| URL: | https://webex.cisco-eu.com/colibri-am/j.php?MTID=mce2103dcde2faf8747fb810fb688b66c |
| Full analysis: | https://app.any.run/tasks/fd3f026f-aaa4-4276-b306-1f4fb3cd9766 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | February 08, 2026, 00:56:24 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | B0C2B1DFD3BCB0BAEB10609F19D9502E |
| SHA1: | CEB981494B30DE11D437032DD332106F7CBD6D27 |
| SHA256: | 5F34188C23B215C48110E11993596CDD1AFC615F793EEFA6895947FF1B3B4D0C |
| SSDEEP: | 3:N8Rgd5kKdJMZhPOIXENAXudKxd/G:2Wd5k0MjsNAXud+k |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 144 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=1292,i,4617391245915704738,16651543076928763627,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=3912 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 492 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=7156,i,4617391245915704738,16651543076928763627,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=4772 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 1080 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1136 | "C:\Users\admin\AppData\Local\Webex\Discord.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\discord" --field-trial-handle=1720,i,10543399191980447857,17545823309818747003,262144 --enable-features=EnableTransparentHwndEnlargement --disable-features=ScreenAIOCREnabled,SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=1896 /prefetch:3 | C:\Users\admin\AppData\Local\Webex\Discord.exe | — | Discord.exe | |||||||||||
User: admin Company: Discord Inc. Integrity Level: HIGH Description: Discord Version: 1.0.9219 Modules
| |||||||||||||||
| 1692 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --string-annotations --gpu-preferences=UAAAAAAAAADoAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAABCAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=6792,i,4617391245915704738,16651543076928763627,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=6684 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 1836 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1840 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=133.0.6943.127 --initial-client-data=0x21c,0x220,0x224,0x1f8,0x228,0x7ffd700efff8,0x7ffd700f0004,0x7ffd700f0010 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 133.0.6943.127 Modules
| |||||||||||||||
| 1860 | powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "Try { New-Item -Path \"HKLM:\SOFTWARE\Microsoft\Windows Defender Security Center\Notifications\" -Force | Out-Null; New-ItemProperty -Path \"HKLM:\SOFTWARE\Microsoft\Windows Defender Security Center\Notifications\" -Name \"DisableEnhancedNotifications\" -Value 1 -PropertyType DWord -Force | Out-Null } Catch {}" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | Webex for Windows.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1860 | C:\WINDOWS\system32\cmd.exe /d /s /c "net session" | C:\Windows\System32\cmd.exe | — | Discord.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1884 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=5372,i,4617391245915704738,16651543076928763627,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5928 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| (PID) Process: | (5044) Webex for Windows.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Spelling\Dictionaries |
| Operation: | delete value | Name: | en-US |
Value: | |||
| (PID) Process: | (5044) Webex for Windows.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Spelling\Dictionaries |
| Operation: | delete value | Name: | en |
Value: | |||
| (PID) Process: | (5044) Webex for Windows.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Spelling\Dictionaries |
| Operation: | delete value | Name: | _Global_ |
Value: | |||
| (PID) Process: | (1860) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender Security Center\Notifications |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1860) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender Security Center\Notifications |
