File name:

Setup.exe

Full analysis: https://app.any.run/tasks/5cb486a9-af70-4800-b67a-42bc12df051b
Verdict: Malicious activity
Analysis date: September 20, 2024, 23:19:18
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
qrcode
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

D9E09E6102FD39858C0BA79FE9DDAA1C

SHA1:

6A9038FA227945E09185C2635923215890333486

SHA256:

4F2CE158EA63E2723F515E55FDB677F87D55F7E7302BFA6C9E2E6306F6759420

SSDEEP:

3072:Yefw3AuFiCg2kW3WBo9A/BwdKIkIXgtqr444G:Y0wHi6x4o9AWxHwtWR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • nszD5C9.tmp (PID: 8020)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 6956)
      • nszD5C9.tmp (PID: 8020)
      • Watchdog.exe (PID: 3144)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Setup.exe (PID: 6956)
      • nszD5C9.tmp (PID: 8020)
      • SetupEngine.exe (PID: 8152)
      • SetupEngine.exe (PID: 7292)
    • Starts application with an unusual extension

      • Setup.exe (PID: 6956)
    • Executable content was dropped or overwritten

      • nszD5C9.tmp (PID: 8020)
      • Setup.exe (PID: 6956)
      • PcAppStore.exe (PID: 6904)
      • SetupEngine.exe (PID: 7292)
      • SetupEngine.exe (PID: 8152)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 6956)
      • nszD5C9.tmp (PID: 8020)
      • Watchdog.exe (PID: 3144)
    • The process creates files with name similar to system file names

      • nszD5C9.tmp (PID: 8020)
    • Process drops legitimate windows executable

      • nszD5C9.tmp (PID: 8020)
      • SetupEngine.exe (PID: 8152)
    • Searches for installed software

      • nszD5C9.tmp (PID: 8020)
    • Creates a software uninstall entry

      • nszD5C9.tmp (PID: 8020)
    • Application launched itself

      • NW_store.exe (PID: 6624)
      • nw.exe (PID: 8460)
      • nw.exe (PID: 8488)
    • Executes as Windows Service

      • FastSRV.exe (PID: 8020)
    • Starts CMD.EXE for commands execution

      • SetupEngine.exe (PID: 8152)
    • The executable file from the user directory is run by the CMD process

      • diskspd.exe (PID: 5376)
  • INFO

    • Creates files or folders in the user directory

      • Setup.exe (PID: 6956)
      • nszD5C9.tmp (PID: 8020)
      • Watchdog.exe (PID: 3144)
      • NW_store.exe (PID: 6200)
      • NW_store.exe (PID: 6624)
      • NW_store.exe (PID: 7940)
    • Reads the machine GUID from the registry

      • Setup.exe (PID: 6956)
      • Watchdog.exe (PID: 3144)
      • nszD5C9.tmp (PID: 8020)
      • NW_store.exe (PID: 6624)
    • Create files in a temporary directory

      • Setup.exe (PID: 6956)
      • nszD5C9.tmp (PID: 8020)
      • NW_store.exe (PID: 6624)
    • Reads the computer name

      • identity_helper.exe (PID: 7268)
      • nszD5C9.tmp (PID: 8020)
      • PcAppStore.exe (PID: 6904)
      • Watchdog.exe (PID: 3144)
      • NW_store.exe (PID: 6624)
      • NW_store.exe (PID: 7828)
      • NW_store.exe (PID: 7940)
    • Checks supported languages

      • identity_helper.exe (PID: 7268)
      • nszD5C9.tmp (PID: 8020)
      • Watchdog.exe (PID: 3144)
      • PcAppStore.exe (PID: 6904)
      • NW_store.exe (PID: 6624)
      • NW_store.exe (PID: 6200)
      • NW_store.exe (PID: 7940)
      • NW_store.exe (PID: 7828)
      • NW_store.exe (PID: 7884)
      • NW_store.exe (PID: 5908)
    • Checks proxy server information

      • Setup.exe (PID: 6956)
      • nszD5C9.tmp (PID: 8020)
      • Watchdog.exe (PID: 3144)
      • NW_store.exe (PID: 6624)
    • Reads the software policy settings

      • nszD5C9.tmp (PID: 8020)
      • Watchdog.exe (PID: 3144)
      • PcAppStore.exe (PID: 6904)
    • Application launched itself

