URL:

https://install.printanistall.net/eci-dca/H58LENZF629S?brand=PrintanistaCompact#windows

Full analysis: https://app.any.run/tasks/788c5898-60dc-47b2-8176-9035ec65077b
Verdict: Malicious activity
Analysis date: May 27, 2025, 10:52:08
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
crypto-regex
Indicators:
MD5:

CA8F0E9080DC7FD895D329410F737BE4

SHA1:

1DE1887944666EF485B21E0F25A3B56FA4EC523D

SHA256:

697F89FC9553964C2C40941310A0A1F8EAC9F1E82FE4FD4571A9E47158297918

SSDEEP:

3:N8LREJF9MliMWirAIxSslXiuYvWiuvRFKK:2lgPMUXih4sNkOioKK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 5428)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 3032)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 7932)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 2192)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 6760)
    • Reads the Windows owner or organization settings

      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
    • Uses TASKKILL.EXE to kill process

      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
    • Process drops legitimate windows executable

      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
    • Reads security settings of Internet Explorer

      • DCA.Edge.Console.exe (PID: 1196)
      • DCA.Edge.Console.exe (PID: 7700)
      • DCA.Edge.Console.exe (PID: 536)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 6656)
    • Restarts service on failure

      • sc.exe (PID: 5720)
    • Creates a new Windows service

      • sc.exe (PID: 2136)
    • Executes as Windows Service

      • DCA.Edge.Console.exe (PID: 536)
    • There is functionality for taking screenshot (YARA)

      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 2192)
    • Found regular expressions for crypto-addresses (YARA)

      • DCA.Edge.Console.exe (PID: 536)
      • DCA.Edge.TrayIcon.exe (PID: 7508)
      • DCA.Edge.TrayIcon.exe (PID: 7688)
    • Process uses IPCONFIG to get network configuration information

      • cmd.exe (PID: 240)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 7420)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 5428)
      • DCA.Edge.Console.exe (PID: 1196)
      • DCA.Edge.TrayIcon.exe (PID: 7688)
      • DCA.Edge.Console.exe (PID: 536)
      • DCA.Edge.Console.exe (PID: 7700)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 6760)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 6656)
    • Application launched itself

      • msedge.exe (PID: 7052)
    • Create files in a temporary directory

      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 5428)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 6760)
    • Process checks computer location settings

      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 6656)
    • Reads the computer name

      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
      • identity_helper.exe (PID: 7420)
      • DCA.Edge.Console.exe (PID: 1196)
      • DCA.Edge.TrayIcon.exe (PID: 7688)
      • DCA.Edge.Console.exe (PID: 7700)
      • DCA.Edge.Console.exe (PID: 536)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 6656)
    • Reads Environment values

      • identity_helper.exe (PID: 7420)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 3968)
      • msedge.exe (PID: 7052)
      • msedge.exe (PID: 7100)
    • Launch of the file from Downloads directory

      • msedge.exe (PID: 7052)
      • msedge.exe (PID: 7940)
    • Compiled with Borland Delphi (YARA)

      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 6760)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 6656)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 5428)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 3032)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 4964)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 7932)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 2192)
    • Detects InnoSetup installer (YARA)

      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 6656)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 6760)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 5428)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 3032)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 4964)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 7932)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 2192)
    • Creates files in the program directory

      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
      • DCA.Edge.Console.exe (PID: 1196)
    • Reads the machine GUID from the registry

      • DCA.Edge.Console.exe (PID: 1196)
      • DCA.Edge.Console.exe (PID: 536)
      • DCA.Edge.TrayIcon.exe (PID: 7688)
      • DCA.Edge.Console.exe (PID: 7700)
    • Reads the software policy settings

      • DCA.Edge.Console.exe (PID: 1196)
      • DCA.Edge.Console.exe (PID: 7700)
      • DCA.Edge.Console.exe (PID: 536)
    • Launch of the file from Startup directory

      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
    • Creates a software uninstall entry

      • ECI DCA 1.5.12.10306 [H58LENZF629S].tmp (PID: 7568)
    • The sample compiled with english language support

