9b08-bf56d5d5764c --desktopshortcut=1 --wait-for-package --initial-proc-handle=4806000000000000 | C:\Users\admin\Downloads\Opera_95.0.4635.90_Setup.exe | Opera_95.0.4635.90_Setup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Installer Exit code: 0 Version: 95.0.4635.90 Modules
| |||||||||||||||
452 | "C:\Program Files\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:amazon-new-ids=on --with-feature:cashback=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:extended-unstoppable-domains=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-maker-studio-integration=on --with-feature:gaming-api=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:personalized-speeddials=on --with-feature:premium-valve-in=on --with-feature:proxy-switcher-ui-default-visible=on --with-feature:sd-suggestions-external=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=off --with-feature:installer-one-version-one-subfolder=off --mojo-platform-channel-handle=2364 --field-trial-handle=1156,i,7396179613548773581,13781110346699848130,131072 /prefetch:8 | C:\Program Files\Opera\opera.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 95.0.4635.90 Modules
| |||||||||||||||
552 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3964 --field-trial-handle=1316,i,11491878259647414399,9320209265343758294,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
568 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=30 --mojo-platform-channel-handle=4140 --field-trial-handle=1316,i,11491878259647414399,9320209265343758294,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
604 | "C:\Program Files\Opera\opera.exe" --type=renderer --extension-process --with-feature:amazon-new-ids=on --with-feature:cashback=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:extended-unstoppable-domains=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-maker-studio-integration=on --with-feature:gaming-api=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:personalized-speeddials=on --with-feature:premium-valve-in=on --with-feature:proxy-switcher-ui-default-visible=on --with-feature:sd-suggestions-external=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=off --with-feature:installer-one-version-one-subfolder=off --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --mojo-platform-channel-handle=2172 --field-trial-handle=1156,i,7396179613548773581,13781110346699848130,131072 /prefetch:1 | C:\Program Files\Opera\opera.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 95.0.4635.90 Modules
| |||||||||||||||
696 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1260 --field-trial-handle=1316,i,11491878259647414399,9320209265343758294,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
752 | "C:\Program Files\Opera\95.0.4635.90\opera_crashreporter.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=95.0.4635.90 --initial-client-data=0x174,0x178,0x17c,0x148,0x180,0x19935990,0x199359a0,0x199359ac | C:\Program Files\Opera\95.0.4635.90\opera_crashreporter.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera crash-reporter Version: 95.0.4635.90 Modules
| |||||||||||||||
