File name:

ZipThis.exe

Full analysis: https://app.any.run/tasks/0f74b1b0-eb37-4581-aa72-4711025f4a97
Verdict: Malicious activity
Analysis date: August 06, 2024, 15:20:07
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
MD5:

B00E6B651799ADE8DA83DE8DEF7C11B3

SHA1:

6C8017F07FE67A051825E31E1C9C4639C1C092B9

SHA256:

91F329CC468BFE5740E3A35D659F03C85F80D404ED0551C608E1EE50C3212B1F

SSDEEP:

98304:4w4Duw4xT2ZyydrN7phb9dFqtq1lpI2zkymGeIPyPn7bWLRIhc35MaiGqF25ekAS:m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ZipThis.exe (PID: 6412)
      • ZipThis.exe (PID: 6784)
    • Changes powershell execution policy (RemoteSigned)

      • ZipThis.exe (PID: 6784)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ZipThis.exe (PID: 6412)
      • ZipThis.exe (PID: 6784)
      • ZipThisApp.exe (PID: 5484)
    • Reads the date of Windows installation

      • ZipThis.exe (PID: 6412)
      • ZipThis.exe (PID: 6784)
    • Application launched itself

      • ZipThis.exe (PID: 6412)
    • Starts POWERSHELL.EXE for commands execution

      • ZipThis.exe (PID: 6784)
    • The process executes Powershell scripts

      • ZipThis.exe (PID: 6784)
    • Gets path to any of the special folders (POWERSHELL)

      • powershell.exe (PID: 6900)
    • Executable content was dropped or overwritten

      • ZipThis.exe (PID: 6784)
    • Process drops legitimate windows executable

      • ZipThis.exe (PID: 6784)
    • Creates a software uninstall entry

      • ZipThis.exe (PID: 6784)
    • The process drops C-runtime libraries

      • ZipThis.exe (PID: 6784)
    • Searches for installed software

      • ZipThis.exe (PID: 6784)
  • INFO

    • Reads the machine GUID from the registry

      • ZipThis.exe (PID: 6412)
      • ZipThis.exe (PID: 6784)
      • ZipThisApp.exe (PID: 5484)
    • Checks supported languages

      • ZipThis.exe (PID: 6412)
      • ZipThis.exe (PID: 6784)
      • ZipThisApp.exe (PID: 5484)
    • Reads the computer name

      • ZipThis.exe (PID: 6412)
      • ZipThis.exe (PID: 6784)
      • ZipThisApp.exe (PID: 5484)
    • Creates files or folders in the user directory

      • ZipThis.exe (PID: 6412)
    • Reads Environment values

      • ZipThis.exe (PID: 6412)
      • ZipThis.exe (PID: 6784)
      • ZipThisApp.exe (PID: 5484)
    • Disables trace logs

      • ZipThis.exe (PID: 6412)
      • ZipThis.exe (PID: 6784)
      • ZipThisApp.exe (PID: 5484)
    • Checks proxy server information

      • ZipThis.exe (PID: 6412)
      • ZipThis.exe (PID: 6784)
      • ZipThisApp.exe (PID: 5484)
    • Reads the software policy settings

      • ZipThis.exe (PID: 6412)
      • ZipThis.exe (PID: 6784)
      • ZipThisApp.exe (PID: 5484)
    • Process checks computer location settings

      • ZipThis.exe (PID: 6412)
      • ZipThis.exe (PID: 6784)
    • Creates files in the program directory

      • ZipThis.exe (PID: 6784)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 6900)
    • Reads Microsoft Office registry keys

      • chrome.exe (PID: 5052)
    • Create files in a temporary directory

      • ZipThisApp.exe (PID: 5484)
    • The process uses the downloaded file

      • chrome.exe (PID: 7476)
      • chrome.exe (PID: 7676)
      • chrome.exe (PID: 7464)
      • chrome.exe (PID: 8176)
      • chrome.exe (PID: 7776)
      • chrome.exe (PID: 8008)
      • chrome.exe (PID: 8112)
      • chrome.exe (PID: 6892)
    • Manual execution by a user