| Operation: | write | Name: | DisableEnhancedNotifications |
Value: 1 | |||
| (PID) Process: | (9140) Discord.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | electron.app.Discord |
Value: C:\Windows\explorer.exe C:\Users\admin\AppData\Roaming\webex_session\Discord.exe | |||
| (PID) Process: | (9140) Discord.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run |
| Operation: | delete value | Name: | electron.app.Discord |
Value: | |||
| (PID) Process: | (8148) Webex for Windows.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: Webex for Windows.exe | |||
| (PID) Process: | (8148) Webex for Windows.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication |
| Operation: | write | Name: | ID |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 8556 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old~RF1e50cd.TMP | — | |
MD5:— | SHA256:— | |||
| 8556 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 8556 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF1e50dd.TMP | — | |
MD5:— | SHA256:— | |||
| 8556 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 8556 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old~RF1e50ec.TMP | — | |
MD5:— | SHA256:— | |||
| 8556 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 8556 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF1e50ec.TMP | — | |
MD5:— | SHA256:— | |||
| 8556 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF1e50ec.TMP | — | |
MD5:— | SHA256:— | |||
| 8556 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 8556 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF1e50fc.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7832 | chrome.exe | GET | 302 | 172.67.182.140:443 | https://webex.cisco-eu.com/cdn-cgi/challenge-platform/scripts/jsd/main.js | unknown | — | — | unknown |
7832 | chrome.exe | OPTIONS | 200 | 35.190.80.1:443 | https://a.nel.cloudflare.com/report/v4?s=VGvuBO%2F8CgAB1VkmqoKjbcd2bEVlque8LWXru6f1wAicTVNV5VtLdhD5kOLZf%2BLIOdSRZ5hHGX8J0sh9oMCishl6%2FuLmEUMKxipsDFTciMpvWA%3D%3D | unknown | — | — | unknown |
7832 | chrome.exe | GET | 200 | 172.217.16.206:80 | http://clients2.google.com/time/1/current?cup2key=8:TyUXvjOhloRjOMiEyac8VklvmB0QUxcfOM6ulQ8AIyk&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | unknown | — | — | whitelisted |
7832 | chrome.exe | GET | 200 | 142.251.13.94:443 | https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133 | unknown | compressed | 83.6 Kb | whitelisted |
7832 | chrome.exe | POST | 200 | 142.251.127.84:443 | https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard | unknown | text | 17 b | whitelisted |
7832 | chrome.exe | GET | 200 | 172.67.182.140:443 | https://webex.cisco-eu.com/styles/main.css | unknown | text | 128 Kb | unknown |
7832 | chrome.exe | GET | 200 | 172.67.182.140:443 | https://webex.cisco-eu.com/colibri-am/j.php?MTID=mce2103dcde2faf8747fb810fb688b66c | unknown | text | 11.4 Kb | unknown |
7832 | chrome.exe | GET | 200 | 172.67.182.140:443 | https://webex.cisco-eu.com/styles/vendor.css | unknown | text | 22.6 Kb | unknown |
7832 | chrome.exe | GET | 200 | 172.67.182.140:443 | https://webex.cisco-eu.com/wbxmjs/joinservice/sites/colibri-am/meeting/download/cad480a8bb68b015ea04085784e62774?MTID=mce2103dcde2faf8747fb810fb688b66c | unknown | html | 30.3 Kb | unknown |
7832 | chrome.exe | GET | 200 | 172.67.182.140:443 | https://webex.cisco-eu.com/styles/components.css | unknown | text | 128 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6768 | MoUsoCoreWorker.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
3344 | svchost.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5512 | RUXIMICS.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7832 | chrome.exe | 172.217.16.206:80 | clients2.google.com | GOOGLE | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
7832 | chrome.exe | 172.217.16.170:443 | safebrowsingohttpgateway.googleapis.com | GOOGLE | US | whitelisted |
