URL:

https://xvpn.io/download

Full analysis: https://app.any.run/tasks/0ad05cbe-7d2d-466e-9a76-721a6148fb65
Verdict: Malicious activity
Analysis date: November 28, 2024, 03:09:22
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
obfuscated-js
Indicators:
MD5:

E22B2B51200DB774B604C998150EC312

SHA1:

C26D3FF7D0BC0C3C9412475BC2AA752E4C19FB88

SHA256:

749A4DA3EDD5D31F2819F894B433DF02B928EA053BA7E1813A9B222B1C6AB451

SSDEEP:

3:N8/hq8M:2JC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • X-VPN_Installer76.4_4450_2b074f54_2024-09-24-11-21-19.exe (PID: 7556)
      • X-VPN.exe (PID: 4392)
      • X-VPN_Installer76.4_4450_2b074f54_2024-09-24-11-21-19.exe (PID: 6628)
  • SUSPICIOUS

    • Creates a software uninstall entry

      • X-VPN_Installer76.4_4450_2b074f54_2024-09-24-11-21-19.exe (PID: 7556)
    • Executable content was dropped or overwritten

      • X-VPN_Installer76.4_4450_2b074f54_2024-09-24-11-21-19.exe (PID: 7556)
      • X-VPN.exe (PID: 4392)
      • pnputil.exe (PID: 1540)
      • drvinst.exe (PID: 7400)
      • drvinst.exe (PID: 7432)
    • Drops a system driver (possible attempt to evade defenses)

      • X-VPN.exe (PID: 4392)
      • pnputil.exe (PID: 1540)
      • drvinst.exe (PID: 7400)
      • drvinst.exe (PID: 7432)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 7400)
    • Connects to unusual port

      • X-VPN.exe (PID: 4392)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • X-VPN_Installer76.4_4450_2b074f54_2024-09-24-11-21-19.exe (PID: 7556)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 7432)
    • Suspicious use of NETSH.EXE

      • tapctl64.exe (PID: 4824)
    • Process uses IPCONFIG to clear DNS cache

      • X-VPN.exe (PID: 4392)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 1668)
    • Reads the computer name

      • identity_helper.exe (PID: 8076)
      • X-VPN_Installer76.4_4450_2b074f54_2024-09-24-11-21-19.exe (PID: 7556)
      • X-VPN.exe (PID: 4392)
      • drvinst.exe (PID: 7432)
    • The process uses the downloaded file

      • msedge.exe (PID: 3992)
    • Reads Environment values

      • identity_helper.exe (PID: 8076)
    • Checks supported languages

      • X-VPN_Installer76.4_4450_2b074f54_2024-09-24-11-21-19.exe (PID: 7556)
      • X-VPN.exe (PID: 4392)
      • drvinst.exe (PID: 7400)
      • openvpn-windows-x86.exe (PID: 4668)
      • tapctl64.exe (PID: 4824)
      • identity_helper.exe (PID: 8076)
    • Reads the machine GUID from the registry

      • X-VPN.exe (PID: 4392)
      • drvinst.exe (PID: 7400)
    • Sends debugging messages

      • X-VPN.exe (PID: 4392)
    • Checks proxy server information

      • X-VPN.exe (PID: 4392)
    • Process checks computer location settings

      • X-VPN.exe (PID: 4392)
    • Reads the software policy settings

      • X-VPN.exe (PID: 4392)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 1668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
178
Monitored processes
46
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs x-vpn_installer76.4_4450_2b074f54_2024-09-24-11-21-19.exe no specs x-vpn_installer76.4_4450_2b074f54_2024-09-24-11-21-19.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs x-vpn.exe openvpn-windows-x86.exe no specs conhost.exe no specs pnputil.exe conhost.exe no specs drvinst.exe tapctl64.exe no specs conhost.exe no specs drvinst.exe netsh.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs ipconfig.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
644\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeipconfig.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1400"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3108 --field-trial-handle=2080,i,2811922916955698889,7597297981810210113,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1540C:\WINDOWS\sysnative\pnputil.exe /add-driver "C:\Program Files (x86)\X-VPN\lib1\oemvista.inf" /installC:\Windows\System32\pnputil.exe
X-VPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft PnP Utility - Tool to add, delete, export, and enumerate driver packages.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\pnputil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\devobj.dll
c:\windows\system32\advapi32.dll
1668"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://xvpn.io/download"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1796netsh interface set interface name="Local Area Connection" newname="x-ovpn-tap"C:\Windows\System32\netsh.exetapctl64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2216"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=30 --mojo-platform-channel-handle=7540 --field-trial-handle=2080,i,2811922916955698889,7597297981810210113,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3992"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=7852 --field-trial-handle=2080,i,2811922916955698889,7597297981810210113,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4392"C:\Program Files (x86)\X-VPN\X-VPN.exe"C:\Program Files (x86)\X-VPN\X-VPN.exe
X-VPN_Installer76.4_4450_2b074f54_2024-09-24-11-21-19.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\program files (x86)\x-vpn\x-vpn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4520\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeopenvpn-windows-x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4668"C:\Program Files (x86)\X-VPN\lib1\openvpn-windows-x86.exe" --versionC:\Program Files (x86)\X-VPN\lib1\openvpn-windows-x86.exeX-VPN.exe
User:
admin
Company:
The OpenVPN Project
Integrity Level:
HIGH
Description:
OpenVPN Daemon
Exit code:
0
Version:
2.6.5.0
Modules
Images
c:\program files (x86)\x-vpn\lib1\openvpn-windows-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
13 753
Read events
13 667
Write events
77
Delete events
9

