URL:

www.freescrabbledictionary.com

Full analysis: https://app.any.run/tasks/6b259db9-9f17-4140-b9f8-97679b05c6e7
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 24, 2025, 14:35:44
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
autorun-download
stealer
Indicators:
MD5:

F08095DF1A9411421D07E9D12902B200

SHA1:

74E63DE84DF03AFFA51E52D57C5D834DC08E4AC0

SHA256:

67651F19F441B2BD68C42073A24BD04F1E67EECE075B99CF2BDE24391BE83E8C

SSDEEP:

3:E0OtQ4I:xOts

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 5512)
    • Actions looks like stealing of personal data

      • WinZip System Utilities Suite.exe (PID: 5132)
    • Steals credentials from Web Browsers

      • WinZip System Utilities Suite.exe (PID: 5132)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 5512)
      • WinZipSmartMonitorSetup.exe (PID: 6656)
    • Executable content was dropped or overwritten

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 5512)
      • WinZipSmartMonitorSetup.exe (PID: 6656)
      • WinZip System Utilities Suite.exe (PID: 5132)
    • The process drops C-runtime libraries

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 5512)
    • The process creates files with name similar to system file names

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 5512)
      • WinZipSmartMonitorSetup.exe (PID: 6656)
    • Reads security settings of Internet Explorer

      • WinZip System Utilities Suite.exe (PID: 664)
      • WinZip System Utilities Suite.exe (PID: 6736)
      • WinZip System Utilities Suite.exe (PID: 6072)
      • WinZip System Utilities Suite.exe (PID: 2692)
      • WinZip System Utilities Suite.exe (PID: 1532)
      • WinZip System Utilities Suite.exe (PID: 6228)
      • WinZip System Utilities Suite.exe (PID: 5132)
    • Process drops legitimate windows executable

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 5512)
    • Executes as Windows Service

      • WinZip Smart Monitor Service.exe (PID: 7560)
    • Windows service management via SC.EXE

      • sc.exe (PID: 7556)
    • Drops 7-zip archiver for unpacking

      • WinZip System Utilities Suite.exe (PID: 5132)
    • Application launched itself

      • WinZip System Utilities Suite.exe (PID: 5132)
    • Reads Internet Explorer settings

      • WinZip System Utilities Suite.exe (PID: 5132)
    • Detected use of alternative data streams (AltDS)

      • WinZip System Utilities Suite.exe (PID: 5132)
    • Searches for installed software

      • WinZip System Utilities Suite.exe (PID: 5132)
      • Settings.exe (PID: 8972)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 1180)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 5988)
      • BackgroundTransferHost.exe (PID: 4988)
      • BackgroundTransferHost.exe (PID: 5344)
      • BackgroundTransferHost.exe (PID: 3268)
      • BackgroundTransferHost.exe (PID: 1040)
    • Reads the computer name

      • identity_helper.exe (PID: 8048)
      • ShellExperienceHost.exe (PID: 5548)
      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 5512)
      • WinZip System Utilities Suite.exe (PID: 664)
      • WinZip System Utilities Suite.exe (PID: 6072)
      • WinZip System Utilities Suite.exe (PID: 7924)
      • WinZip System Utilities Suite.exe (PID: 2692)
      • Settings.exe (PID: 6404)
      • WinZip System Utilities Suite.exe (PID: 8788)
      • Settings.exe (PID: 8972)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 5988)
      • WinZip System Utilities Suite.exe (PID: 664)
      • WinZip System Utilities Suite.exe (PID: 6736)
      • WinZip System Utilities Suite.exe (PID: 5132)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 1180)
      • msedge.exe (PID: 8356)
    • Create files in a temporary directory

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 5512)
      • WinZipSmartMonitorSetup.exe (PID: 6656)
    • Autorun file from Downloads

      • msedge.exe (PID: 1116)
    • Reads the software policy settings

      • slui.exe (PID: 7996)
      • WinZip System Utilities Suite.exe (PID: 664)
      • WinZip System Utilities Suite.exe (PID: 6736)
      • BackgroundTransferHost.exe (PID: 5988)
      • WinZip System Utilities Suite.exe (PID: 7924)
      • WinZip System Utilities Suite.exe (PID: 6072)
      • WinZip System Utilities Suite.exe (PID: 1532)
      • Settings.exe (PID: 1660)
      • WinZip Smart Monitor Service.exe (PID: 7560)
      • Settings.exe (PID: 6404)
      • WinZip System Utilities Suite.exe (PID: 5132)
      • Settings.exe (PID: 8972)
    • Checks supported languages

