| URL: | 17ebook.co. |
| Full analysis: | https://app.any.run/tasks/572066ba-e989-4d01-9510-831b6d44bc9e |
| Verdict: | Malicious activity |
| Analysis date: | September 01, 2024, 12:30:44 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MD5: | 6835E370335801E2DDC280095E38BFDB |
| SHA1: | D362FBA771851D6E2E4A18DF676A58279CA83780 |
| SHA256: | 643A4F1672D3626DBCCA01B1EEC537B4D789A9C51EF5FC2B6B7C8CBC446C9099 |
| SSDEEP: | 3:LAqKO1:r1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 488 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2732 --field-trial-handle=2452,i,9485789206001939091,6994299480273666855,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 892 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=4312 --field-trial-handle=2452,i,9485789206001939091,6994299480273666855,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 936 | "C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=5704 --field-trial-handle=2452,i,9485789206001939091,6994299480273666855,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: PWA Identity Proxy Host Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1116 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "17ebook.co." | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1224 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3484 --field-trial-handle=2452,i,9485789206001939091,6994299480273666855,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1356 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6392 --field-trial-handle=2452,i,9485789206001939091,6994299480273666855,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1920 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2920 --field-trial-handle=2452,i,9485789206001939091,6994299480273666855,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1992 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6872 --field-trial-handle=2452,i,9485789206001939091,6994299480273666855,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2024 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --no-appcompat-clear --mojo-platform-channel-handle=1384 --field-trial-handle=2452,i,9485789206001939091,6994299480273666855,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2040 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=5228 --field-trial-handle=2452,i,9485789206001939091,6994299480273666855,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (1116) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (1116) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (1116) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (1116) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (1116) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1116) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (1116) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (1116) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge |
| Operation: | write | Name: | UsageStatsInSample |
Value: 1 | |||
| (PID) Process: | (1116) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (1116) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
