URL: | https://adagiofe.neodatagroup.com/ad/clk.jsp?x=509393.683503.1063.519813.-1.en^md^08245K|04635B|08245|08255|08255E|08|04|05685M|08233A|08232|08245B|08243C|15216|15216C|08243|04635|08243A|08255H|08235B|08232C|08255F|08262|08245I|08240|08255I|08235|08243B|08259A|08245A|08259|08232A|08255B|08245G|08250|05685K|08245F|08245R|08220A|08245J|04605E|08215|08255G|08259B|08233|05685|08245M|08220|08245E|08245D|02666I|21667B|08235A|19577H|15220|08233E|08245H|05685A|08245C|08209|15220A|19577|05695|08233B|04605|08215E|08255C|04615|18704|04565A|05685C|18710A|10657|05|08|15|04|02|21|19|18|10^.21.48.1.3937.1.-1.-1.-1..-1.0...&link=https%3A%2F%2Fwww.google.com%2Furl%3Fq%3Dhttps%3A%2F%2Fwww.google.com%2Furl%3Fq%253Dhttps%25253A%25252F%25252Flinkprotect.cudasvc.com%25252Furl%25253Fa%25253Dhttps%25253A%25252F%25252Fwww.buoyhealth.com%25252Fbazaar%25252Fredirect%25252F%25253FcareResourceURL%2525253DaHR0cHM6Ly9hcGkucGFwZXJmbGl0ZS5jb20vbGlua3MvNjU3OTliOTQ1YzdjMjY2YWJiMzcyMDdlLzY1Nzk5YjkzNWM3YzI2NmFiYjM3MjAyMj9yZWRpcmVjdD1odHRwczovL3U0NjEzMDc4NS5jdC5zZW5kZ3JpZC5uZXQlMkZscyUyRmNsaWNrJTNGdXBuJTNEdTAwMS5BTXpuUHk4Qkt3THk5QU5UNDEzd2ItMkZwTEZTbThqaFJ1NXhhbVFwUDl5TlFCTVlqaGFUbXphdnZISW1xTzZSOFJ3Uk1hazdQdm43TzFUUUlJLTJCSU8zUnF6U3BKUEhrTnljdlNDUkpWNm0zaFBiWGZOcTFWbi0yQlNrU3dnRk1GUmNsSktCcG52eXAxbHBkemp3b3YtMkZLMlhYcWRUcGgtMkZVT0FCMjgtMkZiaC0yQnpEV3Fza3NVZmliV0JjWXRTTDhKSGMtMkJhZjFqckVoLTJCZjIyOEtwWXNRZUYtMkJsUndWdGV2U0Y3WTJPaGFlRjdpSmVxUlBickZIY1dhckRpMXhQQTdob0xGeVRjaFI5Zi0yRi0yRi0yQjROTXlCWGVLZUxId2ZldUtpMG5TZzBka1Z6TXlucnFzNWstMkZqaWN4NlY2ZEc5LTJCSGlEV2tYVXZQTFN3elJISEJfZ0djVVZXRnZQZkt6ZHRIY05wZzM0Q0JoWUZRalpyQk1VQjB3UlEtMkZLUjktMkZiOS0yRnB0bkNpNUdSUXFJRGJpLTJCd1JWOHBpY0xGNGZ5SmpUZjFZMXNuaGlNNkRoWDladmdZMXBKakdhSmd4ZC0yRi0yRmxUUmlaN2ZmUlMxNXRBaUlBYVJESUUtMkY2OGE0cGREckVCQldpN3RpTzlnaE43SVp5THVBLTJCbE1pbDhkSnMzanVjc0lUSzRtU21oSHZtV1h6ZkFjS0JRWnBOckZza09VUS0yQmxlMEFDd1ZNSFZZdUluWmFhN3I2WlVSc210cS0yRnU1Q2I3b1dMU2p3a2FMNzNJS3NPd0l1U0U4MW5XSjNJTVlyUy0yQlNLamxJT3VvSGdEY1pvd3d6WVZOU0Q1OUlMSW1wYjh0bXp1Z2lSUHVNMGZqRW5sTWFESFFwTjFrTUk1LTJGNHRWNG1VZ1hPbzZNNjRIR3JCeFhaNXFYTXVGQ09vQi0yQlBDbzU2MDBoMThPQ05pc0wtMkZ5QVg5QVg2dTFzTTlUVFNmcmlHZ3UtMkZEZFdMWE9VYjg2ekEzbHRUMUJoa0NJbG5wcmI4TVZwRzlzWDZiUnctMkY0WUFaZU5zNG1Z%252526c%25253DE%25252C1%25252C0mhHQFs2jkJgMgvfVlPVJH7wA8qcmLISMboK1W5OV7sMG38Hy0XS5t74GF2mw1ibIDohCLGDcjdDPF-bH5wLzU6LBXE0mGPKLqWdZuhhKufc2N7G86Jd75T7nfXm%252526typo%25253D1%2526sa%253DD%2526sntz%253D1%2526usg%253DAOvVaw27Nd1RrCI-oVuy3vdFO4b7%26sa%3DD%26source%3Deditors%26ust%3D1722951066906825%26usg%3DAOvVaw1Hx0j3URYlYkfLLBt9txj5%23YnJhbnRsZXkuZGF1Z2h0cnlAb3dlbnMtbWlub3IuY29t |
Full analysis: | https://app.any.run/tasks/c1f40f52-50e6-447b-a20f-76e619e87deb |
Verdict: | Malicious activity |
Analysis date: | August 06, 2024, 22:28:02 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MD5: | E418AD735636DF2616CBC65635E3CE11 |
SHA1: | A5E2FB5A87F74782D40D6412D890DA6271A4C1D0 |
SHA256: | 4BCA366914F25DED31E16C08AAAD3A02E1D2961D3D23B09DCE4D44D6646E9CF9 |
SSDEEP: | 48:OFittHXC5ncVLNktGgHeXy8YcdCC3rFf1sBfPFN/zfC32Nkb2j15cZj4pv3sdbSi:lbC5ftGV3/37FGBf9N/TCLb2p3pv34bb |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2268 | "C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca | C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Version: 123.26505.0.0 Modules
| |||||||||||||||
