File name:

bootskin_free.exe

Full analysis: https://app.any.run/tasks/04de190b-fe0e-4dd3-9b2d-8e2c1c9cb7e5
Verdict: Malicious activity
Analysis date: May 25, 2025, 18:33:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

496735BA53F15AFBA30233C7C1B11E13

SHA1:

66DF0DA35A8567F3F1387716DBD152A3F9C6B3B4

SHA256:

8EFD264263CA146CACC03A301D2852D1FA3625228C39C6676AB620FC67054E92

SSDEEP:

49152:FthbBxbPxmhGLesRyQ8j0KHPSq191doCp8B0p3u+ts1HpQ2RqD7OdEYG9RG:F7NxbP0YCQI0KL1dbp8Op3u+ypQ2RcSl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • bootskin_free.exe (PID: 2212)
    • Creates a software uninstall entry

      • bootskin_free.exe (PID: 2212)
    • Creates files in the driver directory

      • bootskin_free.exe (PID: 2212)
    • Drops a system driver (possible attempt to evade defenses)

      • bootskin_free.exe (PID: 2212)
    • Reads the Internet Settings

      • bootskin_free.exe (PID: 2212)
      • BootSkin.exe (PID: 1848)
    • There is functionality for taking screenshot (YARA)

      • bootskin_free.exe (PID: 2212)
      • BootSkin.exe (PID: 1848)
    • Searches for installed software

      • bootskin_free.exe (PID: 2212)
    • Creates or modifies Windows services

      • bootskin_free.exe (PID: 2212)
      • BootSkin.exe (PID: 1848)
    • Reads security settings of Internet Explorer

      • bootskin_free.exe (PID: 2212)
  • INFO

    • The sample compiled with english language support

      • bootskin_free.exe (PID: 2212)
    • Create files in a temporary directory

      • bootskin_free.exe (PID: 2212)
    • Checks supported languages

      • bootskin_free.exe (PID: 2212)
      • BootSkin.exe (PID: 1848)
    • Creates files in the program directory

      • bootskin_free.exe (PID: 2212)
    • Reads the computer name

      • bootskin_free.exe (PID: 2212)
      • BootSkin.exe (PID: 1848)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 2588)
    • Reads the Internet Settings

      • explorer.exe (PID: 2588)
    • Application launched itself

      • msedge.exe (PID: 1276)
      • msedge.exe (PID: 3816)
    • Manual execution by a user

      • msedge.exe (PID: 3816)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (96.9)
.dll | Win32 Dynamic Link Library (generic) (1.3)
.exe | Win32 Executable (generic) (0.9)
.exe | Generic Win/DOS Executable (0.4)
.exe | DOS Executable Generic (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2000:04:25 14:37:12+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap
PEType: PE32
LinkerVersion: 6
CodeSize: 8704
InitializedDataSize: 5632
UninitializedDataSize: -
EntryPoint: 0x21af
OSVersion: 4
ImageVersion: 4
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Stardock.net, Inc. www.stardock.com
FileDescription: BootSkin
FileVersion: 1.x
LegalCopyright: Stardock.net, Inc. 2003
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
67
Monitored processes
30
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bootskin_free.exe explorer.exe no specs explorer.exe no specs bootskin.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs bootskin_free.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
740"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=18 --mojo-platform-channel-handle=4820 --field-trial-handle=1324,i,7403794408725865891,16388723543071324598,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
892"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4336 --field-trial-handle=1324,i,7403794408725865891,16388723543071324598,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1076"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2220 --field-trial-handle=1324,i,7403794408725865891,16388723543071324598,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1168"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2264 --field-trial-handle=1324,i,7403794408725865891,16388723543071324598,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1224"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_collections.mojom.CollectionsDataManager --lang=en-US --service-sandbox-type=collections --mojo-platform-channel-handle=4312 --field-trial-handle=1324,i,7403794408725865891,16388723543071324598,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1276"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.wincustomize.com/skins.asp?library=32C:\Program Files\Microsoft\Edge\Application\msedge.exeBootSkin.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1336"C:\Windows\explorer.exe" C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinCustomizeC:\Windows\explorer.exebootskin_free.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1764"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=4016 --field-trial-handle=1324,i,7403794408725865891,16388723543071324598,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1828"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3376 --field-trial-handle=1324,i,7403794408725865891,16388723543071324598,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1832"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3952 --field-trial-handle=1324,i,7403794408725865891,16388723543071324598,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
16 776
Read events
16 495
Write events
262
Delete events
19

