File name:

Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.7z

Full analysis: https://app.any.run/tasks/7720c1a7-1eba-4832-bdaf-79f2666116c8
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: April 29, 2025, 13:12:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
ransomware
arch-exec
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

633FF2565393487041ED58440A6B3E2D

SHA1:

B0C6F506A15C87E1424ABB57213C72E88DF240D6

SHA256:

816856A36481B03B40717F13414C821951C0B5AD3A1549ED27248BF2E2BD44C2

SSDEEP:

1536:QCENrjYhGA02rO8zgRcxqqu6vHEtLiMCqW:QxNw02rExqu6/EtemW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • RANSOMWARE has been detected

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
    • Renames files like ransomware

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
  • SUSPICIOUS

    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 7908)
    • Executing commands from a ".bat" file

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
    • Creates file in the systems drive root

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
    • Likely accesses (executes) a file from the Public directory

      • msedge.exe (PID: 6112)
    • Starts CMD.EXE for commands execution

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 7908)
    • Write to the desktop.ini file (may be used to cloak folders)

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6108)
    • Manual execution by a user

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
      • msedge.exe (PID: 6112)
    • Checks supported languages

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
    • Reads the machine GUID from the registry

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
    • Creates files in the program directory

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
    • Create files in a temporary directory

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
    • Creates files or folders in the user directory

      • Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe (PID: 7884)
    • Reads the computer name

      • identity_helper.exe (PID: 5132)
    • Reads the software policy settings

      • slui.exe (PID: 7252)
    • Application launched itself

      • msedge.exe (PID: 6112)
    • Reads Environment values

      • identity_helper.exe (PID: 5132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2017:07:23 12:58:48+00:00
ArchivedFileName: Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
196
Monitored processes
59
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe THREAT trojan-ransom.win32.purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exe cmd.exe no specs conhost.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs attrib.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
780"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=6600 --field-trial-handle=2232,i,2540257591393425847,16270375181063763309,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
780"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7264 --field-trial-handle=2232,i,2540257591393425847,16270375181063763309,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
872"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7380 --field-trial-handle=2232,i,2540257591393425847,16270375181063763309,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
920"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6932 --field-trial-handle=2232,i,2540257591393425847,16270375181063763309,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1096"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7768 --field-trial-handle=2232,i,2540257591393425847,16270375181063763309,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1196"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7972 --field-trial-handle=2232,i,2540257591393425847,16270375181063763309,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2772"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7764 --field-trial-handle=2232,i,2540257591393425847,16270375181063763309,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3008"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7020 --field-trial-handle=2232,i,2540257591393425847,16270375181063763309,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3896"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --mojo-platform-channel-handle=5192 --field-trial-handle=2232,i,2540257591393425847,16270375181063763309,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4024"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6624 --field-trial-handle=2232,i,2540257591393425847,16270375181063763309,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
24 723
Read events
24 663
Write events
60
Delete events
0

Modification events

(PID) Process:(6108) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6108) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6108) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6108) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.7z
(PID) Process:(6108) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6108) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6108) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6108) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6108) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(6108) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
Executable files
44
Suspicious files
2 673
Text files
276
Unknown types
0

