File name:

copilot-activator.exe

Full analysis: https://app.any.run/tasks/75ed892a-785b-40a0-b627-f359a5887d9d
Verdict: Malicious activity
Analysis date: February 10, 2024, 00:59:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

11AA1574F3A15D854015A54DB164EB08

SHA1:

AE3009B48460AE8E5B4EE30F11A87E41B9B0028A

SHA256:

85F36C24E3F9809D18F7889653591328E20E50121030FA24A361CBE53257CDC2

SSDEEP:

98304:Mv2G3afyNbQFmk9ZSfPWdFPxSJD/pJ+A5So+cByyz6yM2Wj4NxUyz6yM+Wt:ilvlF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • copilot-activator.exe (PID: 3672)
      • MicrosoftEdgeWebview2Setup.exe (PID: 3664)
      • MicrosoftEdgeUpdate.exe (PID: 3892)
    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 3892)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebview2Setup.exe (PID: 3664)
      • MicrosoftEdgeUpdate.exe (PID: 3892)
    • Process drops legitimate windows executable

      • copilot-activator.exe (PID: 3672)
      • MicrosoftEdgeUpdate.exe (PID: 3892)
      • MicrosoftEdgeWebview2Setup.exe (PID: 3664)
    • Reads settings of System Certificates

      • copilot-activator.exe (PID: 3672)
      • MicrosoftEdgeUpdate.exe (PID: 1776)
      • MicrosoftEdgeUpdate.exe (PID: 1040)
    • Executable content was dropped or overwritten

      • copilot-activator.exe (PID: 3672)
      • MicrosoftEdgeUpdate.exe (PID: 3892)
      • MicrosoftEdgeWebview2Setup.exe (PID: 3664)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 3892)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 3772)
    • Reads the Internet Settings

      • MicrosoftEdgeUpdate.exe (PID: 1776)
      • MicrosoftEdgeUpdate.exe (PID: 1040)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 1776)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 1776)
  • INFO

    • Reads the computer name

      • copilot-activator.exe (PID: 3672)
      • MicrosoftEdgeUpdate.exe (PID: 3772)
      • MicrosoftEdgeUpdate.exe (PID: 1776)
      • MicrosoftEdgeUpdate.exe (PID: 3892)
      • MicrosoftEdgeUpdate.exe (PID: 3464)
      • MicrosoftEdgeUpdate.exe (PID: 1040)
    • Reads Environment values

      • copilot-activator.exe (PID: 3672)
      • MicrosoftEdgeUpdate.exe (PID: 1776)
    • Checks supported languages

      • copilot-activator.exe (PID: 3672)
      • MicrosoftEdgeWebview2Setup.exe (PID: 3664)
      • MicrosoftEdgeUpdate.exe (PID: 3772)
      • MicrosoftEdgeUpdate.exe (PID: 1776)
      • MicrosoftEdgeUpdate.exe (PID: 3892)
      • MicrosoftEdgeUpdate.exe (PID: 3464)
      • MicrosoftEdgeUpdate.exe (PID: 1040)
    • Create files in a temporary directory

      • copilot-activator.exe (PID: 3672)
      • MicrosoftEdgeWebview2Setup.exe (PID: 3664)
      • MicrosoftEdgeUpdate.exe (PID: 3892)
      • MicrosoftEdgeUpdate.exe (PID: 1776)
    • Reads the machine GUID from the registry

      • copilot-activator.exe (PID: 3672)
      • MicrosoftEdgeUpdate.exe (PID: 3892)
      • MicrosoftEdgeUpdate.exe (PID: 3464)
      • MicrosoftEdgeUpdate.exe (PID: 1040)
      • MicrosoftEdgeUpdate.exe (PID: 1776)
    • Reads the software policy settings