      • ShellExperienceHost.exe (PID: 5548)
      • identity_helper.exe (PID: 8048)
      • WinZip System Utilities Suite.exe (PID: 664)
      • WinZip System Utilities Suite.exe (PID: 7924)
      • WinZip System Utilities Suite.exe (PID: 6072)
      • WinZip System Utilities Suite.exe (PID: 1532)
      • Settings.exe (PID: 1660)
      • WinZipSmartMonitor.exe (PID: 7332)
      • WinZip System Utilities Suite.exe (PID: 2692)
    • Reads Environment values

      • identity_helper.exe (PID: 8048)
    • Creates files in the program directory

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 5512)
      • WinZip System Utilities Suite.exe (PID: 6736)
      • WinZip System Utilities Suite.exe (PID: 6072)
      • WinZip System Utilities Suite.exe (PID: 1532)
      • WinZipSmartMonitor.exe (PID: 7332)
      • WinZipSmartMonitorSetup.exe (PID: 6656)
      • WinZip System Utilities Suite.exe (PID: 5132)
      • Settings.exe (PID: 4016)
      • WinZip System Utilities Suite.exe (PID: 6228)
    • The sample compiled with english language support

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 5512)
      • WinZipSmartMonitorSetup.exe (PID: 6656)
      • WinZip System Utilities Suite.exe (PID: 5132)
      • msedge.exe (PID: 8356)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 5988)
      • WinZip System Utilities Suite.exe (PID: 664)
      • WinZip System Utilities Suite.exe (PID: 6736)
      • WinZip System Utilities Suite.exe (PID: 5132)
    • Reads the machine GUID from the registry

      • WinZip System Utilities Suite.exe (PID: 6736)
      • WinZip System Utilities Suite.exe (PID: 6072)
      • WinZip System Utilities Suite.exe (PID: 1532)
      • WinZip System Utilities Suite.exe (PID: 7924)
      • WinZip System Utilities Suite.exe (PID: 664)
      • WinZip System Utilities Suite.exe (PID: 2692)
      • WinZip System Utilities Suite.exe (PID: 6228)
      • WinZip System Utilities Suite.exe (PID: 5132)
      • Settings.exe (PID: 6404)
      • Settings.exe (PID: 8972)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
247
Monitored processes
102
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs sppextcomobj.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe shellexperiencehost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wzsus53.exe no specs wzsus53.exe f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs winzip system utilities suite.exe winzip system utilities suite.exe winzip system utilities suite.exe no specs winzip system utilities suite.exe no specs winzip system utilities suite.exe no specs regsvr32.exe no specs regsvr32.exe no specs winzipsmartmonitorsetup.exe settings.exe msedge.exe no specs winzip smart monitor service.exe no specs winzipsmartmonitor.exe no specs sc.exe no specs conhost.exe no specs winzip smart monitor service.exe winzip system utilities suite.exe no specs settings.exe no specs winzip system utilities suite.exe winzip system utilities suite.exe no specs settings.exe no specs msedge.exe no specs msedge.exe no specs unsecapp.exe no specs winzip system utilities suite.exe no specs settings.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winzip system utilities suite.exe no specs settings.exe no specs settings.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winzipsmartmonitor.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
208"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=9176 --field-trial-handle=2360,i,55041061561940422,2002675108698301739,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
240"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\WinZip System Utilities Suite\windowscontextmenuhandler-vc141-mt.dll"C:\Windows\SysWOW64\regsvr32.exef4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
300C:\WINDOWS\system32\wbem\unsecapp.exe -EmbeddingC:\Windows\System32\wbem\unsecapp.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Sink to receive asynchronous callbacks for WMI client application
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
664"C:\Program Files\WinZip System Utilities Suite\WinZip System Utilities Suite.exe" -helper -client_id "6C280E2E-F00D-48C9-9D6D-654A02B76E17"C:\Program Files\WinZip System Utilities Suite\WinZip System Utilities Suite.exe
f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip System Utilities Suite
Exit code:
0
Version:
4,0,3,4
Modules
Images
c:\program files\winzip system utilities suite\winzip system utilities suite.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msi.dll
c:\windows\system32\gdi32full.dll
1040"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
1116"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=7944 --field-trial-handle=2360,i,55041061561940422,2002675108698301739,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1132 /s "C:\Program Files\WinZip System Utilities Suite\windowscontextmenuhandler-vc141-mt.dll"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1180"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "www.freescrabbledictionary.com"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1532"C:\Program Files\WinZip System Utilities Suite\WinZip System Utilities Suite.exe" -build_id "53" -client_id "6C280E2E-F00D-48C9-9D6D-654A02B76E17"C:\Program Files\WinZip System Utilities Suite\WinZip System Utilities Suite.exef4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip System Utilities Suite
Exit code:
0
Version:
4,0,3,4
Modules
Images
c:\program files\winzip system utilities suite\winzip system utilities suite.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\program files\winzip system utilities suite\qt5svg.dll
c:\program files\winzip system utilities suite\qt5winextras.dll
1568"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=39 --mojo-platform-channel-handle=5600 --field-trial-handle=2360,i,55041061561940422,2002675108698301739,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
82 305
Read events
82 128
Write events
175
Delete events
2