Dropped files

PID
Process
Filename
Type
7884Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exeC:\Users\admin\AppData\Local\Temp\_E244.tmp.battext
MD5:2B5E3B8B9F06F7CF6A65E531A761BFEA
SHA256:9E19E5BB3CAEE69F58EF4665A650963FE65F3C40926E0651348E4B6F97D37110
7884Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exeC:\Users\admin\AppData\Local\Temp\65b178c1239c11edb4aa806e6f6e6963text
MD5:B91D904B2B08C71D595FEAA496FB6572
SHA256:7D834825852E021E2D98E04219DDEE02E3EE1956813840D2577AB8C2B90D5077
7884Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exeC:\BOOTNXT.626binary
MD5:48CDC4D833C2CBF1A39C49D3F292A3B6
SHA256:2EF5024CDE28A126D56E57D14136510FACC448B5B38CD7C08F1F1A7150CEE23B
7884Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exeC:\Users\RECOVER-FILES..htmlhtml
MD5:F61BE4926DF4DD0A4C9E6967FF39E4AE
SHA256:EB8566A8E4C248AD3FDFA34191DAC59A110EB316E2C1F4107135877B6DBC14FD
7884Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exeC:\Users\Public\RECOVER-FILES..htmlhtml
MD5:F61BE4926DF4DD0A4C9E6967FF39E4AE
SHA256:EB8566A8E4C248AD3FDFA34191DAC59A110EB316E2C1F4107135877B6DBC14FD
7884Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exeC:\Users\desktop.inibinary
MD5:45B190953D890301770514A44751F579
SHA256:3E2190A166B3105127FE0B9F280DF3B8A5E0A8E81C168645C41F33B4EA1F5749
7884Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exeC:\Users\Public\Videos\desktop.ini.626binary
MD5:FA02D576E7AE267A87445EA3DBF97028
SHA256:248B28F2988C88EED9696CC082DDCD1468DC2A8125E7B22E7455AF11E946DFE9
7884Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exeC:\Users\Public\Libraries\RECOVER-FILES..htmlhtml
MD5:F61BE4926DF4DD0A4C9E6967FF39E4AE
SHA256:EB8566A8E4C248AD3FDFA34191DAC59A110EB316E2C1F4107135877B6DBC14FD
7884Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exeC:\RECOVER-FILES..htmlhtml
MD5:F61BE4926DF4DD0A4C9E6967FF39E4AE
SHA256:EB8566A8E4C248AD3FDFA34191DAC59A110EB316E2C1F4107135877B6DBC14FD
7884Trojan-Ransom.Win32.Purgen.fa-31f476d527692946076f1c8919770e05176c742400ae2cf3991bd060c990df99.exeC:\Users\Public\Videos\RECOVER-FILES..htmlhtml
MD5:F61BE4926DF4DD0A4C9E6967FF39E4AE
SHA256:EB8566A8E4C248AD3FDFA34191DAC59A110EB316E2C1F4107135877B6DBC14FD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
111
DNS requests
112
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6028
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
976
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1746054379&P2=404&P3=2&P4=mf%2byz1OXP23TF2O3rYtXk8cGYo4IiMWd9%2fsUcJEY2JVoOtNNg%2ffBru%2bMtaB5LtCKMUI7Wu%2fmELcHdsjiSsadQA%3d%3d
unknown
whitelisted
976
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1746054379&P2=404&P3=2&P4=mf%2byz1OXP23TF2O3rYtXk8cGYo4IiMWd9%2fsUcJEY2JVoOtNNg%2ffBru%2bMtaB5LtCKMUI7Wu%2fmELcHdsjiSsadQA%3d%3d
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
976
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1746054379&P2=404&P3=2&P4=mf%2byz1OXP23TF2O3rYtXk8cGYo4IiMWd9%2fsUcJEY2JVoOtNNg%2ffBru%2bMtaB5LtCKMUI7Wu%2fmELcHdsjiSsadQA%3d%3d
unknown
whitelisted
7300
msedge.exe
GET
204
150.171.74.11:80
http://edge-http.microsoft.com/captiveportal/generate_204
unknown
whitelisted
2104
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
976
svchost.exe
GET
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/cf34b06a-2f53-4bd0-9d11-b58cf2e820a4?P1=1746054380&P2=404&P3=2&P4=ZMSrFAYv4ljLkPL%2bMOjEjDA%2fQEf6JMXvog47S4AhKNZ9XSvrjB6NRABLgHGt79g6OEHhfNmxA1BzOd630NWByg%3d%3d
unknown
whitelisted
976
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1746054379&P2=404&P3=2&P4=HMj3SgiECrVO9CWFOD6A9a%2fXGEAlgRMzdhzilzWteu3WlJK7AuBbuQbPqnh3Rud3CGHbd4WjegRtmFYRPJEafQ%3d%3d
unknown
whitelisted
976
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1746054379&P2=404&P3=2&P4=mf%2byz1OXP23TF2O3rYtXk8cGYo4IiMWd9%2fsUcJEY2JVoOtNNg%2ffBru%2bMtaB5LtCKMUI7Wu%2fmELcHdsjiSsadQA%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4108
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
2104
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
config.edge.skype.com
  • 13.107.43.16
whitelisted
edge.microsoft.com
  • 150.171.29.11
  • 150.171.30.11
  • 150.171.27.11
  • 150.171.28.11
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.45
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted

Threats

PID
Process
Class
Message
Misc activity
ET INFO DNS Query to .onion proxy Domain (onion.link)
Misc activity
ET INFO DNS Query to .onion proxy Domain (onion.link)
Not Suspicious Traffic
INFO [ANY.RUN] Possible Abuse Customer Service with Ticketing (.freshdesk .com)
Not Suspicious Traffic
INFO [ANY.RUN] Possible Abuse Customer Service with Ticketing (.freshdesk .com)
Not Suspicious Traffic
INFO [ANY.RUN] Possible Abuse Customer Service with Ticketing (.freshdesk .com)
Not Suspicious Traffic
INFO [ANY.RUN] Possible Abuse Customer Service with Ticketing (.freshdesk .com)
No debug info