6052 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5264 --field-trial-handle=2280,i,13108150080982194186,1092695315234492020,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
6052 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=3528 --field-trial-handle=2280,i,13108150080982194186,1092695315234492020,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
6328 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=4268 --field-trial-handle=2280,i,13108150080982194186,1092695315234492020,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
6396 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5548 --field-trial-handle=2280,i,13108150080982194186,1092695315234492020,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
6480 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://adagiofe.neodatagroup.com/ad/clk.jsp?x=509393.683503.1063.519813.-1.en^md^08245K|04635B|08245|08255|08255E|08|04|05685M|08233A|08232|08245B|08243C|15216|15216C|08243|04635|08243A|08255H|08235B|08232C|08255F|08262|08245I|08240|08255I|08235|08243B|08259A|08245A|08259|08232A|08255B|08245G|08250|05685K|08245F|08245R|08220A|08245J|04605E|08215|08255G|08259B|08233|05685|08245M|08220|08245E|08245D|02666I|21667B|08235A|19577H|15220|08233E|08245H|05685A|08245C|08209|15220A|19577|05695|08233B|04605|08215E|08255C|04615|18704|04565A|05685C|18710A|10657|05|08|15|04|02|21|19|18|10^.21.48.1.3937.1.-1.-1.-1..-1.0...&link=https%3A%2F%2Fwww.google.com%2Furl%3Fq%3Dhttps%3A%2F%2Fwww.google.com%2Furl%3Fq%253Dhttps%25253A%25252F%25252Flinkprotect.cudasvc.com%25252Furl%25253Fa%25253Dhttps%25253A%25252F%25252Fwww.buoyhealth.com%25252Fbazaar%25252Fredirect%25252F%25253FcareResourceURL%2525253DaHR0cHM6Ly9hcGkucGFwZXJmbGl0ZS5jb20vbGlua3MvNjU3OTliOTQ1YzdjMjY2YWJiMzcyMDdlLzY1Nzk5YjkzNWM3YzI2NmFiYjM3MjAyMj9yZWRpcmVjdD1odHRwczovL3U0NjEzMDc4NS5jdC5zZW5kZ3JpZC5uZXQlMkZscyUyRmNsaWNrJTNGdXBuJTNEdTAwMS5BTXpuUHk4Qkt3THk5QU5UNDEzd2ItMkZwTEZTbThqaFJ1NXhhbVFwUDl5TlFCTVlqaGFUbXphdnZISW1xTzZSOFJ3Uk1hazdQdm43TzFUUUlJLTJCSU8zUnF6U3BKUEhrTnljdlNDUkpWNm0zaFBiWGZOcTFWbi0yQlNrU3dnRk1GUmNsSktCcG52eXAxbHBkemp3b3YtMkZLMlhYcWRUcGgtMkZVT0FCMjgtMkZiaC0yQnpEV3Fza3NVZmliV0JjWXRTTDhKSGMtMkJhZjFqckVoLTJCZjIyOEtwWXNRZUYtMkJsUndWdGV2U0Y3WTJPaGFlRjdpSmVxUlBickZIY1dhckRpMXhQQTdob0xGeVRjaFI5Zi0yRi0yRi0yQjROTXlCWGVLZUxId2ZldUtpMG5TZzBka1Z6TXlucnFzNWstMkZqaWN4NlY2ZEc5LTJCSGlEV2tYVXZQTFN3elJISEJfZ0djVVZXRnZQZkt6ZHRIY05wZzM0Q0JoWUZRalpyQk1VQjB3UlEtMkZLUjktMkZiOS0yRnB0bkNpNUdSUXFJRGJpLTJCd1JWOHBpY0xGNGZ5SmpUZjFZMXNuaGlNNkRoWDladmdZMXBKakdhSmd4ZC0yRi0yRmxUUmlaN2ZmUlMxNXRBaUlBYVJESUUtMkY2OGE0cGREckVCQldpN3RpTzlnaE43SVp5THVBLTJCbE1pbDhkSnMzanVjc0lUSzRtU21oSHZtV1h6ZkFjS0JRWnBOckZza09VUS0yQmxlMEFDd1ZNSFZZdUluWmFhN3I2WlVSc210cS0yRnU1Q2I3b1dMU2p3a2FMNzNJS3NPd0l1U0U4MW5XSjNJTVlyUy0yQlNLamxJT3VvSGdEY1pvd3d6WVZOU0Q1OUlMSW1wYjh0bXp1Z2lSUHVNMGZqRW5sTWFESFFwTjFrTUk1LTJGNHRWNG1VZ1hPbzZNNjRIR3JCeFhaNXFYTXVGQ09vQi0yQlBDbzU2MDBoMThPQ05pc0wtMkZ5QVg5QVg2dTFzTTlUVFNmcmlHZ3UtMkZEZFdMWE9VYjg2ekEzbHRUMUJoa0NJbG5wcmI4TVZwRzlzWDZiUnctMkY0WUFaZU5zNG1Z%252526c%25253DE%25252C1%25252C0mhHQFs2jkJgMgvfVlPVJH7wA8qcmLISMboK1W5OV7sMG38Hy0XS5t74GF2mw1ibIDohCLGDcjdDPF-bH5wLzU6LBXE0mGPKLqWdZuhhKufc2N7G86Jd75T7nfXm%252526typo%25253D1%2526sa%253DD%2526sntz%253D1%2526usg%253DAOvVaw27Nd1RrCI-oVuy3vdFO4b7%26sa%3DD%26source%3Deditors%26ust%3D1722951066906825%26usg%3DAOvVaw1Hx0j3URYlYkfLLBt9txj5%23YnJhbnRsZXkuZGF1Z2h0cnlAb3dlbnMtbWlub3IuY29t" | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