      • msedge.exe (PID: 7100)
    • Manual execution by a user

      • cmd.exe (PID: 240)
      • ECI DCA 1.5.12.10306 [H58LENZF629S].exe (PID: 3032)
      • DCA.Edge.TrayIcon.exe (PID: 7508)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
236
Monitored processes
92
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs sppextcomobj.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs eci dca 1.5.12.10306 [h58lenzf629s].exe eci dca 1.5.12.10306 [h58lenzf629s].tmp no specs eci dca 1.5.12.10306 [h58lenzf629s].exe eci dca 1.5.12.10306 [h58lenzf629s].tmp msedge.exe no specs msedge.exe no specs msedge.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs dca.edge.console.exe no specs conhost.exe no specs sc.exe no specs sc.exe no specs dca.edge.trayicon.exe no specs dca.edge.console.exe no specs conhost.exe no specs dca.edge.console.exe msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs dca.edge.trayicon.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe cmd.exe no specs conhost.exe no specs ipconfig.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs rundll32.exe no specs msedge.exe no specs eci dca 1.5.12.10306 [h58lenzf629s].exe eci dca 1.5.12.10306 [h58lenzf629s].tmp no specs eci dca 1.5.12.10306 [h58lenzf629s].exe eci dca 1.5.12.10306 [h58lenzf629s].tmp msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\WINDOWS\system32\cmd.exe" C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\wldp.dll
536"C:\Program Files (x86)\ECI DCA\DCA.Edge.Console.exe" --config "C:\ProgramData\ECI DCA\dca.config"C:\Program Files (x86)\ECI DCA\DCA.Edge.Console.exe
services.exe
User:
SYSTEM
Company:
ECI Software Solutions, Inc
Integrity Level:
SYSTEM
Description:
ECI DCA
Version:
1.5.12.10306
Modules
Images
c:\program files (x86)\eci dca\dca.edge.console.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
616"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2356 --field-trial-handle=2360,i,10046841225514517243,11449951909296415753,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1180"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=1668 --field-trial-handle=2360,i,10046841225514517243,11449951909296415753,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1196"C:\Program Files (x86)\ECI DCA\DCA.Edge.Console.exe" config --config "C:\ProgramData\ECI DCA\dca.config" --installer "C:\Users\admin\Downloads\ECI DCA 1.5.12.10306 [H58LENZF629S].exe" --install-service C:\Program Files (x86)\ECI DCA\DCA.Edge.Console.exeECI DCA 1.5.12.10306 [H58LENZF629S].tmp
User:
admin
Company:
ECI Software Solutions, Inc
Integrity Level:
HIGH
Description:
ECI DCA
Exit code:
0
Version:
1.5.12.10306
Modules
Images
c:\program files (x86)\eci dca\dca.edge.console.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1272"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=8048 --field-trial-handle=2360,i,10046841225514517243,11449951909296415753,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2136"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5536 --field-trial-handle=2360,i,10046841225514517243,11449951909296415753,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2136"C:\WINDOWS\system32\sc.exe" create "DCAPulse" start= delayed-auto DisplayName= "ECI DCA" binPath= "\"C:\Program Files (x86)\ECI DCA\DCA.Edge.Console.exe\" --config \"C:\ProgramData\ECI DCA\dca.config\"" C:\Windows\SysWOW64\sc.exeDCA.Edge.Console.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2192"C:\Users\admin\AppData\Local\Temp\is-CI9L1.tmp\ECI DCA 1.5.12.10306 [H58LENZF629S].tmp" /SL5="$3036C,3501329,428032,C:\Users\admin\Downloads\ECI DCA 1.5.12.10306 [H58LENZF629S].exe" /SPAWNWND=$1037E /NOTIFYWND=$20372 C:\Users\admin\AppData\Local\Temp\is-CI9L1.tmp\ECI DCA 1.5.12.10306 [H58LENZF629S].tmp
ECI DCA 1.5.12.10306 [H58LENZF629S].exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ci9l1.tmp\eci dca 1.5.12.10306 [h58lenzf629s].tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2244"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=3912 --field-trial-handle=2360,i,10046841225514517243,11449951909296415753,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
34 446
Read events
34 380
Write events
66
Delete events
0

Modification events

(PID) Process:(7052) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
0CA1E023B2942F00
(PID) Process:(6852) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6852) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6852) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6852) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(6852) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(6852) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:DisableFirstRunCustomize
Value:
1
(PID) Process:(7052) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(7052) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(7052) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
Executable files
107
Suspicious files
376
Text files
115
Unknown types
51

Dropped files

PID
Process
Filename
Type
7052msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF10a79c.TMP
MD5:
SHA256:
7052msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7052msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF10a79c.TMP
MD5:
SHA256:
7052msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
7052msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF10a809.TMP
MD5:
SHA256:
7052msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
7052msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF10a809.TMP
MD5:
SHA256:
7052msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7052msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF10a848.TMP
MD5:
SHA256:
7052msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
83
DNS requests
99
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7052
msedge.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
7052
msedge.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
7052
msedge.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA8cHCF8NlPTdgv23R4%2Fs7Y%3D
unknown
whitelisted
7288
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7288
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
536
DCA.Edge.Console.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
536
DCA.Edge.Console.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
536
DCA.Edge.Console.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA8cHCF8NlPTdgv23R4%2Fs7Y%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5756
RUXIMICS.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5796
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3968
msedge.exe
13.107.43.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3968
msedge.exe
13.107.253.45:443
edge-mobile-static.azureedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3968
msedge.exe
13.107.6.158:443
business.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7052
msedge.exe
239.255.255.250:1900
whitelisted
3968
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
install.printanistall.net
unknown
config.edge.skype.com
  • 13.107.43.16
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.253.45
whitelisted
google.com
  • 216.58.212.142
  • 142.250.185.174
whitelisted
update.googleapis.com
  • 142.250.185.195
whitelisted
edgeservices.bing.com
  • 92.123.104.12
  • 92.123.104.62
  • 92.123.104.63
  • 92.123.104.67
  • 92.123.104.65
  • 92.123.104.13
  • 92.123.104.10
  • 92.123.104.66
  • 92.123.104.5
whitelisted
edgeassetservice.azureedge.net
  • 13.107.253.45
whitelisted
www.bing.com
  • 92.123.104.12
  • 92.123.104.62
  • 92.123.104.63
  • 92.123.104.67
  • 92.123.104.65
  • 92.123.104.13
  • 92.123.104.10
  • 92.123.104.66
  • 92.123.104.5
  • 2.16.241.201
  • 2.16.241.219
  • 2.16.241.211
  • 2.16.241.218
  • 2.16.241.206
  • 2.16.241.216
  • 2.16.241.224
  • 2.16.241.222
  • 2.16.241.213
  • 2.23.227.215
  • 2.23.227.208
whitelisted

Threats

No threats detected
No debug info