| Operation: | write | Name: | urlstats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1116 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1299d7.TMP | — | |
MD5:— | SHA256:— | |||
| 1116 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1116 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1299d7.TMP | — | |
MD5:— | SHA256:— | |||
| 1116 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1116 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1299e6.TMP | — | |
MD5:— | SHA256:— | |||
| 1116 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1116 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1299f6.TMP | — | |
MD5:— | SHA256:— | |||
| 1116 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1116 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF1299f6.TMP | — | |
MD5:— | SHA256:— | |||
| 1116 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4976 | msedge.exe | GET | 302 | 103.224.182.243:80 | http://17ebook.co./ | unknown | — | — | whitelisted |
4976 | msedge.exe | GET | 200 | 103.224.182.206:80 | http://pinsid.com/xr.php?e=odR1vGbDAJvVBftYcg2hkH49fms0ODJTMzNDb01zeTAzMzVJODBGQUhOd3dnUzVTeUJVNnVqaGZaU3M3czJ2TU5PalBLS29qWVVLWlR4NVpvRW1Fcm1uaVljbTRRR3pYN2p4d0MvS3o5MFA1V3RObDZPWWZwbFI4Ujg2RW5NRmdjczEweEFFUGNSbGwva2Vra0tzUWFSUjdMQTVXMVVkNEZhWU1BVlFrcEd5Q3h1NWZ1UjZKb3RmVmhEL1dHN2VwREFWMjZkUnQzb2xtQkFlb0tadWJ3bDQ0Um40cjg2anVlYXV4TWVBYUJVcXF3Rm1XdWV1b0RJdjJwdFA2bFk4RzJjamRIM3NFQlYzWjFkVCtkdTJqTE5TOWw0VUczU1VJVTVrNmt6VTZEbDg2c1FIai81NXZNV29LalRFME1ZZ1E4czdVR01wdXNJOGh3TkZTY0FVakpzbi9icC9XS3dRYTc4RW56WDdSSXlMSWNOV2k1RU90NnkrcDBrYXRuYlVsNFN0SnNCR2R4c0J4RXQwQndScVROVGR3NXViZ3JITSs0MGFDdTdoRWlJaWZhV0N2cFhtT3hyK25nRXRNdFZsbDVmUzdmWmNYdE12RDZkNHZXTmVjWjEwSlZDbnFOMUxuL3NlTU8xSGxyZUFaOUlKR2VxRERCcHF0UTkyUmlKQlgxelJvbHBXOStpRVBWNEtoUHFaMVMwejQyOTB4ZDcweDJWWVVkaklBVG94Rm9ZQ3BWRVE3OVVkWk5Cdy82cHJhM3lKSWE0Z1FLMjVRejNyMFc5dEtERlRtdk44L3pRZ1E4c0E3Ujdpb1pERHB6VlVDbldtRHV2b05MZkZCNCt6R3pYNlQyeG5GSEtLMFFLcUNCcHJnNi81dkhJd0RYRWdKUXljSGxQMmlpSHphbGlIZndmeXA0STQ4NS9kS3BmRGNIVk10cjBQNEd5T1RXWHBVcjhYQjlRN29oNlhQU0dPblVGYmpzVnhGenUwZFlBcS8ydW01eWZ4N2VCNzcwWWlYa0NQS3d1Z3JuR1BzeTQ3ZytnWG82VXQzRUd6TG11ejNBdTFqcmJNU0M4TWFtaHQ4YmV5UXp1ZmlBek04YkxkNUVPY0VyU1phU2xxZ3pHMjRaN0hEV1RKOHFhdkY3OFFLbEtFSUI3WUNSYlZKbkVlYm9VeTZsZFcvVStoVnVQNTArOCt6cWpPanA5SXppQkR2em95SUlEaGFFVHBYVzJYL0lwNDhhcU52TGRIUmdhKzZ4bWtnMEkrYzRCTW03QWpndFRBTDI5Q1FQRjJFRDNKUFlBOWFQaFc3ejlLV2JMYThNdy9QWk9Zbm42NFJhVGRLYlQzRGpLQkdJVVlia2M9 | unknown | — | — | unknown |
4976 | msedge.exe | GET | 200 | 103.224.182.206:80 | http://pinsid.com/jscheck.php?enc=Ymf7qjuGt0i%2BXssEEuhJ6X49fjFVc2N6VUtXZmYyKzhpUU5CM2ZmWTduQnlkU0lpdE1zTmhMb2s4VUZJeElqYytIREdJVFNRMGgyTnZOMitkZFI5cGpDTHJ3VTdrcVZyUU4yOVZXbXhISXZPM2loYW93LzBNZ0t2MEt1ZkJ2Q3ozTnRpTDR4dksra2Z5WStoWUdjaHY0QUN3MWpUMmJLKzU0YzN0aW1pSkNkSUsySWhGYVZjZ0NjcWRIbWhBZ0dBZTZJVlJZbWsvblFRUXYvUDR4ZjRHV3hNSG9KYUp5dWZhTWJhallPTEd5STZWQzNwMXdaVVpremxLUFZXL1I4Y3QzZDBIcjFqVWMzSWZMSG1xQ0VPV0RuTmxTeVNYWWVRMDVhUEtpbTQ5RjNZNERnbUJGTGxXdkZwT3A0