764 | "C:\Program Files\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:amazon-new-ids=on --with-feature:cashback=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:extended-unstoppable-domains=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-maker-studio-integration=on --with-feature:gaming-api=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:personalized-speeddials=on --with-feature:premium-valve-in=on --with-feature:proxy-switcher-ui-default-visible=on --with-feature:sd-suggestions-external=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=off --with-feature:installer-one-version-one-subfolder=off --mojo-platform-channel-handle=6268 --field-trial-handle=1156,i,7396179613548773581,13781110346699848130,131072 /prefetch:8 | C:\Program Files\Opera\opera.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 95.0.4635.90 Modules
| |||||||||||||||
844 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=38 --mojo-platform-channel-handle=4436 --field-trial-handle=1316,i,11491878259647414399,9320209265343758294,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
|
(PID) Process: | (3936) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
Operation: | write | Name: | failed_count |
Value: 0 | |||
(PID) Process: | (3936) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
Operation: | write | Name: | state |
Value: 2 | |||
(PID) Process: | (3936) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
Operation: | write | Name: | StatusCodes |
Value: | |||
(PID) Process: | (3936) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
(PID) Process: | (3936) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
Operation: | write | Name: | state |
Value: 1 | |||
(PID) Process: | (3936) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
Operation: | write | Name: | dr |
Value: 1 | |||
(PID) Process: | (3936) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics |
Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
(PID) Process: | (3936) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge |
Operation: | write | Name: | UsageStatsInSample |
Value: 1 | |||
(PID) Process: | (3936) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
Operation: | write | Name: | usagestats |
Value: 1 | |||
(PID) Process: | (3936) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
Operation: | write | Name: | urlstats |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3936 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat | binary | |
MD5:— | SHA256:— | |||
1692 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\CrashpadMetrics.pma | binary | |
MD5:— | SHA256:— | |||
3936 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Variations | binary | |
MD5:— | SHA256:— | |||
3936 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\cf7bcefc-1418-4b5b-b115-3ab4ed133f46.tmp | text | |
MD5:— | SHA256:— | |||
3936 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF182333.TMP | text | |
MD5:— | SHA256:— | |||
3936 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State | — | |
MD5:— | SHA256:— | |||
3936 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Last Version | text | |
MD5:— | SHA256:— | |||
3936 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\LOG.old~RF1823b0.TMP | text | |
MD5:— | SHA256:— | |||
3936 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
3936 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF1823cf.TMP | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2936 | Opera_95.0.4635.90_Setup.exe | GET | 304 | 173.222.108.147:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e7a01d75146102e1 | unknown | — | — | — |
2936 | Opera_95.0.4635.90_Setup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D | unknown | — | — | — |
