URL:

https://addons.mozilla.org/en-US/firefox/addon/webcompatcom-reporter/

Full analysis: https://app.any.run/tasks/113eb8eb-a911-4725-ba30-0e0d25c100e0
Verdict: Malicious activity
Analysis date: May 27, 2025, 20:29:08
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
upx
arch-scr
Indicators:
MD5:

3AE109CCD2D733647050998EC2EAE7DC

SHA1:

9CB318A628D530EF16E0F2EC5F98E5E49EE53F2F

SHA256:

8F7280134A201A5E871729B3240F353F14E17783920A06922D5CDCDE2158A151

SSDEEP:

3:N8qQMUHiMhKDWmKdpBK+zm6dIna:2qkHiABmKdp/Ca

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • setup.exe (PID: 4424)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Firefox Installer.exe (PID: 4628)
      • setup-stub.exe (PID: 5720)
      • setup-stub.exe (PID: 4896)
      • download.exe (PID: 7596)
      • setup.exe (PID: 4424)
      • maintenanceservice_installer.exe (PID: 2908)
      • maintenanceservice_tmp.exe (PID: 7768)
    • The process creates files with name similar to system file names

      • setup-stub.exe (PID: 5720)
      • setup-stub.exe (PID: 4896)
      • setup.exe (PID: 4424)
      • maintenanceservice_installer.exe (PID: 2908)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • setup-stub.exe (PID: 5720)
      • setup-stub.exe (PID: 4896)
      • setup.exe (PID: 4424)
      • maintenanceservice_installer.exe (PID: 2908)
    • Reads security settings of Internet Explorer

      • setup-stub.exe (PID: 4896)
      • setup-stub.exe (PID: 5720)
      • maintenanceservice_installer.exe (PID: 2908)
    • Application launched itself

      • setup-stub.exe (PID: 5720)
    • Reads Microsoft Outlook installation path

      • setup-stub.exe (PID: 4896)
    • Reads Internet Explorer settings

      • setup-stub.exe (PID: 4896)
    • There is functionality for taking screenshot (YARA)

      • setup-stub.exe (PID: 5720)
      • setup-stub.exe (PID: 4896)
    • The process drops Mozilla's DLL files

      • download.exe (PID: 7596)
      • setup.exe (PID: 4424)
    • The process drops C-runtime libraries

      • download.exe (PID: 7596)
      • setup.exe (PID: 4424)
    • Process drops legitimate windows executable

      • download.exe (PID: 7596)
      • setup.exe (PID: 4424)
    • Loads DLL from Mozilla Firefox

      • regsvr32.exe (PID: 7748)
      • default-browser-agent.exe (PID: 5176)
      • crashhelper.exe (PID: 7084)
    • Searches for installed software

      • setup.exe (PID: 4424)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 7748)
    • Creates a software uninstall entry

      • setup.exe (PID: 4424)
      • maintenanceservice_installer.exe (PID: 2908)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 300)
      • Firefox Installer.exe (PID: 4628)
      • setup-stub.exe (PID: 5720)
      • setup-stub.exe (PID: 4896)
      • download.exe (PID: 7596)
      • setup.exe (PID: 4424)
      • maintenanceservice_installer.exe (PID: 2908)
      • maintenanceservice_tmp.exe (PID: 7768)
      • crashhelper.exe (PID: 7084)
      • crashhelper.exe (PID: 924)
      • default-browser-agent.exe (PID: 5176)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 2140)
      • msedge.exe (PID: 2284)
      • firefox.exe (PID: 5988)
    • Reads the computer name

      • identity_helper.exe (PID: 300)
      • Firefox Installer.exe (PID: 4628)
      • setup-stub.exe (PID: 5720)
      • setup-stub.exe (PID: 4896)
      • setup.exe (PID: 4424)
      • maintenanceservice_installer.exe (PID: 2908)
      • maintenanceservice_tmp.exe (PID: 7768)
    • Application launched itself

      • msedge.exe (PID: 2140)
      • firefox.exe (PID: 3156)
      • firefox.exe (PID: 7972)
      • firefox.exe (PID: 5988)
      • firefox.exe (PID: 6036)
    • The sample compiled with english language support

      • msedge.exe (PID: 2284)
      • msedge.exe (PID: 2140)
      • Firefox Installer.exe (PID: 4628)
      • setup-stub.exe (PID: 4896)
      • download.exe (PID: 7596)
      • setup.exe (PID: 4424)
      • maintenanceservice_installer.exe (PID: 2908)
    • Reads Environment values

      • identity_helper.exe (PID: 300)
    • Launch of the file from Downloads directory

      • msedge.exe (PID: 2140)
      • msedge.exe (PID: 6584)
    • Create files in a temporary directory

      • setup-stub.exe (PID: 5720)
      • Firefox Installer.exe (PID: 4628)
      • setup-stub.exe (PID: 4896)
      • download.exe (PID: 7596)
      • setup.exe (PID: 4424)
      • maintenanceservice_installer.exe (PID: 2908)
    • Creates files in the program directory

      • setup-stub.exe (PID: 4896)
      • setup.exe (PID: 4424)
      • maintenanceservice_installer.exe (PID: 2908)
    • Reads the machine GUID from the registry

      • setup-stub.exe (PID: 4896)
      • setup.exe (PID: 4424)
    • Process checks whether UAC notifications are on

