URL:

https://urldefense.com/v3/__https://u44145144.ct.sendgrid.net/ls/click?upn=u001.6mgma0ioyCVvMmbhI30xa4YNrO2mZKQUncsKrguHNJLTglcDuy1wNbPZZFDOwsWlw-2Bu9GeXwaGYKo96Qk-2BZ4avlxcjgxvwEZZGwhTskTmplU7xpgyF17ZIAZ4lcbYSfazkiY4uy7r9A0pDkBTOM3WKAiESbR-2FqoIErbUGiayucxxI-2BhxoZ3JFB3hJ155whQz-2FiZwpp1J1iuQQpazdwWCt2fKFZY8fRte48rNwltA5FA-2Fuzc7n3Bv2DKGiSlbdnQ5dI4O48E-2BBYByjduVDCh6Jxb-2BzH-2BbRbf1R8dxiSUVrsX3gbYZb1stdML7K5EGJitA99lPOyaEd7vTpfw0fsFCb6egI6jqhNGj8VBBb0dv3gQMBnyzElNe1SsVeNvVs6LBvmmKsIRVTA4vCeY6cGfGMa11rpS-2BIQ80zeR9Wvj-2Fk3fd3vvTl5cZebw1xyHunVrExMyPXZYVMAa1wyVq-2FbykRnBWSvpsv-2FcnRA8CPQWThJbX2IOi2CeDnmWHi53mF8jG4NjvPvMPc-2BD5DQOX8kTTj00usbcjFoM0tLezp5gWG9Pu133kWkEv-2F-2Ftpg6Ny9BwFyunVVIuXcOKQ9otq0bbNNZnS9T1N7eIxFJISRInVpk3zmzaolJTMLV7hBzlhZOD0hxumv-2Br24fbthzyb5y5YeZSlcailkyuJhF-2B-2FW6XtVhAcBJIvjfbUQ6DTxG8N6iJuii-2Fd3yoPc6CN-2FfCk5ftkbHQoBbxfyPOsWM-2FdWAJZSyQmVRa28FDP49M5pMCcrONSgslmsMmA1nXgYDUzjJeySeTz4h6pv2oQ1HPJyiOn1kJwJMs00E0NTrreKRWyUAfM5vb2fuT5h5Ctb-2BMI3myn3N7CME-2F3XBdo1ScQF00NZaEbu1IxOrX-2BJDwSbNNRjBqFrPDlivJg1dTlGsesNi0PvMMrhzWcAPEapwfjHizEZ3I6mYKpZPAXTPQhWzjxBq2zMoVhzgafLgg9QyooiwqQQy25qYWwYtjP458FBlU-2FPRM8h0nSRITCCsmtRxAk7Bu7-2FrWU3Ep5JwqfCfAjrrU9yAq6nm4XjlBKJX85rFmYrWKL8spjGMv5TMKnZt5lKc46-2FCBxIwIcobdoNd4ZrPER4lDPSCySQM9AyOHmEN4wvPycqH4fkywYya-2BQkICHQBY7hDi3Y9lsV6kIYjyN5U9h1Lv18eOVEXia2x9AACrTZDdu4dt4Eb8N4RcYP-2BIT9xF3xrohwMDH4hQ2SCyfJptlQOHmNWSXQR8T-2BcXAWKR3bMc-3D5suY_8cWMsm8ohRHvur4NHIBRY5weo6bMaaSUQ1kE5eI0KBVVKHW7e9zlwSU-2BTT-2FFICMXul4-2FLVQvFBrUqvd5z3jP4aOe73f4gRk-2BySm69v39NvdOGJDEto4VTtPEkjpXC0-2F7U56PAHjmk-2BaB03C7Powp5eb4uLuu7g50u3ZNyK0Kf5DAdXp-2FycaD-2FdiTi5n5F7pBw-2FTANFYsZAP3lqUef-2FxvHg-3D-3D__;!!H7yp__TR!f25ANXbu4Pdo6JoBTaRxfcNofbo8tyulY2GWEzbwG6wUzgVwDQ7iqwUnaYZcM8Xcq00pmsVeds3arigHBxXOvRzLFVWQYIjhPA$

Full analysis: https://app.any.run/tasks/fd8ad2fd-04c1-40ea-9bfe-007af76ea346
Verdict: Malicious activity
Threats:

Tycoon 2FA is a phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) protections, particularly targeting Microsoft 365 and Gmail accounts. Its advanced evasion techniques and modular architecture make it a significant threat to organizations relying on MFA for security.