eWppazJZN083Q0JWTkJ2V3lDUG0xVERzSmUrSVFVVXUwYTlSWGFMdG1jTEVHeWtPLzIzbHY5SFg0R0JBSE1abnMybXROaStnM0NKQ1pjT1N5WmFXZEZwNlh6ZkdLMGN6VHpteEtNZi9kWE5ObnpUMm5rU2o1eUlUdmlETGt4NXcvbUpFYXgwWXRMT2xqd25EWXYreHk5U3JNdElXanpMTTJLQXQ2bC8ySjhpOC8xcE9USkhJQ1h2WHgxQ2tpZ2g0SHY4bGRNMmx2MmdGcWRZR0FrSm52eXA2aUd5UTNRSE9oZTA1VHFoRGpoakJsd3RXUnU1bi9QQXg4VFV1OE10N2ZEZkw0R0dwME9XUWFzZEYzcmM2N29nMTRtTGtXbGZHM1JPbmxnbDRFQkUrRkNhN3dvOTdIa20rOTFOTDJrMkZTWGtwQ3c3MVJ3NXI0cGJBSmorZUFrd1oxdlIzY3JFWEhLc1NlV2d0VG5XdHJqOEM0aDEvN2ZwRDEzYjZTUTVGR3VuNGd2ci96S0RZaHRWQWF1RnB3bFFtazM3YjQ4SXowZmJ4cEhxQkdLY0s0VjFqYTViOW5aSGFrYnVnTUtTTXNvNU9QVmpNRDVBTWEyUGIzaU5CblZjM0V4UGk4SVZ6SlE0RXFIdXRXc2w5N0RyR3RFWWJudlZzZ0pvMExPbmNkMGJDYVlSSEZvQjE4MU05Nlhxc2s5SERzdEtlWU9RNDV3eVBPVTE1YU1wb2paVHZlYUJNRStLdUtDTWZlVG45TWFHTE81MFJqV0hxN05PQzk1Ynk2RDdYZVh5M2I4QlFzRVJFcS9nby9sbnk1M2Q0cGVOaGx1NnNzY2t4NTYrVmlXQ1NBR3JJTmk0T1hTc1RpWDh2dU5QcWpvWWZQZjQ4YVpiK204RTllczlsZi8yQmFlRXNhTzRKVGd6UERaQ1ZFZWtCVUJwdHhLd1RHYXplZWVQL2t4bDdQRmJUS2dIOG5CZjF1RHlGWkRUSWJNQW1sWG9LUUNHcG9LNzN0c1JvdXZvPQ%3D%3D&rand=0.869699194949825&vs=1272:606&ds=1280:720&sl=0:0&os=f&nos=f&if=f&sc=f&gpu=Google%20Inc.%20(Google)%20-%20ANGLE%20(Google,%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE)),%20SwiftShader%20driver)&fp=830d32d1e0315de41ae158f693ec9572 | unknown | — | — | unknown |
4976 | msedge.exe | GET | — | 103.224.182.206:80 | http://pinsid.com/favicon.ico | unknown | — | — | unknown |
4976 | msedge.exe | GET | 302 | 103.224.182.206:80 | http://pinsid.com/r.php?u=https%3A%2F%2Faccomgusa.xyz%2Fclick%3Fkey%3Ded5db6ddce2a7d0cc3f4%26t0%3D0.141%26t1%3D46050372%26t2%3D.de.04.desktop.nonadult.windows.edge%26t3%3Dtt&s=j&enc=Ymf7qjuGt0i%2BXssEEuhJ6X49fjFVc2N6VUtXZmYyKzhpUU5CM2ZmWTduQnlkU0lpdE1zTmhMb2s4VUZJeElqYytIREdJVFNRMGgyTnZOMitkZFI5cGpDTHJ3VTdrcVZyUU4yOVZXbXhISXZPM2loYW93LzBNZ0t2MEt1ZkJ2Q3ozTnRpTDR4dksra2Z5WStoWUdjaHY0QUN3MWpUMmJLKzU0YzN0aW1pSkNkSUsySWhGYVZjZ0NjcWRIbWhBZ0dBZTZJVlJZbWsvblFRUXYvUDR4ZjRHV3hNSG9KYUp5dWZhTWJhallPTEd5STZWQzNwMXdaVVpremxLUFZXL1I4Y3QzZDBIcjFqVWMzSWZMSG1xQ0VPV0RuTmxTeVNYWWVRMDVhUEtpbTQ5RjNZNERnbUJGTGxXdkZwT3A0eWppazJZN083Q0JWTkJ2V3lDUG0xVERzSmUrSVFVVXUwYTlSWGFMdG1jTEVHeWtPLzIzbHY5SFg0R0JBSE1abnMybXROaStnM0NKQ1pjT1N5WmFXZEZwNlh6ZkdLMGN6VHpteEtNZi9kWE5ObnpUMm5rU2o1eUlUdmlETGt4NXcvbUpFYXgwWXRMT2xqd25EWXYreHk5U3JNdElXanpMTTJLQXQ2bC8ySjhpOC8xcE9USkhJQ1h2WHgxQ2tpZ2g0SHY4bGRNMmx2MmdGcWRZR0FrSm52eXA2aUd5UTNRSE9oZTA1VHFoRGpoakJsd3RXUnU1bi9QQXg4VFV1OE10N2ZEZkw0R0dwME9XUWFzZEYzcmM2N29nMTRtTGtXbGZHM1JPbmxnbDRFQkUrRkNhN3dvOTdIa20rOTFOTDJrMkZTWGtwQ3c3MVJ3NXI0cGJBSmorZUFrd1oxdlIzY3JFWEhLc1NlV2d0VG5XdHJqOEM0aDEvN2ZwRDEzYjZTUTVGR3VuNGd2ci96S0RZaHRWQWF1RnB3bFFtazM3YjQ4SXowZmJ4cEhxQkdLY0s0VjFqYTViOW5aSGFrYnVnTUtTTXNvNU9QVmpNRDVBTWEyUGIzaU5CblZjM0V4UGk4SVZ6SlE0RXFIdXRXc2w5N0RyR3RFWWJudlZzZ0pvMExPbmNkMGJDYVlSSEZvQjE4MU05Nlhxc2s5SERzdEtlWU9RNDV3eVBPVTE1YU1wb2paVHZlYUJNRStLdUtDTWZlVG45TWFHTE81MFJqV0hxN05PQzk1Ynk2RDdYZVh5M2I4QlFzRVJFcS9nby9sbnk1M2Q0cGVOaGx1NnNzY2t4NTYrVmlXQ1NBR3JJTmk0T1hTc1RpWDh2dU5QcWpvWWZQZjQ4YVpiK204RTllczlsZi8yQmFlRXNhTzRKVGd6UERaQ1ZFZWtCVUJwdHhLd1RHYXplZWVQL2t4bDdQRmJUS2dIOG5CZjF1RHlGWkRUSWJNQW1sWG9LUUNHcG9LNzN0c1JvdXZvPQ%3D%3D&vs=1272:606&ds=1280:720&sl=0:0&os=f&nos=f&if=f&sc=f&gpu=Google%20Inc.%20(Google)%20-%20ANGLE%20(Google,%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE)),%20SwiftShader%20driver)&fp=830d32d1e0315de41ae158f693ec9572 | unknown | — | — | unknown |