6572 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x300,0x304,0x308,0x2f8,0x310,0x7fffcb775fd8,0x7fffcb775fe4,0x7fffcb775ff0 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
6764 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2276 --field-trial-handle=2280,i,13108150080982194186,1092695315234492020,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
6772 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2372 --field-trial-handle=2280,i,13108150080982194186,1092695315234492020,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
6812 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2824 --field-trial-handle=2280,i,13108150080982194186,1092695315234492020,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
|
(PID) Process: | (6480) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
Operation: | write | Name: | failed_count |
Value: 0 | |||
(PID) Process: | (6480) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
Operation: | write | Name: | state |
Value: 2 | |||
(PID) Process: | (6480) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
Operation: | write | Name: | StatusCodes |
Value: | |||
(PID) Process: | (6480) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
(PID) Process: | (6480) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
Operation: | write | Name: | state |
Value: 1 | |||
(PID) Process: | (6480) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
Operation: | write | Name: | dr |
Value: 1 | |||
(PID) Process: | (6480) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
(PID) Process: | (6480) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge |
Operation: | write | Name: | UsageStatsInSample |
Value: 1 | |||
(PID) Process: | (6480) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
Operation: | write | Name: | usagestats |
Value: 0 | |||
(PID) Process: | (6480) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
Operation: | write | Name: | urlstats |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
6480 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFe5f52.TMP | — | |
MD5:— | SHA256:— | |||
6480 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
6480 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFe5f61.TMP | — | |
MD5:— | SHA256:— | |||
6480 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFe5f61.TMP | — | |
MD5:— | SHA256:— | |||
6480 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
6480 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFe5f42.TMP | — | |
MD5:— | SHA256:— | |||
6480 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
6480 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
6480 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RFe5fbf.TMP | — | |
MD5:— | SHA256:— | |||
6480 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 239.255.255.250:1900 | — | — | — | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
adagiofe.neodatagroup.com |
| unknown |
edge.microsoft.com |
| whitelisted |
business.bing.com |
| whitelisted |
edge-mobile-static.azureedge.net |
| whitelisted |
www.google.com |
| whitelisted |
bzib.nelreports.net |
| whitelisted |
www.bing.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net) |