URL:

www.stremio.com

Full analysis: https://app.any.run/tasks/934d6e65-668d-4824-974b-50eb18348d50
Verdict: Malicious activity
Analysis date: February 13, 2026, 20:09:37
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
antivm
nodejs
github
phishing
Indicators:
MD5:

201B21671AD9720B8F8D3D0DC45C623B

SHA1:

C5CC4FAFCCFC7582F2EA3410C176DA5471A0CF99

SHA256:

725021CC299996643C782A5C15E9D030CC5B5D31882BC62894C85FDFBB4784DC

SSDEEP:

3:EPT:cT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • QtWebEngineProcess.exe (PID: 3192)
    • PHISHING has been detected (SURICATA)

      • svchost.exe (PID: 2292)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Stremio+4.4.116.exe (PID: 1824)
    • Executable content was dropped or overwritten

      • Stremio+4.4.116.exe (PID: 1824)
    • Node.exe was dropped

      • Stremio+4.4.116.exe (PID: 1824)
    • The process drops C-runtime libraries

      • Stremio+4.4.116.exe (PID: 1824)
    • The process creates files with name similar to system file names

      • Stremio+4.4.116.exe (PID: 1824)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Stremio+4.4.116.exe (PID: 1824)
    • Executes script using NodeJS

      • node.exe (PID: 9196)
    • Starts POWERSHELL.EXE for commands execution

      • node.exe (PID: 9196)
    • Starts CMD.EXE for commands execution

      • node.exe (PID: 9196)
    • There is functionality for VM detection VMWare (YARA)

      • QtWebEngineProcess.exe (PID: 3192)
      • stremio.exe (PID: 8996)
    • Uses WMIC.EXE to obtain local storage devices information

      • cmd.exe (PID: 876)
  • INFO

    • Drops script file

      • msedge.exe (PID: 5080)
      • msedge.exe (PID: 3656)
      • Stremio+4.4.116.exe (PID: 1824)
      • stremio.exe (PID: 8996)
      • node.exe (PID: 9196)
      • powershell.exe (PID: 7700)
    • Application launched itself

      • msedge.exe (PID: 5080)
    • Checks supported languages

      • identity_helper.exe (PID: 6444)
      • Stremio+4.4.116.exe (PID: 1824)
      • stremio.exe (PID: 8996)
      • QtWebEngineProcess.exe (PID: 3192)
      • node.exe (PID: 9196)
    • Reads the computer name

      • identity_helper.exe (PID: 6444)
      • Stremio+4.4.116.exe (PID: 1824)
      • stremio.exe (PID: 8996)
      • node.exe (PID: 9196)
    • Reads Environment values

      • identity_helper.exe (PID: 6444)
    • The sample compiled with english language support

      • msedge.exe (PID: 5080)
      • Stremio+4.4.116.exe (PID: 1824)
    • Create files in a temporary directory

      • Stremio+4.4.116.exe (PID: 1824)
      • powershell.exe (PID: 7700)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 5080)
    • Creates files or folders in the user directory

      • Stremio+4.4.116.exe (PID: 1824)
      • stremio.exe (PID: 8996)
      • node.exe (PID: 9196)
    • There is functionality for taking screenshot (YARA)

      • Stremio+4.4.116.exe (PID: 1824)
      • stremio.exe (PID: 8996)
      • QtWebEngineProcess.exe (PID: 3192)
    • Checks proxy server information

      • slui.exe (PID: 5484)
      • stremio.exe (PID: 8996)
    • Creates a software uninstall entry

      • Stremio+4.4.116.exe (PID: 1824)
    • Reads the machine GUID from the registry

      • node.exe (PID: 9196)
      • stremio.exe (PID: 8996)
    • Reads security settings of Internet Explorer

      • WMIC.exe (PID: 5600)
      • powershell.exe (PID: 7700)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 7700)
    • Node.js compiler has been detected

      • node.exe (PID: 9196)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
204
Monitored processes
50
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs stremio+4.4.116.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs stremio.exe node.exe conhost.exe no specs qtwebengineprocess.exe no specs powershell.exe no specs cmd.exe no specs wmic.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs #PHISHING svchost.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
876C:\WINDOWS\system32\cmd.exe /d /s /c "wmic logicaldisk where drivetype=3 get caption"C:\Windows\SysWOW64\cmd.exenode.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
936"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=22 --always-read-main-dll --field-trial-handle=7084,i,15324524442657960016,8917840625575629225,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5704 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1044"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2160,i,15324524442657960016,8917840625575629225,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=2516 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1672"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --string-annotations --gpu-preferences=UAAAAAAAAADoAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAABCAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=3636,i,15324524442657960016,8917840625575629225,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=3432 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1688"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6160,i,15324524442657960016,8917840625575629225,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6572 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1824"C:\Users\admin\Downloads\Stremio+4.4.116.exe" C:\Users\admin\Downloads\Stremio+4.4.116.exe
msedge.exe
User:
admin
Company:
Smart Code Ltd
Integrity Level:
MEDIUM
Description:
Stremio 4.4.116 Installer
Exit code:
0
Version:
4.4.116
Modules
Images
c:\users\admin\downloads\stremio+4.4.116.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
2292C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2352"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6664,i,15324524442657960016,8917840625575629225,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6516 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2912"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4288,i,15324524442657960016,8917840625575629225,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=4236 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3168"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5360,i,15324524442657960016,8917840625575629225,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=3608 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
20 874
Read events
20 861
Write events
13
Delete events
0