Modification events

(PID) Process:(1668) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1668) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(1668) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1668) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(1668) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
AF3775B186862F00
(PID) Process:(1668) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328536
Operation:writeName:WindowTabManagerFileMappingId
Value:
{F84D082F-06C1-4543-AB4D-88F44E18B3D2}
(PID) Process:(1668) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
250CDEB186862F00
(PID) Process:(1668) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:MicrosoftEdgeAutoLaunch_29EBC4579851B72EE312C449CF839B1A
Value:
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start
(PID) Process:(1668) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\Commands\on-logon-autolaunch
Operation:writeName:Enabled
Value:
0
(PID) Process:(1668) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328536
Operation:writeName:WindowTabManagerFileMappingId
Value:
{BDFFA0CB-FBAE-4BCD-93E0-E8C6D1638DBE}
Executable files
27
Suspicious files
204
Text files
64
Unknown types
0

Dropped files

PID
Process
Filename
Type
1668msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF135372.TMP
MD5:
SHA256:
1668msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
1668msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF135372.TMP
MD5:
SHA256:
1668msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
1668msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF135382.TMP
MD5:
SHA256:
1668msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
1668msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF135382.TMP
MD5:
SHA256:
1668msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
1668msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF135382.TMP
MD5:
SHA256:
1668msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
412
DNS requests
135
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3220
svchost.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3220
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6792
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7156
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7156
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4392
X-VPN.exe
POST
200
130.211.50.202:20005
http://130.211.50.202:20005/ClientApi
unknown
whitelisted
4392
X-VPN.exe
POST
200
35.205.250.171:20005
http://35.205.250.171:20005/ClientApi
unknown
unknown
4392
X-VPN.exe
POST
200
130.211.50.202:20005
http://130.211.50.202:20005/ClientApi
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
3220
svchost.exe
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
3220
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2.23.209.130:443
www.bing.com
Akamai International B.V.
GB
whitelisted
6416
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
239.255.255.250:1900
whitelisted
6416
msedge.exe
104.26.13.241:443
xvpn.io
whitelisted
6416
msedge.exe
104.21.44.219:443
globalchat1.com
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 216.58.206.78
whitelisted
www.bing.com
  • 2.23.209.130
  • 2.23.209.187
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
xvpn.io
  • 104.26.13.241
  • 172.67.69.206
  • 104.26.12.241
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.45
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted

Threats

PID
Process
Class
Message
4392
X-VPN.exe
Misc activity
ET USER_AGENTS Go HTTP Client User-Agent
4392
X-VPN.exe
Misc activity
ET USER_AGENTS Go HTTP Client User-Agent
4392
X-VPN.exe
Misc activity
ET USER_AGENTS Go HTTP Client User-Agent
Misc activity
ET USER_AGENTS Go HTTP Client User-Agent
4392
X-VPN.exe
Misc activity
ET USER_AGENTS Go HTTP Client User-Agent
4392
X-VPN.exe
Generic Protocol Command Decode
SURICATA DNS Invalid opcode
Process
Message
X-VPN.exe
[1128/031015.500:ERROR:main_delegate.cc(718)] Could not load cef_extensions.pak
X-VPN.exe
[1128/031015.719:WARNING:histograms.cc(40)] Started multiple compositor clients (Browser, Renderer) in one process. Some metrics will be disabled.
X-VPN.exe
[1128/031016.154:INFO:CONSOLE(14)] "vite: loading legacy build because dynamic import is unsupported, syntax error above should be ignored", source: http://127.0.0.1:50001/ (14)
X-VPN.exe
[1128/031016.154:INFO:CONSOLE(1)] "Uncaught SyntaxError: Unexpected token import", source: http://127.0.0.1:50001/assets/index.js (1)
X-VPN.exe
[1128/031016.751:INFO:CONSOLE(1)] "[Update UserInfo]", source: http://127.0.0.1:50001/assets/index-legacy.js (1)