URL:

https://www.zen-browser.app/

Full analysis: https://app.any.run/tasks/0365d14b-4777-4d74-9036-25cad0ea4cbb
Verdict: Malicious activity
Analysis date: August 24, 2024, 11:51:43
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MD5:

779EE76CF002D25B05086391A07B3778

SHA1:

741A5B316FE15F12BCB348CDF870E90F15623545

SHA256:

7DEC4B56424E2F2BA9197FEBD3518AF322C61F729423691CD097089F237C5A77

SSDEEP:

3:N8DSLo83tXwCn:2OLoigC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • setup.exe (PID: 4068)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • zen.installer.exe (PID: 2340)
      • setup.exe (PID: 4068)
    • Executable content was dropped or overwritten

      • zen.installer.exe (PID: 2340)
      • setup.exe (PID: 1944)
      • setup.exe (PID: 4068)
      • zen.exe (PID: 3916)
    • Drops the executable file immediately after the start

      • zen.installer.exe (PID: 2340)
      • setup.exe (PID: 1944)
      • setup.exe (PID: 4068)
      • zen.exe (PID: 3916)
    • The process drops C-runtime libraries

      • zen.installer.exe (PID: 2340)
      • setup.exe (PID: 4068)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 1944)
      • setup.exe (PID: 4068)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • setup.exe (PID: 1944)
      • setup.exe (PID: 4068)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 1944)
      • setup.exe (PID: 4068)
      • zen.exe (PID: 3916)
    • Reads the date of Windows installation

      • setup.exe (PID: 1944)
    • Application launched itself

      • setup.exe (PID: 1944)
      • zen.exe (PID: 4880)
      • zen.exe (PID: 2572)
      • zen.exe (PID: 3916)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 6348)
    • Searches for installed software

      • setup.exe (PID: 4068)
    • Creates a software uninstall entry

      • setup.exe (PID: 4068)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 6596)
    • Reads the computer name

      • zen.installer.exe (PID: 2340)
      • setup.exe (PID: 1944)
      • setup.exe (PID: 4068)
      • zen.exe (PID: 3916)
      • zen.exe (PID: 6496)
      • zen.exe (PID: 4056)
      • zen.exe (PID: 5704)
      • zen.exe (PID: 6908)
      • zen.exe (PID: 7152)
      • zen.exe (PID: 7092)
      • zen.exe (PID: 6248)
      • zen.exe (PID: 3900)
      • zen.exe (PID: 6268)
      • zen.exe (PID: 7076)
      • zen.exe (PID: 6228)
      • zen.exe (PID: 3004)
      • zen.exe (PID: 6304)
      • zen.exe (PID: 4168)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 6596)
    • Reads Microsoft Office registry keys

      • chrome.exe (PID: 6596)
      • setup.exe (PID: 4068)
      • zen.exe (PID: 3916)
    • Checks supported languages

      • zen.installer.exe (PID: 2340)
      • setup.exe (PID: 1944)
      • setup.exe (PID: 4068)
      • zen.exe (PID: 4880)
      • zen.exe (PID: 5704)
      • zen.exe (PID: 2572)
      • zen.exe (PID: 3916)
      • zen.exe (PID: 6496)
      • zen.exe (PID: 4056)
      • zen.exe (PID: 7076)
      • zen.exe (PID: 7152)
      • zen.exe (PID: 7092)
      • zen.exe (PID: 3900)
      • zen.exe (PID: 6908)
      • zen.exe (PID: 6248)
      • zen.exe (PID: 6268)
      • zen.exe (PID: 6304)
      • zen.exe (PID: 3004)
      • zen.exe (PID: 4168)
      • zen.exe (PID: 6228)
    • Create files in a temporary directory

      • zen.installer.exe (PID: 2340)
      • setup.exe (PID: 1944)
      • setup.exe (PID: 4068)
      • zen.exe (PID: 5704)
      • zen.exe (PID: 3916)
    • Process checks whether UAC notifications are on

      • setup.exe (PID: 1944)
      • zen.exe (PID: 5704)
    • Process checks computer location settings

      • setup.exe (PID: 1944)
      • zen.exe (PID: 3916)
    • UPX packer has been detected

      • zen.installer.exe (PID: 2340)
    • Creates files in the program directory

      • setup.exe (PID: 4068)
      • zen.exe (PID: 5704)
      • zen.exe (PID: 3916)
    • Reads CPU info

      • zen.exe (PID: 5704)
      • zen.exe (PID: 3916)
      • zen.exe (PID: 6268)
      • zen.exe (PID: 4056)
    • Creates files or folders in the user directory

      • zen.exe (PID: 3916)
    • Checks proxy server information

      • setup.exe (PID: 4068)
      • zen.exe (PID: 3916)
    • Reads the machine GUID from the registry