Modification events

(PID) Process:(1824) Stremio+4.4.116.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Stremio
Operation:writeName:EstimatedSize
Value:
268940
(PID) Process:(1824) Stremio+4.4.116.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Stremio
Operation:writeName:DisplayName
Value:
Stremio
(PID) Process:(1824) Stremio+4.4.116.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Stremio
Operation:writeName:DisplayVersion
Value:
4.4.116
(PID) Process:(1824) Stremio+4.4.116.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Stremio
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\Programs\LNV\Stremio-4\stremio.exe
(PID) Process:(1824) Stremio+4.4.116.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Stremio
Operation:writeName:Publisher
Value:
Smart Code Ltd
(PID) Process:(1824) Stremio+4.4.116.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Stremio
Operation:writeName:UninstallString
Value:
C:\Users\admin\AppData\Local\Programs\LNV\Stremio-4\Uninstall.exe
(PID) Process:(1824) Stremio+4.4.116.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Stremio
Operation:writeName:InstallString
Value:
C:\Users\admin\AppData\Local\Programs\LNV\Stremio-4
(PID) Process:(1824) Stremio+4.4.116.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Stremio
Operation:writeName:URLInfoAbout
Value:
https://www.stremio.com
(PID) Process:(1824) Stremio+4.4.116.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Stremio
Operation:writeName:NoModify
Value:
1
(PID) Process:(1824) Stremio+4.4.116.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Stremio
Operation:writeName:NoRepair
Value:
1
Executable files
88
Suspicious files
748
Text files
948
Unknown types
42

Dropped files

PID
Process
Filename
Type
5080msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1e5021.TMP
MD5:
SHA256:
5080msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1e5021.TMP
MD5:
SHA256:
5080msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
5080msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1e5012.TMP
MD5:
SHA256:
5080msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
5080msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1e5021.TMP
MD5:
SHA256:
5080msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
5080msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
5080msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1e5031.TMP
MD5:
SHA256:
5080msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
170
TCP/UDP connections
227
DNS requests
184
Threats
137

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
unknown
whitelisted
1044
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:RUAb0zEDxzOD1sKOJ5NjZfq4_FKlIa_QcOldhOjebQg&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
1044
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
unknown
text
446 b
whitelisted
1044
msedge.exe
GET
200
104.16.203.97:443
https://www.stremio.com/pure-grid.css
unknown
text
14.6 Kb
unknown
1044
msedge.exe
GET
200
13.107.246.45:443
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appId=edge-extensions&country=US
unknown
binary
82 b
whitelisted
1044
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=66&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0
unknown
text
4.30 Kb
whitelisted
1044
msedge.exe
GET
200
104.16.203.97:443
https://www.stremio.com/
unknown
html
19.9 Kb
unknown
1044
msedge.exe
GET
200
104.18.22.222:443
https://copilot.microsoft.com/c/api/user/eligibility
unknown
binary
25 b
whitelisted
1044
msedge.exe
GET
200
104.16.203.97:443
https://www.stremio.com/js/toasts.js
unknown
text
784 b
unknown
1044
msedge.exe
GET
200
104.16.203.97:443
https://www.stremio.com/icons.css
unknown
text
22.4 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5780
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8964
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
2.16.241.222:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
162.159.142.9:80
ocsp.digicert.com
CLOUDFLARENET
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3412
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1044
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.251.141.78
whitelisted
www.bing.com
  • 13.107.246.44
  • 13.107.213.44
  • 2.16.241.222
  • 2.16.241.207
  • 2.16.241.218
  • 2.16.241.205
  • 184.86.251.9
  • 184.86.251.7
  • 184.86.251.27
  • 95.101.136.201
  • 95.101.136.194
whitelisted
ocsp.digicert.com
  • 162.159.142.9
  • 172.66.2.5
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
self.events.data.microsoft.com
  • 20.189.173.27
  • 51.104.15.252
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
www.stremio.com
  • 104.16.203.97
  • 104.16.204.97
unknown

Threats

PID
Process
Class
Message
1044
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
1044
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
1044
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
1044
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
1044
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
1044
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
1044
msedge.exe
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
8996
stremio.exe
Unknown Traffic
ET JA3 Hash - [Abuse.ch] Possible Adware
8996
stremio.exe
Unknown Traffic
ET JA3 Hash - [Abuse.ch] Possible Adware
8996
stremio.exe
Unknown Traffic
ET JA3 Hash - [Abuse.ch] Possible Adware
Process
Message
stremio.exe
ScreenSaver::retrieveState
stremio.exe
qml: Loading web UI from URL: https://app.strem.io/shell-v4.4/#?loginFlow=desktop
stremio.exe
qml: Stremio Shell version: 4.4.116
stremio.exe
qml: **** Completed. Loading Autoupdater ***
stremio.exe
qml: Auto-updater: checking for new version
stremio.exe
QNetworkReplyHttpImplPrivate::_q_startOperation was called more than once QUrl("https://www.stremio.com/updater/check?serverSum=2909c164de6148f37fe420870cda8e6f8623d30cce6eb3a8314cc1ed2f2e603b&asarSum=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855&shellVersion=4.4.116")
stremio.exe
qml: Auto-updater: up to date