URL:

https://www.badlion.net/

Full analysis: https://app.any.run/tasks/c5fba8ac-0698-4153-b296-ee4d9f96d4aa
Verdict: Malicious activity
Analysis date: January 24, 2025, 22:02:05
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

B168DF3B4DAC97E0A3A3E0AFFF05BF63

SHA1:

EFA15204ADDB3EEBE8CFD10C8D2B62ED80BFA56D

SHA256:

6B0EABAD69843F39621ABC338B18100947E218B38593C587A0E8BB73E11F8611

SSDEEP:

3:N8DSLkj/0RKn:2OLk7Xn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Badlion Client.exe (PID: 2084)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • Badlion Client Setup 4.5.1.exe (PID: 5880)
    • The process creates files with name similar to system file names

      • Badlion Client Setup 4.5.1.exe (PID: 5880)
    • Drops 7-zip archiver for unpacking

      • Badlion Client Setup 4.5.1.exe (PID: 5880)
    • Reads security settings of Internet Explorer

      • Badlion Client Setup 4.5.1.exe (PID: 5880)
      • Badlion Client.exe (PID: 2084)
    • Executable content was dropped or overwritten

      • Badlion Client Setup 4.5.1.exe (PID: 5880)
      • Badlion Client.exe (PID: 2084)
    • Process drops legitimate windows executable

      • Badlion Client Setup 4.5.1.exe (PID: 5880)
      • Badlion Client.exe (PID: 2084)
    • Creates a software uninstall entry

      • Badlion Client Setup 4.5.1.exe (PID: 5880)
    • The process drops C-runtime libraries

      • Badlion Client Setup 4.5.1.exe (PID: 5880)
      • Badlion Client.exe (PID: 2084)
    • Application launched itself

      • Badlion Client.exe (PID: 7496)
    • Checks Windows Trust Settings

      • Badlion Client.exe (PID: 2084)
  • INFO

    • Reads the computer name

      • identity_helper.exe (PID: 8092)
      • Badlion Client Setup 4.5.1.exe (PID: 5880)
      • Badlion Client.exe (PID: 7496)
      • Badlion Client.exe (PID: 5004)
      • Badlion Client.exe (PID: 1512)
      • Badlion Client.exe (PID: 2084)
      • Badlion Client.exe (PID: 2424)
    • Reads Environment values

      • identity_helper.exe (PID: 8092)
      • Badlion Client.exe (PID: 7496)
      • Badlion Client.exe (PID: 2084)
      • Badlion Client.exe (PID: 8120)
      • Badlion Client.exe (PID: 7516)
      • Badlion Client.exe (PID: 7344)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 6184)
    • Checks supported languages

      • identity_helper.exe (PID: 8092)
      • Badlion Client Setup 4.5.1.exe (PID: 5880)
      • Badlion Client.exe (PID: 7496)
      • Badlion Client.exe (PID: 1512)
      • Badlion Client.exe (PID: 2084)
      • Badlion Client.exe (PID: 5004)
      • Badlion Client.exe (PID: 8120)
      • Badlion Client.exe (PID: 7516)
      • Badlion Client.exe (PID: 7344)
      • Badlion Client.exe (PID: 2424)
    • The sample compiled with english language support

      • Badlion Client Setup 4.5.1.exe (PID: 5880)
      • Badlion Client.exe (PID: 2084)
    • Create files in a temporary directory

      • Badlion Client Setup 4.5.1.exe (PID: 5880)
      • Badlion Client.exe (PID: 7496)
    • Creates files or folders in the user directory

      • Badlion Client Setup 4.5.1.exe (PID: 5880)
      • Badlion Client.exe (PID: 7496)
      • Badlion Client.exe (PID: 2084)
      • Badlion Client.exe (PID: 8120)
      • Badlion Client.exe (PID: 5004)
    • Manual execution by a user

      • Badlion Client.exe (PID: 7496)
    • Application launched itself

      • msedge.exe (PID: 6184)
    • Reads product name

      • Badlion Client.exe (PID: 7496)
      • Badlion Client.exe (PID: 2084)
      • Badlion Client.exe (PID: 8120)
      • Badlion Client.exe (PID: 7516)
      • Badlion Client.exe (PID: 7344)
    • Process checks computer location settings

      • Badlion Client.exe (PID: 7496)
      • Badlion Client.exe (PID: 2084)
      • Badlion Client.exe (PID: 8120)
      • Badlion Client.exe (PID: 7344)
      • Badlion Client.exe (PID: 7516)
    • Checks proxy server information

      • Badlion Client.exe (PID: 7496)
      • Badlion Client.exe (PID: 2084)
    • Reads the machine GUID from the registry

      • Badlion Client.exe (PID: 7496)
      • Badlion Client.exe (PID: 2084)
    • Reads the software policy settings

