File name:

NL-Hybrid.zip

Full analysis: https://app.any.run/tasks/4b02dce2-1c36-4f7e-b4c3-321be1b3fd5e
Verdict: Malicious activity
Analysis date: June 28, 2025, 20:10:03
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

DE4F9389E47E8052F8CA90CD44BBB1C2

SHA1:

0FF2BF2F7E4447F012184E0A551CA505784CA3C8

SHA256:

948D5B604FE5467802E384744B31D2449BCBA9AEEC0833250BDD76AFAF25A0AC

SSDEEP:

98304:7e89tUKcxmX3g5VhxNWYgsBFqSmS0w2Wruvx4HLyQsEVVldsk8+AbBwy13j8fpux:UBFOK45gCHF1KxJJMV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Internet Explorer settings

      • WinRAR.exe (PID: 72)
    • Reads Microsoft Outlook installation path

      • WinRAR.exe (PID: 72)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 72)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 72)
    • Reads security settings of Internet Explorer

      • NL-Hybrid.exe (PID: 4764)
      • WinRAR.exe (PID: 72)
      • NL-Hybrid.exe (PID: 8176)
    • Drops 7-zip archiver for unpacking

      • msiexec.exe (PID: 7596)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7596)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7676)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 7596)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 72)
      • msiexec.exe (PID: 7596)
    • Checks supported languages

      • NL-Hybrid.exe (PID: 4764)
      • identity_helper.exe (PID: 4984)
      • msiexec.exe (PID: 7596)
      • NL-Hybrid.exe (PID: 8176)
    • Reads the computer name

      • NL-Hybrid.exe (PID: 4764)
      • identity_helper.exe (PID: 4984)
      • msiexec.exe (PID: 7596)
      • NL-Hybrid.exe (PID: 8176)
    • Checks proxy server information

      • WinRAR.exe (PID: 72)
      • slui.exe (PID: 4680)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 72)
      • msedge.exe (PID: 1180)
      • msedge.exe (PID: 2124)
      • msiexec.exe (PID: 7596)
    • Manual execution by a user

      • NL-Hybrid.exe (PID: 4764)
      • NL-Hybrid.exe (PID: 6732)
      • msedge.exe (PID: 2124)
      • NL-Hybrid.exe (PID: 8176)
      • NL-Hybrid.exe (PID: 868)
      • msiexec.exe (PID: 3876)
    • Creates files in the program directory

      • NL-Hybrid.exe (PID: 4764)
    • Reads Environment values

      • identity_helper.exe (PID: 4984)
    • Application launched itself

      • msedge.exe (PID: 6404)
      • msedge.exe (PID: 4168)
      • msedge.exe (PID: 2124)
      • msedge.exe (PID: 4264)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 2124)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 2124)
    • Manages system restore points

      • SrTasks.exe (PID: 8040)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 7596)
    • The sample compiled with russian language support