      • msedge.exe (PID: 5992)
    • Process checks computer location settings

      • NW_store.exe (PID: 6624)
      • NW_store.exe (PID: 7884)
      • NW_store.exe (PID: 5908)
    • Reads Environment values

      • NW_store.exe (PID: 6200)
      • PcAppStore.exe (PID: 6904)
    • Sends debugging messages

      • NW_store.exe (PID: 6200)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 2568)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:57:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 186880
UninitializedDataSize: 2048
EntryPoint: 0x352d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1091
ProductVersionNumber: 1.0.0.1091
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Fast Corporation LTD
FileDescription: PC App Store Setup
LegalCopyright: Fast Corporation LTD
ProductName: PC App Store
ProductVersion: 1.0.0.1091x
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
237
Monitored processes
100
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start setup.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs nszd5c9.tmp msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs pcappstore.exe watchdog.exe nw_store.exe nw_store.exe nw_store.exe no specs nw_store.exe nw_store.exe no specs nw_store.exe nw_store.exe no specs msiexec.exe no specs setupengine.exe no specs setupengine.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs nw_store.exe no specs nw_store.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setupengine.exe cmd.exe no specs conhost.exe no specs diskspd.exe no specs nw_store.exe no specs msedge.exe no specs msedge.exe no specs fastsrv.exe no specs msedge.exe no specs fast!.exe no specs fast!.exe no specs nw.exe no specs nw.exe no specs nw.exe no specs nw.exe no specs nw.exe no specs nw.exe no specs nw.exe no specs nw.exe no specs nw.exe no specs nw.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1072"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=47 --mojo-platform-channel-handle=3796 --field-trial-handle=2504,i,9561789308929618812,7466463145265273620,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5196 --field-trial-handle=2504,i,9561789308929618812,7466463145265273620,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1224"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6596 --field-trial-handle=2504,i,9561789308929618812,7466463145265273620,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1920"C:\Users\admin\PCAppStore\nwjs\NW_store.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-sandbox --user-data-dir="C:\Users\admin\AppData\Local\pc_app_store\User Data" --nwapp-path=".\ui\." --no-appcompat-clear --start-stack-profiler --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=4648 --field-trial-handle=1960,i,2681952625505735915,11307024420486757233,262144 --variations-seed-version /prefetch:8C:\Users\admin\PCAppStore\nwjs\NW_store.exeNW_store.exe
User:
admin
Company:
The NW.js Community
Integrity Level:
MEDIUM
Description:
nwjs
Exit code:
0
Version:
0.85.0
1948"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=5292 --field-trial-handle=2504,i,9561789308929618812,7466463145265273620,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2064"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=5296 --field-trial-handle=2504,i,9561789308929618812,7466463145265273620,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2192"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://veryfast.io/installing.html?guid=1D1FB0BB-21B9-4FC0-B017-A4DADA231E17&_fcid=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeSetupEngine.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2568"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5684 --field-trial-handle=2504,i,9561789308929618812,7466463145265273620,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2820"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=6908 --field-trial-handle=2504,i,9561789308929618812,7466463145265273620,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
2820"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4896 --field-trial-handle=2504,i,9561789308929618812,7466463145265273620,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Total events
12 156
Read events
12 068
Write events
87
Delete events
1

Modification events

(PID) Process:(6956) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(6956) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\PCAppStore
Operation:writeName:Version
Value:
fa.1091x
(PID) Process:(5992) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(5992) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(5992) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6956) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\PCAppStore
Operation:writeName:InstallPath
Value:
C:\Users\admin\PCAppStore
(PID) Process:(5992) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(5992) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
CDF0108E2B812F00
(PID) Process:(5992) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
31011A8E2B812F00
(PID) Process:(5992) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\656244
Operation:writeName:WindowTabManagerFileMappingId
Value:
{62AE4004-B14E-4295-B715-8A2751864067}
Executable files
52
Suspicious files
845
Text files
451
Unknown types
30