      • copilot-activator.exe (PID: 3672)
      • MicrosoftEdgeUpdate.exe (PID: 1776)
      • MicrosoftEdgeUpdate.exe (PID: 1040)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 3892)
      • MicrosoftEdgeUpdate.exe (PID: 1776)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 1776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 3
CodeSize: 4152832
InitializedDataSize: 678400
UninitializedDataSize: -
EntryPoint: 0x6e090
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.1.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: 宇智科技
FileDescription: copilot激活器
LegalCopyright: www.quan2go.com
ProductName: copilot激活器
ProductVersion: 1.1.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start copilot-activator.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
1040"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1776"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xODEuNSIgc2hlbGxfdmVyc2lvbj0iMS4zLjE4MS41IiBpc21hY2hpbmU9IjAiIHNlc3Npb25pZD0iezk2MEMzMzI1LTM2M0EtNDdERi05M0MyLTU0ODhDNUI3N0M4Q30iIGluc3RhbGxzb3VyY2U9InRhZ2dlZG1pIiByZXF1ZXN0aWQ9IntFOTlCRUVENS01RDMwLTRBN0ItOEMxOC01Q0JEQTY3NjU2RTB9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iMyIgZGlza190eXBlPSIwIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiIHByb2R1Y3RfdHlwZT0iNDgiIGlzX3dpcD0iMCIgaXNfaW5fbG9ja2Rvd25fbW9kZT0iMCIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9IkRFTEwiIHByb2R1Y3RfbmFtZT0iREVMTCIvPjxleHAgZXRhZz0iIi8-PGFwcCBhcHBpZD0ie0YzQzRGRTAwLUVGRDUtNDAzQi05NTY5LTM5OEEyMEYxQkE0QX0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4xODEuNSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTU3NTU2MTUyMzQiIGluc3RhbGxfdGltZV9tcz0iNTQ2Ii8-PC9hcHA-PC9yZXF1ZXN0PgC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3464"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=false" /installsource taggedmi /sessionid "{960C3325-363A-47DF-93C2-5488C5B77C8C}"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3664C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe
copilot-activator.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3672"C:\Users\admin\AppData\Local\Temp\copilot-activator.exe" C:\Users\admin\AppData\Local\Temp\copilot-activator.exe
explorer.exe
User:
admin
Company:
宇智科技
Integrity Level:
MEDIUM
Description:
copilot激活器
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\copilot-activator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
3772"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3892C:\Users\admin\AppData\Local\Temp\EU932.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EU932.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\temp\eu932.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
15 467
Read events
13 920
Write events
1 507
Delete events
40

Modification events

(PID) Process:(3672) copilot-activator.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3892) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(3892) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate
Operation:writeName:path
Value:
C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(PID) Process:(3892) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate
Operation:writeName:UninstallCmdLine
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall
(PID) Process:(3892) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.181.5
(PID) Process:(3892) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
Microsoft Edge Update
(PID) Process:(3892) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.181.5
(PID) Process:(3892) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft Edge Update
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.181.5\MicrosoftEdgeUpdateCore.exe"
(PID) Process:(3892) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate
Operation:writeName:edgeupdate_task_name_c
Value:
MicrosoftEdgeUpdateTaskUserS-1-5-21-1302019708-1500728564-335382590-1000Core{9397CEB6-913F-44DF-9172-B3CD52D5C77E}
(PID) Process:(3892) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate
Operation:writeName:edgeupdate_task_name_ua
Value:
MicrosoftEdgeUpdateTaskUserS-1-5-21-1302019708-1500728564-335382590-1000UA{A53AA750-41E4-41E9-B2F7-D0EE5F8C171B}
Executable files
202
Suspicious files
3
Text files
5
Unknown types
2