1080 | svchost.exe | GET | 304 | 2.16.100.168:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e90c163b6659448e | unknown | — | — | — |
2936 | Opera_95.0.4635.90_Setup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAfyOr5A1UWlCmQhXhy%2Bwwk%3D | unknown | — | — | — |
1080 | svchost.exe | GET | 200 | 2.16.100.168:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?1b8fee253118cbef | unknown | — | — | — |
3164 | msedge.exe | GET | — | 103.224.182.206:80 | http://pinsid.com/favicon.ico | unknown | — | — | — |
3164 | msedge.exe | GET | 302 | 103.224.182.224:80 | http://googs.com/ | unknown | — | — | — |
3164 | msedge.exe | GET | 302 | 103.224.182.206:80 | http://pinsid.com/r.php?u=https%3A%2F%2Fadonsonlyd.xyz%2Fclick.php%3Fkey%3D3cdq1k8mfqcc09umlzp5%26cpv%3D0.081%26subid%3D1593352750%26kw%3D.de.02.desktop.nonadult.windows.edge%26tt%3Dtt&s=j&enc=1kgM2DLf9w%2B6tq3%2FRFJnkn49flRURmp1RHZOaTZGWVdyYlpIZ1JPd3g4MFZ3LzZ2b1BTQWJtU0RueUxYTzBPN1BPc0EyL2x1UkRJUkt2Q21SeVZPbEpPZTJaV2grV0VHQnBHcFQ4a0VtSjA2dkd0Z3luK3doaU9veG1RTE80bU5SZnZMdGE5bUM3d2xDY0dMOWYyVHBNOHUrazhmRDAyaFRyUmMvdWptN3J4aUFhWHdFZ3N6czVLREFqNTJEUUU2S2dGQ0luMkdQaWdwaEQxaG54QWIvOHYrSWtoUEpHc1ZZQU5xWkZ1MDJocHM5Q0NVeWJmL0VWOUh4aUlFQWF2RnViSlJVZVgvbHBtWTdIR1JVMHA2UkNxZXlsLzdGbzJXdHVuOHhDb25ZRFFUT0xHbUFueWtBTHpabzhaK1hvZ2RuaGNWSmNCRm9SMDR4cnFmUXFnMDJET3d2dVhWYVlPRmhpVjYzNE5YU2NYNW8zUVRjUlhwRVIwckFia3R2eUM3QnEwMEM5N0Z5VW5nS0I3Q0lmMFBCYlRzOXpVdE1YalVibTdQK1ptbWd0NE91eWorSlNtS2g1SHZLRUZ6VlBka05WcHlwVXZMNTh0ZGxwTWU4WlY5UzdvUmpxTnZIRU1tVHlWS3VZUGpJYjVpV0lMTDBnbG1INFpDbHZod0d4V1hDdEpLdjRBSk9qMmp4ODBvRjdjeGJYQytQRXcySzY1NkhGVzBnUElENStxbE5ZMlNlOUIxZ2dxSVdSdVQxeEhMb2ZCM1ZHeTJYcHhKR2gyNURvZ0pBZENIOG9iRERqYTA1M1hUVDlTSk9SMnlYTy9TOXlLOHY0VlhKa3FLUktRT1J6RU52YVZnbVZrZmJRd0N3MHY1OUs3ZmdrZ2JPdE5kTmEzYjlub2cxbFR5SFlMUFpSeGxYS3pJL1pFMGsySFRXcTBoa3hWRmNCM3FkNlN0QXpmMExhNUpNYU5NS1FqQytwWXNmZGQ3MTR5TmM0Y0lDOW9XS05DU3dVOUFRVnUwZDFZdjE4S1JMK0N4QnB1Y3VRMFNPK3VZQU0vVEFrNmpSbURHYWJyVS9uL0dzYk5WT1VjWTV4N0NoczhSUC9Ueml4ZXd2U3ViOWh6UHJuZ3Z3NUtRTTMya2I5eVdjUGtvb0pRR1hkZk50TXptUUozaDV6eWhWWWVsbS9wcmNFS25oK3hoU1pGSldVWjlzM3pNcHdVYUlBaHdrYWx2dzNyQU5aS0hBNnRGVGZVWE0xY3ppb1VKMTdaY0JaU1ZtRTdaT1JoU3NydFZwOWUva2NIdmtIMDhGbTJsczU3c0JuK21INzFQOXlvUi9ERFlDUEl1MFYzcHN2c3c4S2RhTWYrVnRyNTdJeG9IOVIrZ1hIdElGbjU%3D&vs=1280:564&ds=1280:720&sl=0:0&os=f&nos=f&if=f&sc=f&gpu=Google%20Inc.%20(Google)%20-%20ANGLE%20(Google,%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE)),%20SwiftShader%20driver)&fp=-1 | unknown | — | — | — |
3164 | msedge.exe | GET | 200 | 103.224.182.206:80 | http://pinsid.com/jscheck.php?enc=1kgM2DLf9w%2B6tq3%2FRFJnkn49flRURmp1RHZOaTZGWVdyYlpIZ1JPd3g4MFZ3LzZ2b1BTQWJtU0RueUxYTzBPN1BPc0EyL2x1UkRJUkt2Q21SeVZPbEpPZTJaV2grV0VHQnBHcFQ4a0VtSjA2dkd0Z3luK3doaU9veG1RTE80bU5SZnZMdGE5bUM3d2xDY0dMOWYyVHBNOHUrazhmRDAyaFRyUmMvdWptN3J4aUFhWHdFZ3N6czVLREFqNTJEUUU2S2dGQ0luMkdQaWdwaEQxaG54QWIvOHYrSWtoUEpHc1ZZQU5xWkZ1MDJocHM5Q0NVeWJmL0VWOUh4aUlFQWF2RnViSlJVZVgvbHBtWTdIR1JVMHA2UkNxZXlsLzdGbzJXdHVuOHhDb25ZRFFUT0xHbUFueWtBTHpabzhaK1hvZ2RuaGNWSmNCRm9SMDR4cnFmUXFnMDJET3d2dVhWYVlPRmhpVjYzNE5YU2NYNW8zUVRjUlhwRVIwckFia3R2eUM3QnEwMEM5N0Z5VW5nS0I3Q0lmMFBCYlRzOXpVdE1YalVibTdQK1ptbWd0NE91eWorSlNtS2g1SHZLRUZ6VlBka05WcHlwVXZMNTh0ZGxwTWU4WlY5UzdvUmpxTnZIRU1tVHlWS3VZUGpJYjVpV0lMTDBnbG1INFpDbHZod0d4V1hDdEpLdjRBSk9qMmp4ODBvRjdjeGJYQytQRXcySzY1NkhGVzBnUElENStxbE5ZMlNlOUIxZ2dxSVdSdVQxeEhMb2ZCM1ZHeTJYcHhKR2gyNURvZ0pBZENIOG9iRERqYTA1M1hUVDlTSk9SMnlYTy9TOXlLOHY0VlhKa3FLUktRT1J6RU52YVZnbVZrZmJRd0N3MHY1OUs3ZmdrZ2JPdE5kTmEzYjlub2cxbFR5SFlMUFpSeGxYS3pJL1pFMGsySFRXcTBoa3hWRmNCM3FkNlN0QXpmMExhNUpNYU5NS1FqQytwWXNmZGQ3MTR5TmM0Y0lDOW9XS05DU3dVOUFRVnUwZDFZdjE4S1JMK0N4QnB1Y3VRMFNPK3VZQU0vVEFrNmpSbURHYWJyVS9uL0dzYk5WT1VjWTV4N0NoczhSUC9Ueml4ZXd2U3ViOWh6UHJuZ3Z3NUtRTTMya2I5eVdjUGtvb0pRR1hkZk50TXptUUozaDV6eWhWWWVsbS9wcmNFS25oK3hoU1pGSldVWjlzM3pNcHdVYUlBaHdrYWx2dzNyQU5aS0hBNnRGVGZVWE0xY3ppb1VKMTdaY0JaU1ZtRTdaT1JoU3NydFZwOWUva2NIdmtIMDhGbTJsczU3c0JuK21INzFQOXlvUi9ERFlDUEl1MFYzcHN2c3c4S2RhTWYrVnRyNTdJeG9IOVIrZ1hIdElGbjU%3D&rand=0.46412676218124727&vs=1280:564&ds=1280:720&sl=0:0&os=f&nos=f&if=f&sc=f&gpu=Google%20Inc.%20(Google)%20-%20ANGLE%20(Google,%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE)),%20SwiftShader%20driver)&fp=-1 | unknown | — | — | — |
3164 | msedge.exe | GET | — | 103.224.182.206:80 | http://zajtpa.com/favicon.ico | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
3936 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
3164 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3164 | msedge.exe | 172.67.188.120:443 | www.mywatchseries.cyou | — | — | unknown |
3164 | msedge.exe | 131.253.33.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3164 | msedge.exe | 35.190.80.1:443 | a.nel.cloudflare.com | GOOGLE | US | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3164 | msedge.exe | 104.17.3.184:443 | challenges.cloudflare.com | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
config.edge.skype.com |
| unknown |
www.mywatchseries.cyou |
| unknown |
edge.microsoft.com |
| unknown |
a.nel.cloudflare.com |
| unknown |
challenges.cloudflare.com |
| unknown |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| unknown |
www.bing.com |
| unknown |
www.googletagmanager.com |
| unknown |
static.mywatchseries.cyou |
| unknown |
sizzledfirings.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] A free CDN for open source projects (jsdelivr .net) |
— | — | Misc Attack | ET CINS Active Threat Intelligence Poor Reputation IP group 32 |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
Process | Message |
---|---|
assistant_installer.exe | [0412/130013.562:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202404121259571\assistant\assistant_installer.exe" --version
|
assistant_installer.exe | [0412/130029.402:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202404121259571\assistant\assistant_installer.exe" --installfolder="C:\Program Files\Opera\assistant" --copyonly=0 --allusers=0
|
assistant_installer.exe | [0412/130029.507:INFO:assistant_installer.cc(283)] Setting up the registry
|
assistant_installer.exe | [0412/130029.585:INFO:assistant_installer.cc(337)] Creating scheduled task
|
assistant_installer.exe | [0412/130029.636:INFO:assistant_installer.cc(242)] Running Assistant
|
assistant_installer.exe | [0412/130029.636:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Program Files\Opera\assistant\assistant_installer.exe" --installfolder="C:\Program Files\Opera\assistant" --run-assistant --allusers=0
|
browser_assistant.exe | [0412/130029.934:ERROR:tracking_data_utils.cc(72)] Can't read edition: missing value.
|
assistant_installer.exe | [0412/130030.419:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Program Files\Opera\assistant\assistant_installer.exe" --post-elevated-install-tasks --installfolder="C:\Program Files\Opera\assistant"
|