      • WinRAR.exe (PID: 8100)
    • Application launched itself

      • chrome.exe (PID: 5996)
      • chrome.exe (PID: 5052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2064:01:19 15:32:14+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 48
CodeSize: 2749440
InitializedDataSize: 120320
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 10.1.24.110
ProductVersionNumber: 10.1.24.110
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: ZipThis
FileVersion: 10.1.24.110
InternalName: ZipThis.exe
LegalCopyright: Copyright © 2015-2023 Lightner Tok All rights reserved
LegalTrademarks: -
OriginalFileName: ZipThis.exe
ProductName: ZipThis
ProductVersion: 10.1.24.110
AssemblyVersion: 10.1.24.110
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
174
Monitored processes
36
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start zipthis.exe zipthis.exe powershell.exe no specs conhost.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs zipthisapp.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs winrar.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2128"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3120 --field-trial-handle=1904,i,2361300241588760586,8666098585961399579,262144 --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2396"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2156 --field-trial-handle=1904,i,2361300241588760586,8666098585961399579,262144 --variations-seed-version /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4292"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3176 --field-trial-handle=1904,i,2361300241588760586,8666098585961399579,262144 --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5052"C:\Program Files\Google\Chrome\Application\chrome.exe" https://www.zipthisapp.com/success?u=4e9de6d0-69fb-4a88-8047-54be289f6b8eC:\Program Files\Google\Chrome\Application\chrome.exe
ZipThis.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5196"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=122.0.6261.70 --initial-client-data=0x214,0x218,0x21c,0x1f0,0x220,0x7fffcd07dc40,0x7fffcd07dc4c,0x7fffcd07dc58C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5484"C:\Program Files\ZipThis\ZipThisApp.exe" C:\Program Files\ZipThis\ZipThisApp.exe
ZipThis.exe
User:
admin
Integrity Level:
HIGH
Description:
ZipThisApp
Exit code:
0
Version:
9.10.100.100
Modules
Images
c:\program files\zipthis\zipthisapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
5540"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2376 --field-trial-handle=1904,i,2361300241588760586,8666098585961399579,262144 --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5976"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4536 --field-trial-handle=1904,i,2361300241588760586,8666098585961399579,262144 --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5996"C:\Program Files\Google\Chrome\Application\chrome.exe" https://visit.keyguardai.com/click?pid=496&offer_id=14039178C:\Program Files\Google\Chrome\Application\chrome.exeZipThis.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6172"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=122.0.6261.70 --initial-client-data=0x214,0x218,0x21c,0x1f0,0x220,0x7fffcd07dc40,0x7fffcd07dc4c,0x7fffcd07dc58C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
49 410
Read events
49 079
Write events
313
Delete events
18

Modification events

(PID) Process:(6412) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6412) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6412) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6412) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6412) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6412) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6412) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6412) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6412) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6412) ZipThis.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ZipThis_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
25
Suspicious files
382
Text files
48
Unknown types
0