      • setup-stub.exe (PID: 5720)
    • Process checks computer location settings

      • setup-stub.exe (PID: 5720)
    • Creates files or folders in the user directory

      • setup-stub.exe (PID: 4896)
      • crashhelper.exe (PID: 7084)
    • Reads the software policy settings

      • setup-stub.exe (PID: 4896)
    • Checks proxy server information

      • setup-stub.exe (PID: 4896)
    • UPX packer has been detected

      • Firefox Installer.exe (PID: 4628)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
231
Monitored processes
91
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs sppextcomobj.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox installer.exe setup-stub.exe setup-stub.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs download.exe setup.exe regsvr32.exe no specs maintenanceservice_installer.exe maintenanceservice_tmp.exe default-browser-agent.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs crashhelper.exe no specs firefox.exe no specs firefox.exe no specs crashhelper.exe no specs firefox.exe no specs firefox.exe crashhelper.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs slui.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=6208 --field-trial-handle=2324,i,471588665594567324,3474632101112042229,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
664"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=8188 --field-trial-handle=2324,i,471588665594567324,3474632101112042229,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
812"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250522210034 -prefsHandle 3684:27341 -prefMapHandle 3688:274574 -ipcHandle 3696 -initialChannelId {3382f591-ccd1-47b3-9c12-750d2ca348bb} -parentPid 5988 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5988" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
139.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
924"C:\Program Files\Mozilla Firefox\crashhelper.exe" "7884" "\\.\pipe\gecko-crash-server-pipe.7884" "C:\Users\admin\AppData\Local\Temp\\" "832" "816"C:\Program Files\Mozilla Firefox\crashhelper.exefirefox.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
MEDIUM
Exit code:
0
Version:
139.0
Modules
Images
c:\program files\mozilla firefox\crashhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
1004"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=45 --mojo-platform-channel-handle=7544 --field-trial-handle=2324,i,471588665594567324,3474632101112042229,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1244"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2704 --field-trial-handle=2324,i,471588665594567324,3474632101112042229,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1280"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3908:27404 -prefMapHandle 3912:274574 -jsInitHandle 3916:245828 -parentBuildID 20250522210034 -ipcHandle 3656 -initialChannelId {328e6ce2-2f15-4817-b543-a0b8807e5bfc} -parentPid 5988 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5988" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
139.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1672"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250522210034 -prefsHandle 2148:24875 -prefMapHandle 2152:274574 -ipcHandle 2172 -initialChannelId {c9d92409-fed3-463c-ba7b-0c37aefe4064} -parentPid 5988 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5988" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
139.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2108"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6272 --field-trial-handle=2324,i,471588665594567324,3474632101112042229,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2140"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://addons.mozilla.org/en-US/firefox/addon/webcompatcom-reporter/"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
30 300
Read events
30 078
Write events
190
Delete events
32

Modification events

(PID) Process:(2140) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2140) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2140) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2140) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(2140) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
6DDE7A33BA942F00
(PID) Process:(2140) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
3E27A633BA942F00
(PID) Process:(2140) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262990
Operation:writeName:WindowTabManagerFileMappingId
Value:
{219746AA-4620-4E20-A350-8674351AEEE2}
(PID) Process:(2140) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262990
Operation:writeName:WindowTabManagerFileMappingId
Value:
{50278A96-2E03-4797-A59A-9F9A940C22CE}
(PID) Process:(2140) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262990
Operation:writeName:WindowTabManagerFileMappingId
Value:
{68CAF35C-FE75-4650-98D1-AFAD15E477C7}
(PID) Process:(2140) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262990
Operation:writeName:WindowTabManagerFileMappingId
Value:
{91FA2BFD-40A7-4B23-BDD6-97DDE2D759BA}
Executable files
96
Suspicious files
988
Text files
2 167
Unknown types
390

Dropped files

PID
Process
Filename
Type
2140msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF10c044.TMP
MD5:
SHA256:
2140msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
2140msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF10c073.TMP
MD5:
SHA256:
2140msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
2140msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF10c093.TMP
MD5:
SHA256:
2140msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
2140msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF10c054.TMP
MD5:
SHA256:
2140msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
2140msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF10c093.TMP
MD5:
SHA256:
2140msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
68
TCP/UDP connections
228
DNS requests
275
Threats
39

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2140
msedge.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAEkCvseOAuKFvFLcZ3008A%3D
unknown
whitelisted
2140
msedge.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2140
msedge.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA8O98LYGSc%2BjBPwFtLgmyU%3D
unknown
whitelisted
2140
msedge.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
4896
setup-stub.exe
GET
200
18.66.145.213:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
unknown
whitelisted
1568
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4896
setup-stub.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
2284
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2140
msedge.exe
239.255.255.250:1900
whitelisted
2284
msedge.exe
151.101.129.91:443
addons.mozilla.org
FASTLY
US
whitelisted
2284
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2284
msedge.exe
13.107.6.158:443
business.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2284
msedge.exe
13.107.246.45:443
edge-mobile-static.azureedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
google.com
  • 142.250.185.78
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
addons.mozilla.org
  • 151.101.129.91
  • 151.101.65.91
  • 151.101.193.91
  • 151.101.1.91
  • 2a04:4e42:400::347
  • 2a04:4e42:600::347
  • 2a04:4e42:200::347
  • 2a04:4e42::347
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.45
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
  • 2.16.241.205
  • 2.16.241.201
  • 2.16.241.218
  • 2.16.241.222
whitelisted

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info