      • Badlion Client.exe (PID: 2084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
201
Monitored processes
67
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start iexplore.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs badlion client setup 4.5.1.exe msedge.exe no specs msedge.exe no specs badlion client.exe no specs msedge.exe no specs badlion client.exe badlion client.exe no specs badlion client.exe badlion client.exe no specs badlion client.exe no specs badlion client.exe no specs badlion client.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1448"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=1556 --field-trial-handle=2372,i,580974746772218482,1031197570519190228,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1512"C:\Users\admin\AppData\Local\Programs\Badlion Client\Badlion Client.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\Badlion Client" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --field-trial-handle=1960,i,11024492966844094766,16728543098075018517,262144 --enable-features=kWebSQLAccess --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --variations-seed-version --mojo-platform-channel-handle=1952 /prefetch:2C:\Users\admin\AppData\Local\Programs\Badlion Client\Badlion Client.exeBadlion Client.exe
User:
admin
Company:
Badlion
Integrity Level:
LOW
Description:
Badlion Client
Version:
4.5.1
Modules
Images
c:\users\admin\appdata\local\programs\badlion client\badlion client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1576"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=1452 --field-trial-handle=2372,i,580974746772218482,1031197570519190228,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2072"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.badlion.net/"C:\Program Files\Internet Explorer\iexplore.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2084"C:\Users\admin\AppData\Local\Programs\Badlion Client\Badlion Client.exe" "C:\Users\admin\AppData\Local\Programs\Badlion Client\resources\app.asar\app\child-process.js"C:\Users\admin\AppData\Local\Programs\Badlion Client\Badlion Client.exe
Badlion Client.exe
User:
admin
Company:
Badlion
Integrity Level:
MEDIUM
Description:
Badlion Client
Version:
4.5.1
Modules
Images
c:\users\admin\appdata\local\programs\badlion client\badlion client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\programs\badlion client\ffmpeg.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2132"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=8816 --field-trial-handle=2372,i,580974746772218482,1031197570519190228,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2424"C:\Users\admin\AppData\Local\Programs\Badlion Client\Badlion Client.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --user-data-dir="C:\Users\admin\AppData\Roaming\Badlion Client" --field-trial-handle=3964,i,11024492966844094766,16728543098075018517,262144 --enable-features=kWebSQLAccess --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --variations-seed-version --mojo-platform-channel-handle=3960 /prefetch:8C:\Users\admin\AppData\Local\Programs\Badlion Client\Badlion Client.exeBadlion Client.exe
User:
admin
Company:
Badlion
Integrity Level:
LOW
Description:
Badlion Client
Version:
4.5.1
Modules
Images
c:\users\admin\appdata\local\programs\badlion client\badlion client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2992"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=6988 --field-trial-handle=2372,i,580974746772218482,1031197570519190228,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3172"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=5404 --field-trial-handle=2372,i,580974746772218482,1031197570519190228,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3832"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=52 --mojo-platform-channel-handle=5708 --field-trial-handle=2372,i,580974746772218482,1031197570519190228,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
21 557
Read events
21 391
Write events
146
Delete events
20

Modification events

(PID) Process:(6184) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6184) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6184) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6184) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6184) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
4F168429118B2F00
(PID) Process:(2072) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2072) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2072) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2072) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2072) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
Executable files
452
Suspicious files
1 112
Text files
322
Unknown types
0

Dropped files

PID
Process
Filename
Type
6184msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF13664f.TMP
MD5:
SHA256:
6184msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6184msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF13665e.TMP
MD5:
SHA256:
6184msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6184msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF13666e.TMP
MD5:
SHA256:
6184msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF13666e.TMP
MD5:
SHA256:
6184msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6184msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6184msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF13667d.TMP
MD5:
SHA256:
6184msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
208
DNS requests
235
Threats
18

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.169:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3220
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1944
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1944
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7980
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
304
2.23.197.184:80
http://x1.i.lencr.org/
unknown
whitelisted
6424
msedge.exe
GET
304
23.209.209.135:80
http://r3.i.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.169:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3220
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.21.65.132:443
www.bing.com
Akamai International B.V.
NL
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6424
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6184
msedge.exe
239.255.255.250:1900
whitelisted
6424
msedge.exe
104.16.148.116:443
www.badlion.net
CLOUDFLARENET
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.48.23.169
  • 23.48.23.166
  • 23.48.23.164
  • 23.48.23.137
  • 23.48.23.194
  • 23.48.23.162
  • 23.48.23.193
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 2.23.246.101
whitelisted
www.bing.com
  • 2.21.65.132
  • 2.21.65.154
  • 104.126.37.162
  • 104.126.37.139
  • 104.126.37.144
  • 104.126.37.130
  • 104.126.37.152
  • 104.126.37.145
  • 104.126.37.146
  • 104.126.37.153
  • 104.126.37.137
  • 2.23.227.215
  • 2.23.227.208
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
google.com
  • 142.250.186.174
whitelisted
www.badlion.net
  • 104.16.148.116
  • 104.16.147.116
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted

Threats

PID
Process
Class
Message
6424
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
6424
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
6424
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
6424
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
5004
Badlion Client.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
5004
Badlion Client.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
5004
Badlion Client.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
5004
Badlion Client.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
5004
Badlion Client.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
5004
Badlion Client.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info