      • msiexec.exe (PID: 7596)
    • Reads the software policy settings

      • slui.exe (PID: 4680)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:11:13 12:15:28
ZipCRC: 0x7798f956
ZipCompressedSize: 769737
ZipUncompressedSize: 1437056
ZipFileName: clrjit.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
205
Monitored processes
60
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs slui.exe nl-hybrid.exe no specs nl-hybrid.exe conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe no specs msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs nl-hybrid.exe no specs nl-hybrid.exe conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
72"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\NL-Hybrid.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
760"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3596,i,17211496690799269596,2983720893670029268,262144 --variations-seed-version --mojo-platform-channel-handle=3620 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
868"C:\Users\admin\Desktop\Preferences\NL-Hybrid.exe" C:\Users\admin\Desktop\Preferences\NL-Hybrid.exeexplorer.exe
User:
admin
Company:
Marcin Szeniak
Integrity Level:
MEDIUM
Description:
WinUpdateHelper
Exit code:
3221226540
Version:
5.8.2.0
Modules
Images
c:\users\admin\desktop\preferences\nl-hybrid.exe
c:\windows\system32\ntdll.dll
1068C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1180"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2244,i,17211496690799269596,2983720893670029268,262144 --variations-seed-version --mojo-platform-channel-handle=2660 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1480"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2480,i,17211496690799269596,2983720893670029268,262144 --variations-seed-version --mojo-platform-channel-handle=2476 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1720"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=7460,i,17211496690799269596,2983720893670029268,262144 --variations-seed-version --mojo-platform-channel-handle=7468 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2064"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=1788,i,17211496690799269596,2983720893670029268,262144 --variations-seed-version --mojo-platform-channel-handle=7692 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2124"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --disable-quic --flag-switches-end --do-not-de-elevate --single-argument https://igk.filexspace.com/getfile/XKQLPSK?title=DependencyCore&tracker=NL-HybridC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2216"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2064,i,304156625112712291,1998674437961649816,262144 --variations-seed-version --mojo-platform-channel-handle=2536 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
14 266
Read events
13 914
Write events
333
Delete events
19

Modification events

(PID) Process:(72) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(72) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(72) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(72) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NL-Hybrid.zip
(PID) Process:(72) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(72) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(72) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(72) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(72) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(72) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
39
Suspicious files
171
Text files
150
Unknown types
0