Dropped files

PID
Process
Filename
Type
6784ZipThis.exeC:\Program Files\ZipThis\update_task.ps1text
MD5:2E5B6F2E387430EF627CF666FBBE0D12
SHA256:94BBDE99705BF63A3110D592967BE352DC087D4B36AF71B2F0CC7579507CD520
6784ZipThis.exeC:\Program Files\ZipThis\zipthisUserId.txttext
MD5:E7A80B67FD9E573252548242D4DB8346
SHA256:4B26B50A51139A7D9B216398239E59B5678E464BF64510B7B64BB5D260A3D41A
6784ZipThis.exeC:\Program Files\ZipThis\msvcp140_atomic_wait.dllexecutable
MD5:6722344B74084D0AF629283060716BAE
SHA256:C9FD25862B1B8B2977BF188A4E0C4460DADE43C31710283C2B42DBD3B15B4317
6900powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:F580A9B8E6F21C32337E875B6C065683
SHA256:0B3D899D2353FCD741235C2494CFE58482A8AC5C3707FC15A9C20BBC8FD2910D
6784ZipThis.exeC:\Program Files\ZipThis\vcamp140.dllexecutable
MD5:8441A618D2CEF67BDEDCA224FD61AFA2
SHA256:6CD300E597C477260809C5CA036993D923CD8BE304AE323C9C4D7776115FE62D
6412ZipThis.exeC:\Users\admin\AppData\Roaming\SMCR\userId.txttext
MD5:E7A80B67FD9E573252548242D4DB8346
SHA256:4B26B50A51139A7D9B216398239E59B5678E464BF64510B7B64BB5D260A3D41A
6784ZipThis.exeC:\Program Files\ZipThis\concrt140.dllexecutable
MD5:9485D003573E0EAF7952AB23CC82EF7B
SHA256:5E0E8EAC57B86E2DE7CA7D6E8D34DDDEA602CE3660208FB53947A027635D59A1
6784ZipThis.exeC:\Program Files\ZipThis\msvcp140_1.dllexecutable
MD5:7B0A25EEE764D8747F02CB3ED980F07A
SHA256:1274292F4CC655F295272B37E08A9683B8BB8C419B61EA2E1F43EB4D22F02F90
6784ZipThis.exeC:\Program Files\ZipThis\msvcp140.dllexecutable
MD5:C3D497B0AFEF4BD7E09C7559E1C75B05
SHA256:1E57A6DF9E3742E31A1C6D9BFF81EBEEAE8A7DE3B45A26E5079D5E1CCE54CD98
6784ZipThis.exeC:\Program Files\ZipThis\Libs.dllexecutable
MD5:8F22D1409CF9222DD8B05EB8E0456050
SHA256:D658EA24EE115D2071DEDFF84383657BB540DC1037E6D0FEE689D2751204D4D7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
107
DNS requests
111
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5336
SearchApp.exe
GET
304
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3812
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7084
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7060
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7888
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adrga7eefaxjfdmmgfkiaxjg4yjq_2024.7.12.235938/eeigpngbgcognadeebkilcpcaedhellh_2024.07.12.235938_all_a6r64uyugl6fjh3lupjqo6w7ai.crx3
unknown
whitelisted
7888
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adrga7eefaxjfdmmgfkiaxjg4yjq_2024.7.12.235938/eeigpngbgcognadeebkilcpcaedhellh_2024.07.12.235938_all_a6r64uyugl6fjh3lupjqo6w7ai.crx3
unknown
whitelisted
7888
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adrga7eefaxjfdmmgfkiaxjg4yjq_2024.7.12.235938/eeigpngbgcognadeebkilcpcaedhellh_2024.07.12.235938_all_a6r64uyugl6fjh3lupjqo6w7ai.crx3
unknown
whitelisted
7888
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adrga7eefaxjfdmmgfkiaxjg4yjq_2024.7.12.235938/eeigpngbgcognadeebkilcpcaedhellh_2024.07.12.235938_all_a6r64uyugl6fjh3lupjqo6w7ai.crx3
unknown
whitelisted
7888
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adrga7eefaxjfdmmgfkiaxjg4yjq_2024.7.12.235938/eeigpngbgcognadeebkilcpcaedhellh_2024.07.12.235938_all_a6r64uyugl6fjh3lupjqo6w7ai.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1884
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
3028
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6412
ZipThis.exe
45.33.84.9:443
apb.thisilient.com
Linode, LLC
US
unknown
4
System
192.168.100.255:137
whitelisted
6784
ZipThis.exe
45.33.84.9:443
apb.thisilient.com
Linode, LLC
US
unknown
5336
SearchApp.exe
92.123.104.59:443
www.bing.com
Akamai International B.V.
DE
unknown
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.238
whitelisted
apb.thisilient.com
  • 45.33.84.9
unknown
www.bing.com
  • 92.123.104.59
  • 92.123.104.49
  • 92.123.104.50
  • 92.123.104.61
  • 92.123.104.5
  • 92.123.104.47
  • 92.123.104.58
  • 92.123.104.53
  • 92.123.104.66
whitelisted
client.wns.windows.com
  • 40.113.103.199
  • 40.113.110.67
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.73
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.64
  • 40.126.31.71
  • 20.190.159.4
  • 20.190.159.75
whitelisted
th.bing.com
  • 92.123.104.5
  • 92.123.104.59
  • 92.123.104.53
  • 92.123.104.61
  • 92.123.104.58
  • 92.123.104.9
  • 92.123.104.18
  • 92.123.104.66
  • 92.123.104.12
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

PID
Process
Class
Message
2396
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2396
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2396
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
2396
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
2396
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
2396
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
No debug info