Dropped files

PID
Process
Filename
Type
5992msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1fd6a2.TMP
MD5:
SHA256:
5992msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6956Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_C39E9DBC666D19C07EEE7CD1E11AF8BEbinary
MD5:9EBDDFC26615C7776A8783CA786747FA
SHA256:15468E27AA7E609EA69B5DA328AE719C6514EDFB0581BE15C575A37529D38CFE
5992msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1fd6b2.TMP
MD5:
SHA256:
5992msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1fd6b2.TMP
MD5:
SHA256:
5992msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
5992msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
5992msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF1fd6c1.TMP
MD5:
SHA256:
5992msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
6956Setup.exeC:\Users\admin\AppData\Local\Temp\nsjBB6A.tmp\image.gifimage
MD5:1636218C14C357455B5C872982E2A047
SHA256:9B8B6285BF65F086E08701EEE04E57F2586E973A49C5A38660C9C6502A807045
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
89
TCP/UDP connections
192
DNS requests
179
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAsllCLO2YEqFaBOmVKKDvo%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://status.rapidssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJiUKgT2m88fZ4nxc1Lu6M%2FjvkagQUDNtsgkkPSmcKuBTuesRIUojrVjgCEAJsJgstJqiVbIfWU4Raykw%3D
unknown
whitelisted
6956
Setup.exe
GET
200
95.101.54.131:80
http://e6.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBTUejiAQejpjQc4fOz2ttjyD6VkMQQUDcXM%2FZvuFAWhTDCCpT5eisNYCdICEgQu3y6FDNdivRXuDwAOFB59Tw%3D%3D
unknown
whitelisted
2968
svchost.exe
GET
304
2.23.197.184:80
http://x1.c.lencr.org/
unknown
whitelisted
5028
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7736
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5772
svchost.exe
HEAD
200
217.20.57.18:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/8699fac5-cf38-4f97-a2f8-fb1e47f5e54e?P1=1727399887&P2=404&P3=2&P4=CFHDT%2b%2b4bFWepwQsB%2bvL1sg1jIavav9Giazl1ORLjnVNAGI%2bXZYhskbzs2%2fFcCknMSfjlcXtzSDvHVnPAEXCGQ%3d%3d
unknown
whitelisted
7736
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5772
svchost.exe
GET
206
217.20.57.18:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/8699fac5-cf38-4f97-a2f8-fb1e47f5e54e?P1=1727399887&P2=404&P3=2&P4=CFHDT%2b%2b4bFWepwQsB%2bvL1sg1jIavav9Giazl1ORLjnVNAGI%2bXZYhskbzs2%2fFcCknMSfjlcXtzSDvHVnPAEXCGQ%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5196
svchost.exe
52.167.249.196:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
20.42.73.27:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
104.126.37.139:443
www.bing.com
Akamai International B.V.
DE
whitelisted
52.167.249.196:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2120
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4324
svchost.exe
52.167.249.196:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
167.99.235.203:443
pcapp.store
DIGITALOCEAN-ASN
US
suspicious
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 52.167.249.196
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.174
  • 184.24.77.48
  • 184.24.77.54
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 184.30.21.171
whitelisted
pcapp.store
  • 167.99.235.203
  • 159.223.126.41
  • 104.248.126.225
  • 64.176.203.93
  • 209.222.21.115
  • 45.32.1.23
  • 207.246.91.177
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted
status.rapidssl.com
  • 192.229.221.95
whitelisted
delivery.pcapp.store
  • 195.181.170.18
  • 37.19.194.81
  • 169.150.255.184
  • 212.102.56.179
  • 207.211.211.27
  • 169.150.255.181
  • 195.181.175.41
unknown
e6.o.lencr.org
  • 95.101.54.131
  • 2.16.202.121
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted

Threats

No threats detected
Process
Message
NW_store.exe
[0920/232053.393:ERROR:filesystem_win.cc(128)] GetFileAttributes C:\Users\admin\AppData\Local\pc_app_store\User Data\Crashpad\attachments\6b0b20bb-685b-4e80-a64c-607875c84aa3: The system cannot find the file specified. (0x2)
NW_store.exe
[0920/232053.393:ERROR:filesystem_win.cc(128)] GetFileAttributes C:\Users\admin\AppData\Local\pc_app_store\User Data\Crashpad\attachments\6b0b20bb-685b-4e80-a64c-607875c84aa3: The system cannot find the file specified. (0x2)
NW_store.exe
[0920/232053.408:ERROR:filesystem_win.cc(128)] GetFileAttributes C:\Users\admin\AppData\Local\pc_app_store\User Data\Crashpad\attachments\6b0b20bb-685b-4e80-a64c-607875c84aa3: The system cannot find the file specified. (0x2)