Dropped files

PID
Process
Filename
Type
72WinRAR.exeC:\Users\admin\Desktop\Preferences\hostfxr.dllexecutable
MD5:A4431266F13F98D48A2F2B10FD2D8A71
SHA256:88945E1FD1B63C3D941F67E6CF161680F1288C97FB7AC6028D2645477708F124
72WinRAR.exeC:\Users\admin\AppData\Local\Temp\IMT8C61.tmpbinary
MD5:37DD1A3FC6A8F6C87C0DEA4894C67293
SHA256:04BBCBC68D2BD1692A924256596DD3708E19CB9879CB01CC4BBB6BF76FD74374
72WinRAR.exeC:\Users\admin\Desktop\Preferences\clrjit.dllexecutable
MD5:92795535F2855D02685A78985D2F3D28
SHA256:7399B0EFE5B3D0A9656F35A7317C9210DFDA4374FBBA7B2FD07671A5855A9345
72WinRAR.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\style[1].csstext
MD5:D0E81A97B0BF393FACB2790C89A03D54
SHA256:9F83FADD6AB0D45ACCAE671D0D13AAAAC730079F81D0539C374A251CD3FD0036
72WinRAR.exeC:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.datbinary
MD5:E9155693861DFA6646383CA2F6AC59BA
SHA256:BA9DC18F7281CE9E93DE98DAC0EEF74C3ADFB7B157CC1C992E930A501238FF50
72WinRAR.exeC:\Users\admin\AppData\Local\Temp\~DF86985183CC1A4BCC.TMPbinary
MD5:72F5C05B7EA8DD6059BF59F50B22DF33
SHA256:1DC0C8D7304C177AD0E74D3D2F1002EB773F4B180685A7DF6BBE75CCC24B0164
72WinRAR.exeC:\Users\admin\AppData\Local\Temp\~DF355DD68C069937EF.TMPbinary
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
72WinRAR.exeC:\Users\admin\Desktop\Preferences\hostpolicy.dllexecutable
MD5:04AEBB8B06CBFA10DE7225F2AE76F98F
SHA256:BFC1C6DD5EED11E15882A3D9E85C63A942A10F81C82D21BB0E7A190BA2D49A91
72WinRAR.exeC:\Users\admin\Desktop\Preferences\Microsoft.Win32.Primitives.dllexecutable
MD5:CC3035B444919AAF960F226B256C612A
SHA256:C5892083EF60BEAF9551F8DF3DCF4FED0FC2CE96A289AB1B1835979A1DB88FD2
72WinRAR.exeC:\Users\admin\Desktop\Preferences\coreclr.dllexecutable
MD5:CBB2F646B9B2A67DAD68C35BBC7CB7C8
SHA256:C6E05A6D8433F111916F2B107B765A9159F41FA1C7A5D8E267645DBD6734D737
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
87
DNS requests
90
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.29:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4932
svchost.exe
GET
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9244b52a-55cc-41a2-b7c4-7f4983d8753c?P1=1751162518&P2=404&P3=2&P4=Pqxb16Ca8EXmAcv0V8WSmZUm%2bWmlFOsQks4wT7piABHj2zx6Ph3fOujuC8rT8nXFah7RYnzZtFIYO9OtXG8EhA%3d%3d
unknown
whitelisted
4932
svchost.exe
GET
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/2ef98485-cbad-4d99-b4c2-cd4abac73fb4?P1=1751162516&P2=404&P3=2&P4=hnN9zUQo6fOJHPDfHPrnsRn%2fSkVkwFeoJirZAzTFvjn%2b%2f2Hb9KDG6jcjCbU9SYZqlHFn08eVqCBVJZAbqSS%2bzQ%3d%3d
unknown
whitelisted
4932
svchost.exe
GET
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/46df2db5-82ac-46a7-9d9e-cf1580d73a96?P1=1751162517&P2=404&P3=2&P4=JN%2fU22CchwSEsgoqEis0UoZjHqfQLB0bw2UstfBsqZUx5oa0goEIMno4822wlZ99%2br%2fwBDmvbM2V4hPCcUGfpg%3d%3d
unknown
whitelisted
4932
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9244b52a-55cc-41a2-b7c4-7f4983d8753c?P1=1751162518&P2=404&P3=2&P4=Pqxb16Ca8EXmAcv0V8WSmZUm%2bWmlFOsQks4wT7piABHj2zx6Ph3fOujuC8rT8nXFah7RYnzZtFIYO9OtXG8EhA%3d%3d
unknown
whitelisted
4932
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/2ef98485-cbad-4d99-b4c2-cd4abac73fb4?P1=1751162516&P2=404&P3=2&P4=hnN9zUQo6fOJHPDfHPrnsRn%2fSkVkwFeoJirZAzTFvjn%2b%2f2Hb9KDG6jcjCbU9SYZqlHFn08eVqCBVJZAbqSS%2bzQ%3d%3d
unknown
whitelisted
4932
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/46df2db5-82ac-46a7-9d9e-cf1580d73a96?P1=1751162517&P2=404&P3=2&P4=JN%2fU22CchwSEsgoqEis0UoZjHqfQLB0bw2UstfBsqZUx5oa0goEIMno4822wlZ99%2br%2fwBDmvbM2V4hPCcUGfpg%3d%3d
unknown
whitelisted
4932
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/03b2d981-4f59-42a6-8f9a-a2b6278a0020?P1=1751162517&P2=404&P3=2&P4=YYPWjMvqdXJ9WxpwdlKmEsJolRQTn34RcfjpvdDWoH85q8QQxlUdqfUuHOS5fOmXQfBpREmXsy8QDIgTdelGDg%3d%3d
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7060
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6472
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.216.77.29:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
7060
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7060
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 23.216.77.29
  • 23.216.77.32
  • 23.216.77.18
  • 23.216.77.21
  • 23.216.77.20
  • 23.216.77.25
  • 23.216.77.28
  • 23.216.77.26
  • 23.216.77.8
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.17
  • 20.190.160.2
  • 20.190.160.128
  • 20.190.160.14
  • 20.190.160.65
  • 20.190.160.3
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.14
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
1180
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
1180
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
1180
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
1180
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
1180
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
1180
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
Process
Message
NL-Hybrid.exe
Profiler was prevented from loading notification profiler due to app settings. Process ID (decimal): 4764. Message ID: [0x2509].
NL-Hybrid.exe
Profiler was prevented from loading notification profiler due to app settings. Process ID (decimal): 8176. Message ID: [0x2509].