      • zen.exe (PID: 3916)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
170
Monitored processes
34
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs THREAT zen.installer.exe setup.exe setup.exe regsvr32.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
888"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5408 --field-trial-handle=1888,i,12604072078836092320,18185874307411384009,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1944.\setup.exeC:\Users\admin\AppData\Local\Temp\7zS429C52D2\setup.exe
zen.installer.exe
User:
admin
Company:
Zen HQ
Integrity Level:
MEDIUM
Description:
Zen Browser Installer
Exit code:
0
Version:
1.0.0-a.28
Modules
Images
c:\users\admin\appdata\local\temp\7zs429c52d2\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2340"C:\Users\admin\Downloads\zen.installer.exe" C:\Users\admin\Downloads\zen.installer.exe
chrome.exe
User:
admin
Company:
Mozilla
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
18.05
Modules
Images
c:\users\admin\downloads\zen.installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\user32.dll
2572"C:\Program Files\Zen Browser\zen.exe" -first-startupC:\Program Files\Zen Browser\zen.exesetup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Zen Browser
Exit code:
0
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\program files\zen browser\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\zen browser\vcruntime140.dll
3004"C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=6600 -childID 9 -isForBrowser -prefsHandle 6604 -prefMapHandle 6592 -prefsLen 34224 -prefMapSize 258296 -jsInitHandle 1272 -jsInitLen 234852 -parentBuildID 20240822212523 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {56f8db2c-9c1d-4ce0-9fdb-02ea0fce4951} 3916 tabC:\Program Files\Zen Browser\zen.exezen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Zen Browser
Exit code:
0
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3104"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=4176 --field-trial-handle=1888,i,12604072078836092320,18185874307411384009,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3800"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3144 --field-trial-handle=1888,i,12604072078836092320,18185874307411384009,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3900"C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=4504 -childID 4 -isForBrowser -prefsHandle 4544 -prefMapHandle 4528 -prefsLen 24412 -prefMapSize 258296 -jsInitHandle 1272 -jsInitLen 234852 -parentBuildID 20240822212523 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {bc3c16ed-0647-4628-a4c1-0c1e2eede923} 3916 tabC:\Program Files\Zen Browser\zen.exezen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Zen Browser
Exit code:
0
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3916"C:\Program Files\Zen Browser\zen.exe" -first-startupC:\Program Files\Zen Browser\zen.exe
zen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Zen Browser
Exit code:
0
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4056"C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=2240 -parentBuildID 20240822212523 -prefsHandle 2232 -prefMapHandle 2228 -prefsLen 22121 -prefMapSize 258296 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {82b1c3e3-f182-4c27-9bdb-26265773e938} 3916 socketC:\Program Files\Zen Browser\zen.exezen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Zen Browser
Exit code:
0
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
34 712
Read events
34 525
Write events
170
Delete events
17

Modification events

(PID) Process:(6596) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6596) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6596) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(6596) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(6596) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6596) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(6596) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6596) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(6596) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(6596) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:metricsid
Value:
Executable files
73
Suspicious files
399
Text files
144
Unknown types
6

Dropped files

PID
Process
Filename
Type
6596chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF11e750.TMP
MD5:
SHA256:
6596chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6596chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6596chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6596chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6596chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF11e75f.TMP
MD5:
SHA256:
6596chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
6596chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
6596chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.oldtext
MD5:723783C35EAEEE1492EDB30847AE6750
SHA256:C29323F784CF873BF34992E7A2B4630B19641BF42980109E31D5AF2D487DF6F8
6596chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF11e730.TMPtext
MD5:8F45965291AB2DA10EEB049FB6E917C6
SHA256:8A0DE526945B27CDBBD87357C85FDDD37B572370F894CB0A5AC533FD465D2166
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
117
DNS requests
102
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3812
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
304
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3916
zen.exe
GET
200
2.22.61.59:80
http://ciscobinary.openh264.org/openh264-win64-31c4d2e4a037526fd30d4e5c39f60885986cf865.zip
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2876
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3800
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6848
chrome.exe
76.76.21.22:443
www.zen-browser.app
AMAZON-02
US
unknown
6596
chrome.exe
239.255.255.250:1900
whitelisted
6848
chrome.exe
142.251.31.84:443
accounts.google.com
GOOGLE
US
unknown
6848
chrome.exe
142.250.186.42:443
content-autofill.googleapis.com
GOOGLE
US
whitelisted
2876
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6596
chrome.exe
224.0.0.251:5353
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 142.250.186.36
  • 51.104.136.2
whitelisted
google.com
  • 142.250.74.206
whitelisted
www.zen-browser.app
  • 76.76.21.22
  • 76.76.21.61
unknown
accounts.google.com
  • 142.251.31.84
whitelisted
content-autofill.googleapis.com
  • 142.250.186.42
  • 172.217.18.10
  • 142.250.181.234
  • 142.250.184.202
  • 142.250.186.74
  • 216.58.212.170
  • 142.250.185.170
  • 142.250.184.234
  • 172.217.16.138
  • 142.250.186.106
  • 216.58.206.74
  • 172.217.18.106
  • 216.58.206.42
  • 142.250.185.234
  • 142.250.185.202
  • 172.217.16.202
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
www.google.com
  • 142.250.181.228
whitelisted
cdn.jsdelivr.net
  • 151.101.129.229
  • 151.101.65.229
  • 151.101.193.229
  • 151.101.1.229
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.73
  • 20.190.159.4
  • 40.126.31.67
  • 40.126.31.69
  • 20.190.159.2
  • 40.126.31.71
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

PID
Process
Class
Message
6848
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6848
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloud infrastructure to build app (vercel .app)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Canva designs and to share platform (static .canva .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloud infrastructure to build app (vercel .app)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Canva designs and to share platform (static .canva .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Canva designs and to share platform (static .canva .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloud infrastructure to build app (vercel .app)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloud infrastructure to build app (vercel .app)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Canva designs and to share platform (static .canva .com)
No debug info