7832 | chrome.exe | 142.251.13.94:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
7832 | chrome.exe | 142.251.127.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
7832 | chrome.exe | 172.67.182.140:443 | webex.cisco-eu.com | CLOUDFLARENET | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
self.events.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
clients2.google.com |
| whitelisted |
safebrowsingohttpgateway.googleapis.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
webex.cisco-eu.com |
| unknown |
accounts.google.com |
| whitelisted |
api.cisco-eu.com |
| unknown |
a.nel.cloudflare.com |
| whitelisted |
mediu.webex.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
7832 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
7832 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
3344 | svchost.exe | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
7832 | chrome.exe | Misc activity | ET INFO DropBox User Content Domain (dl .dropboxusercontent .com in TLS SNI) |
5728 | Webex for Windows.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
5728 | Webex for Windows.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
7832 | chrome.exe | Potentially Bad Traffic | ET INFO PE EXE or DLL Windows file download HTTP |
7832 | chrome.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Online Pastebin Text Storage |
Process | Message |
|---|---|
Webex for Windows.exe | [5044:0207/195659.436:INFO:CONSOLE(2)] "TypeError: ipcRenderer.handle is not a function", source: node:electron/js2c/renderer_init (2)
|
Webex for Windows.exe | [5044:0207/195659.436:INFO:CONSOLE(2)] "Unable to load preload script: C:\Users\admin\AppData\Local\Temp\38iRQBT4lzi02T9GKmI19dr36U7\resources\app.asar\preload.entry.js", source: node:electron/js2c/renderer_init (2)
|
Webex for Windows.exe | [5044:0207/195659.662:INFO:CONSOLE(25)] "[2026-02-08T00:56:59.661Z] [RENDERER][DEBUG] Renderer bootstrapped [object Object]", source: file:///C:/Users/admin/AppData/Local/Temp/38iRQBT4lzi02T9GKmI19dr36U7/resources/app.asar/renderer.js (25)
|
Webex for Windows.exe | [5044:0207/195659.663:INFO:CONSOLE(25)] "[2026-02-08T00:56:59.662Z] [RENDERER][DEBUG] initializeDefaultPath invoked", source: file:///C:/Users/admin/AppData/Local/Temp/38iRQBT4lzi02T9GKmI19dr36U7/resources/app.asar/renderer.js (25)
|
Webex for Windows.exe | [5044:0207/195659.665:INFO:CONSOLE(25)] "[2026-02-08T00:56:59.664Z] [RENDERER][DEBUG] Received appDataPath from main C:\Users\admin\AppData\Local", source: file:///C:/Users/admin/AppData/Local/Temp/38iRQBT4lzi02T9GKmI19dr36U7/resources/app.asar/renderer.js (25)
|
Webex for Windows.exe | [5044:0207/195659.665:INFO:CONSOLE(25)] "[2026-02-08T00:56:59.664Z] [RENDERER][DEBUG] Settings path input populated C:\Users\admin\AppData\Local\Webex", source: file:///C:/Users/admin/AppData/Local/Temp/38iRQBT4lzi02T9GKmI19dr36U7/resources/app.asar/renderer.js (25)
|
Webex for Windows.exe | [5044:0207/195659.765:INFO:CONSOLE(25)] "[2026-02-08T00:56:59.765Z] [RENDERER][DEBUG] Loading initial lottie animation cloud.json", source: file:///C:/Users/admin/AppData/Local/Temp/38iRQBT4lzi02T9GKmI19dr36U7/resources/app.asar/renderer.js (25)
|
Webex for Windows.exe | [5044:0207/195659.766:INFO:CONSOLE(25)] "[2026-02-08T00:56:59.765Z] [RENDERER][DEBUG] loadLottieAnimation invoked cloud.json", source: file:///C:/Users/admin/AppData/Local/Temp/38iRQBT4lzi02T9GKmI19dr36U7/resources/app.asar/renderer.js (25)
|
Webex for Windows.exe | [5044:0207/195700.170:INFO:CONSOLE(25)] "[2026-02-08T00:57:00.169Z] [RENDERER][DEBUG] checkWebView2Runtime invoked", source: file:///C:/Users/admin/AppData/Local/Temp/38iRQBT4lzi02T9GKmI19dr36U7/resources/app.asar/renderer.js (25)
|
Webex for Windows.exe | [5044:0207/195700.172:INFO:CONSOLE(25)] "[2026-02-08T00:57:00.171Z] [RENDERER][DEBUG] WebView2 runtime status true", source: file:///C:/Users/admin/AppData/Local/Temp/38iRQBT4lzi02T9GKmI19dr36U7/resources/app.asar/renderer.js (25)
|