Dropped files

PID
Process
Filename
Type
3664MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU932.tmp\msedgeupdate.dllexecutable
MD5:0BEC55833F356F89B8D9D63727DDC43E
SHA256:B360AFADECB2334BA103D515C506E792CB9AEEA5925A6CF85DBFD786A225FFC3
3664MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU932.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:4FDA82E4E5DB7141350CDDCEF7DB07A4
SHA256:48EFBB4780A6BE7EADC26DCC6D2C2B16DACCE447E53A3E2725AD4B1318A34E68
3664MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU932.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:9540AD83A08605BA1F52196424CE3067
SHA256:B0B5D9EB6F4B176BDFBE4DA0A060AD1B76C813186FAE3D9A6E1B1DD9EE0D01D1
3664MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU932.tmp\psuser_64.dllexecutable
MD5:9C6EC49FDEA3E6794C7E26E129250702
SHA256:C2C6C9A0E1CCB2CCD9814F73EC43D3B497819039D00AE21658C38C4524BD6D1D
3664MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU932.tmp\psmachine_64.dllexecutable
MD5:A1E69165B66D05938AB8FC8232EDC866
SHA256:5B7345DE0B70B8D0CEFD4140ACF428A5B0FFE5A147ADF8A75D981B37FBD81E3A
3664MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU932.tmp\EdgeUpdate.datbinary
MD5:369BBC37CFF290ADB8963DC5E518B9B8
SHA256:3D7EC761BEF1B1AF418B909F1C81CE577C769722957713FDAFBC8131B0A0C7D3
3664MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU932.tmp\msedgeupdateres_am.dllexecutable
MD5:27B4625745B0D9036FAEEF288DCDC71F
SHA256:74FEFC1AD1BCA85AE3CDCB197396568E9CCDC3DE9095CC3E787E6E28F9A04487
3672copilot-activator.exeC:\Users\admin\AppData\Local\Temp\copilot-activator-updater\cktimetext
MD5:61DEEEB1764182446482DE4133B2C72A
SHA256:D65B048E40A403FCF0745A1DBB10613E4E1A6C9FDAE4E13B96E1F46BDCA2A568
3664MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU932.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:7750D94E4719BA69F5F83213444C0015
SHA256:1AB31694FF0B6283FBB6EC062D6EAB9FFB26DF9D6D1BA140CF60A8E7A4CB9FE5
3672copilot-activator.exeC:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exeexecutable
MD5:2FBE10E4233824FBEA08DDF085D7DF96
SHA256:5B01D964CED28C1FF850B4DE05A71F386ADDD815A30C4A9EE210EF90619DF58E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
16
DNS requests
10
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
856
svchost.exe
GET
23.50.131.30:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/d87a3bbd-7fe5-4ec3-b806-293cca78b363?P1=1708131614&P2=404&P3=2&P4=VQ45UlUecpW2RLo0kd0SGWhhQAQ%2b90%2bNHDFDNKsNkMxY9R7KGQxoVt4D3x3QUFKC98Ib1eGzprsat1rXwin7qQ%3d%3d
DE
unknown
1776
MicrosoftEdgeUpdate.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?624d1ab720bef5f8
GB
compressed
65.2 Kb
unknown
1776
MicrosoftEdgeUpdate.exe
GET
304
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1d85e727c79ce7e5
DE
unknown
856
svchost.exe
HEAD
200
23.50.131.30:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/d87a3bbd-7fe5-4ec3-b806-293cca78b363?P1=1708131614&P2=404&P3=2&P4=VQ45UlUecpW2RLo0kd0SGWhhQAQ%2b90%2bNHDFDNKsNkMxY9R7KGQxoVt4D3x3QUFKC98Ib1eGzprsat1rXwin7qQ%3d%3d
DE
unknown
1080
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?0754c686571bd23f
GB
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
3672
copilot-activator.exe
123.6.40.248:443
2go.inu1255.cn
CHINA UNICOM China169 Backbone
CN
unknown
3672
copilot-activator.exe
184.30.17.189:443
go.microsoft.com
AKAMAI-AS
DE
unknown
3672
copilot-activator.exe
152.199.21.175:443
msedge.sf.dl.delivery.mp.microsoft.com
EDGECAST
DE
whitelisted
1776
MicrosoftEdgeUpdate.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1040
MicrosoftEdgeUpdate.exe
20.166.2.191:443
msedge.api.cdp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1776
MicrosoftEdgeUpdate.exe
51.116.246.104:443
self.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
DE
unknown
1776
MicrosoftEdgeUpdate.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
2go.inu1255.cn
  • 123.6.40.248
  • 119.167.229.212
  • 123.6.40.224
  • 14.205.47.78
  • 123.6.40.242
  • 113.194.51.118
  • 42.56.81.104
  • 36.248.54.85
  • 123.6.40.127
  • 115.56.90.188
  • 221.204.43.72
  • 123.6.40.213
  • 27.221.71.101
  • 60.28.220.196
  • 1.62.64.108
unknown
go.microsoft.com
  • 184.30.17.189
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
msedge.api.cdp.microsoft.com
  • 20.166.2.191
whitelisted
self.events.data.microsoft.com
  • 51.116.246.104
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.194
  • 184.24.77.202
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
msedge.f.tlu.dl.delivery.mp.microsoft.com
  • 23.50.131.30
  • 23.50.131.24
whitelisted

Threats

PID
Process
Class
Message
856
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info