6908 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
8060 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8060 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6880 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6192 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1116 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4976 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4976 | msedge.exe | 13.107.6.158:443 | business.bing.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4976 | msedge.exe | 13.107.246.45:443 | edge-mobile-static.azureedge.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4976 | msedge.exe | 13.107.21.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4976 | msedge.exe | 94.245.104.56:443 | api.edgeoffer.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
edge-mobile-static.azureedge.net |
| whitelisted |
17ebook.co |
| malicious |
api.edgeoffer.microsoft.com |
| whitelisted |
business.bing.com |
| whitelisted |
bzib.nelreports.net |
| whitelisted |
www.bing.com |
| whitelisted |
Process | Message |
|---|---|
msedge.exe | [0901/123110.206:WARNING:device_ticket.cc(151)] Timed out waiting for device ticket. Canceling async operation.
|
msedge.exe | [0901/123110.737:WARNING:pe_image_reader.cc(340)] could not read dos header from C:\WINDOWS\SYSTEM32\dbghelp.dll
|
msedge.exe | [0901/123110.737:ERROR:process_memory_win.cc(74)] ReadMemory at 0x7ffff83c0000 of 64 bytes failed: Only part of a ReadProcessMemory or WriteProcessMemory request was completed. (0x12B)
|
msedge.exe | [0901/123110.737:WARNING:pe_image_reader.cc(340)] could not read dos header from C:\WINDOWS\System32\ws2_32.dll
|
msedge.exe | [0901/123110.737:ERROR:process_memory_win.cc(74)] ReadMemory at 0x7fffe5be0000 of 64 bytes failed: Only part of a ReadProcessMemory or WriteProcessMemory request was completed. (0x12B)
|
msedge.exe | [0901/123110.737:WARNING:pe_image_reader.cc(340)] could not read dos header from C:\WINDOWS\system32\dwrite.dll
|
msedge.exe | [0901/123110.737:ERROR:process_memory_win.cc(74)] ReadMemory at 0x7fffb8350000 of 64 bytes failed: Only part of a ReadProcessMemory or WriteProcessMemory request was completed. (0x12B)
|
msedge.exe | [0901/123110.737:WARNING:pe_image_reader.cc(340)] could not read dos header from C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\ffmpeg.dll
|
msedge.exe | [0901/123110.737:ERROR:process_memory_win.cc(74)] ReadMemory at 0x7ff6278d0000 of 64 bytes failed: Only part of a ReadProcessMemory or WriteProcessMemory request was completed. (0x12B)
|
msedge.exe | [0901/123110.737:WARNING:pe_image_reader.cc(340)] could not read dos header from C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
|