Modification events

(PID) Process:(2212) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BootSkin
Operation:writeName:DisplayName
Value:
BootSkin
(PID) Process:(2212) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BootSkin
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\UNWISE.EXE C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\INSTALL.LOG
(PID) Process:(2212) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Common Files\Stardock\ODZip.dll
Value:
1
(PID) Process:(2588) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(2588) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
0100000002000000070000000E000000000000000B000000060000000C0000000D0000000A0000000900000008000000030000000500000004000000FFFFFFFF
(PID) Process:(2588) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
Operation:writeName:MRUListEx
Value:
000000000100000002000000040000000500000003000000FFFFFFFF
(PID) Process:(2588) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
Operation:writeName:MRUListEx
Value:
0000000001000000FFFFFFFF
(PID) Process:(2212) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BootScreen
Operation:writeName:Type
Value:
1
(PID) Process:(2212) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BootScreen
Operation:writeName:Start
Value:
0
(PID) Process:(2212) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BootScreen
Operation:writeName:ImagePath
Value:
\SystemRoot\System32\drivers\vidstub.sys
Executable files
20
Suspicious files
258
Text files
108
Unknown types
0

Dropped files

PID
Process
Filename
Type
2212bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\~GLH0002.TMPexecutable
MD5:998492D3C53EEF257308C016AC9DD825
SHA256:22F45F5366BB6B14FE12187C97AB96C1C4FD93EDD2B46F4DA7D13D44E589A245
2212bootskin_free.exeC:\Users\admin\AppData\Local\Temp\GLC1519.tmpexecutable
MD5:FBD929BFC7B4A9E4FA4506655BAB4C4A
SHA256:ADF8DEA5D36B58CF621E2BB0C4549F94E0919308DD7CC1215D942417C45E54A4
2212bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\UNWISE.EXEexecutable
MD5:3A938ED2427DF10E571041069E6980CB
SHA256:4751A3547F3B482BB4A2440D4E91E3DCBA9B4B0F5B1BB50416A32FB47AE75C5E
2212bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\skins\BeOS\~GLH0006.TMPimage
MD5:4EAE3DE3EDB33A150122A9D9C529914C
SHA256:D89130945C6458D3770B5195A358055EAE96CEE57699E889FD74C0C86E6940A5
2212bootskin_free.exeC:\Users\admin\AppData\Local\Temp\GLF20E5.tmpexecutable
MD5:B9B41E50D612E00BF3A49A6405B89D74
SHA256:50E7A30E1825FAB93B94B698C2C6D2CC1787B094C6CEE53EEED5C497F77443C9
2212bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exeexecutable
MD5:998492D3C53EEF257308C016AC9DD825
SHA256:22F45F5366BB6B14FE12187C97AB96C1C4FD93EDD2B46F4DA7D13D44E589A245
2212bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\~GLH0003.TMPtext
MD5:39DA5AD27749FE8356A57F8A63F2CD7E
SHA256:5A7AE7565A37BE63D96D073A03EBBF3E9E82534DD2DEA24D114B5F4409B1C88F
2212bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\~GLH0001.TMPexecutable
MD5:3A938ED2427DF10E571041069E6980CB
SHA256:4751A3547F3B482BB4A2440D4E91E3DCBA9B4B0F5B1BB50416A32FB47AE75C5E
2212bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\~GLH0004.TMPtext
MD5:0765402CC5637DCC74DB267AC3627DA4
SHA256:873270B63FB67A1EEACD6D939E57D391104EDEE82CF0A47C20750D4EE6C5D5FE
2212bootskin_free.exeC:\Users\admin\AppData\Local\Temp\~GLH0000.TMPexecutable
MD5:B9B41E50D612E00BF3A49A6405B89D74
SHA256:50E7A30E1825FAB93B94B698C2C6D2CC1787B094C6CEE53EEED5C497F77443C9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
159
DNS requests
147
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3036
msedge.exe
GET
301
66.79.209.92:80
http://www.wincustomize.com/skins.asp?library=32
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
3036
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3036
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3816
msedge.exe
239.255.255.250:1900
whitelisted
3036
msedge.exe
66.79.209.92:80
www.wincustomize.com
TELNET
US
whitelisted
3036
msedge.exe
66.79.209.92:443
www.wincustomize.com
TELNET
US
whitelisted
3036
msedge.exe
104.17.25.14:443
cdnjs.cloudflare.com
whitelisted
3036
msedge.exe
3.160.150.14:443
platform-api.sharethis.com
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.174
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
www.wincustomize.com
  • 66.79.209.92
whitelisted
cdnjs.cloudflare.com
  • 104.17.25.14
  • 104.17.24.14
whitelisted
d1f8f9xcsvx3ha.cloudfront.net
  • 18.66.137.5
  • 18.66.137.188
  • 18.66.137.88
  • 18.66.137.125
whitelisted
platform-api.sharethis.com
  • 3.160.150.14
  • 3.160.150.71
  • 3.160.150.46
  • 3.160.150.115
whitelisted
skins12.wincustomize.com
  • 66.79.209.92
whitelisted
skins20.wincustomize.com
  • 66.79.209.92
whitelisted
skins11.wincustomize.com
  • 66.79.209.92
whitelisted

Threats

PID
Process
Class
Message
3036
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
3036
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
3036
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
3036
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info