Modification events

(PID) Process:(1180) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1180) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(1180) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1180) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(1180) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
715B1CCEAD8F2F00
(PID) Process:(1180) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
076355CEAD8F2F00
(PID) Process:(1180) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\197458
Operation:writeName:WindowTabManagerFileMappingId
Value:
{3B0D759D-3382-422F-96F8-53D6EBF3B55A}
(PID) Process:(1180) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\197458
Operation:writeName:WindowTabManagerFileMappingId
Value:
{68371E52-E7D1-4702-A4D9-9E216DE17B6C}
(PID) Process:(1180) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\197458
Operation:writeName:WindowTabManagerFileMappingId
Value:
{17CBB415-B2B1-4074-98E2-18E9FE3E2941}
(PID) Process:(1180) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\197458
Operation:writeName:WindowTabManagerFileMappingId
Value:
{4034C8AC-2A88-4791-B7C5-D6BD58F8E951}
Executable files
184
Suspicious files
934
Text files
568
Unknown types
0

Dropped files

PID
Process
Filename
Type
1180msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF10e13a.TMP
MD5:
SHA256:
1180msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
1180msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF10e13a.TMP
MD5:
SHA256:
1180msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
1180msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF10e14a.TMP
MD5:
SHA256:
1180msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
1180msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF10e14a.TMP
MD5:
SHA256:
1180msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
1180msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF10e188.TMP
MD5:
SHA256:
1180msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
42
TCP/UDP connections
208
DNS requests
195
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
23.48.23.191:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
660
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4428
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2644
svchost.exe
HEAD
200
84.201.210.39:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e97d85e8-2e6f-4c6c-8a9a-1d07973733be?P1=1743374363&P2=404&P3=2&P4=GLmT%2f8pb0TkV%2f71vp%2fuxusiMW9mu3RSqvhkrpu5qAVhHA6IX8LcqVurih0v9R7fVDju%2brEgiiGMT2kDLejUTIQ%3d%3d
unknown
whitelisted
4428
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2644
svchost.exe
GET
206
84.201.210.39:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e97d85e8-2e6f-4c6c-8a9a-1d07973733be?P1=1743374363&P2=404&P3=2&P4=GLmT%2f8pb0TkV%2f71vp%2fuxusiMW9mu3RSqvhkrpu5qAVhHA6IX8LcqVurih0v9R7fVDju%2brEgiiGMT2kDLejUTIQ%3d%3d
unknown
whitelisted
2644
svchost.exe
GET
206
84.201.210.39:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e97d85e8-2e6f-4c6c-8a9a-1d07973733be?P1=1743374363&P2=404&P3=2&P4=GLmT%2f8pb0TkV%2f71vp%2fuxusiMW9mu3RSqvhkrpu5qAVhHA6IX8LcqVurih0v9R7fVDju%2brEgiiGMT2kDLejUTIQ%3d%3d
unknown
whitelisted
5988
BackgroundTransferHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2644
svchost.exe
GET
206
84.201.210.39:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e97d85e8-2e6f-4c6c-8a9a-1d07973733be?P1=1743374363&P2=404&P3=2&P4=GLmT%2f8pb0TkV%2f71vp%2fuxusiMW9mu3RSqvhkrpu5qAVhHA6IX8LcqVurih0v9R7fVDju%2brEgiiGMT2kDLejUTIQ%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
23.48.23.191:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
6544
svchost.exe
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1180
msedge.exe
239.255.255.250:1900
whitelisted
7416
msedge.exe
13.107.253.44:443
edge-mobile-static.azureedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7416
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.48.23.191
  • 23.48.23.176
  • 23.48.23.183
  • 23.48.23.169
  • 23.48.23.181
  • 23.48.23.192
  • 23.48.23.193
  • 23.48.23.185
  • 23.48.23.188
  • 23.48.23.140
  • 23.48.23.194
  • 23.48.23.144
  • 23.48.23.139
  • 23.48.23.141
  • 23.48.23.137
  • 23.48.23.195
  • 23.48.23.142
whitelisted
google.com
  • 142.250.185.206
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.31.69
  • 20.190.159.23
  • 20.190.159.64
  • 20.190.159.73
  • 40.126.31.131
  • 20.190.159.0
  • 20.190.159.68
  • 20.190.159.4
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
  • 13.107.21.239
  • 204.79.197.239
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.253.44
whitelisted
www.freescrabbledictionary.com
  • 18.216.189.85
unknown

Threats

PID
Process
Class
Message
7416
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
7416
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
7416
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
7416
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
7416
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
7416
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
7416
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
7416
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
7416
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
7416
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
No debug info