Analysis date: May 15, 2026, 15:56:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
phishing
storm1747
tycoon
phishing-ml
Indicators:
MD5:

DE7B9493451FCC330663287C09B634C4

SHA1:

CAA1FAC3133709DA63B84C4EFA78E0B4EBBB3D8A

SHA256:

9EA78815196DD92D34416CD6F6E77DBFBC2C6047D124C8449E19FB46A29B9409

SSDEEP:

24:2hnfl59U2iN7XqLUlJgtDvT+1cy5o8/kMX4MruDzlzKEuf+QBQVuCs9DbUA70:em16kJgJrycKlXY9nu2QVe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Fake Microsoft Authentication Page has been detected

      • msedge.exe (PID: 7804)
    • PHISHING has been detected (ML)

      • msedge.exe (PID: 7804)
    • Tycoon 2FA phishing kit has been detected

      • msedge.exe (PID: 7804)
    • PHISHING has been detected (SURICATA)

      • msedge.exe (PID: 4280)
  • SUSPICIOUS

    • Page with zero-length space title

      • msedge.exe (PID: 7804)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 7804)
    • Reads Environment values

      • identity_helper.exe (PID: 7924)
    • Checks supported languages

      • identity_helper.exe (PID: 7924)
    • Reads the computer name

      • identity_helper.exe (PID: 7924)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
155
Monitored processes
20
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs #PHISHING msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
420"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x294,0x298,0x29c,0x28c,0x2a4,0x7ffe2392f208,0x7ffe2392f214,0x7ffe2392f220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
672"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --disable-quic --onnx-enabled-for-ee --string-annotations --always-read-main-dll --field-trial-handle=5300,i,5511865412059521124,4096913336880668361,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5328 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2204"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=1452,i,5511865412059521124,4096913336880668361,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=2220 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2648"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=3624,i,5511865412059521124,4096913336880668361,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=3940 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2680"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6376,i,5511865412059521124,4096913336880668361,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6784 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2880"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5284,i,5511865412059521124,4096913336880668361,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5308 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4280"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2368,i,5511865412059521124,4096913336880668361,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=2204 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5384"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5868,i,5511865412059521124,4096913336880668361,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5896 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
5404"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=14 --always-read-main-dll --field-trial-handle=6812,i,5511865412059521124,4096913336880668361,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6036 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5632"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5964,i,5511865412059521124,4096913336880668361,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6036 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
370
Read events
370
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
52
Text files
233
Unknown types
0

Dropped files

PID
Process
Filename
Type
7804msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RFdfec3.TMP
MD5:
SHA256:
7804msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7804msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFdfed3.TMP
MD5:
SHA256:
7804msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7804msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFdfed3.TMP
MD5:
SHA256:
7804msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RFdfed3.TMP
MD5:
SHA256:
7804msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFdfed3.TMP
MD5:
SHA256:
7804msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
7804msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7804msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
93
TCP/UDP connections
67
DNS requests
68
Threats
18

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4280
msedge.exe
GET
302
52.204.90.22:443
https://urldefense.com/v3/__https://u44145144.ct.sendgrid.net/ls/click?upn=u001.6mgma0ioyCVvMmbhI30xa4YNrO2mZKQUncsKrguHNJLTglcDuy1wNbPZZFDOwsWlw-2Bu9GeXwaGYKo96Qk-2BZ4avlxcjgxvwEZZGwhTskTmplU7xpgyF17ZIAZ4lcbYSfazkiY4uy7r9A0pDkBTOM3WKAiESbR-2FqoIErbUGiayucxxI-2BhxoZ3JFB3hJ155whQz-2FiZwpp1J1iuQQpazdwWCt2fKFZY8fRte48rNwltA5FA-2Fuzc7n3Bv2DKGiSlbdnQ5dI4O48E-2BBYByjduVDCh6Jxb-2BzH-2BbRbf1R8dxiSUVrsX3gbYZb1stdML7K5EGJitA99lPOyaEd7vTpfw0fsFCb6egI6jqhNGj8VBBb0dv3gQMBnyzElNe1SsVeNvVs6LBvmmKsIRVTA4vCeY6cGfGMa11rpS-2BIQ80zeR9Wvj-2Fk3fd3vvTl5cZebw1xyHunVrExMyPXZYVMAa1wyVq-2FbykRnBWSvpsv-2FcnRA8CPQWThJbX2IOi2CeDnmWHi53mF8jG4NjvPvMPc-2BD5DQOX8kTTj00usbcjFoM0tLezp5gWG9Pu133kWkEv-2F-2Ftpg6Ny9BwFyunVVIuXcOKQ9otq0bbNNZnS9T1N7eIxFJISRInVpk3zmzaolJTMLV7hBzlhZOD0hxumv-2Br24fbthzyb5y5YeZSlcailkyuJhF-2B-2FW6XtVhAcBJIvjfbUQ6DTxG8N6iJuii-2Fd3yoPc6CN-2FfCk5ftkbHQoBbxfyPOsWM-2FdWAJZSyQmVRa28FDP49M5pMCcrONSgslmsMmA1nXgYDUzjJeySeTz4h6pv2oQ1HPJyiOn1kJwJMs00E0NTrreKRWyUAfM5vb2fuT5h5Ctb-2BMI3myn3N7CME-2F3XBdo1ScQF00NZaEbu1IxOrX-2BJDwSbNNRjBqFrPDlivJg1dTlGsesNi0PvMMrhzWcAPEapwfjHizEZ3I6mYKpZPAXTPQhWzjxBq2zMoVhzgafLgg9QyooiwqQQy25qYWwYtjP458FBlU-2FPRM8h0nSRITCCsmtRxAk7Bu7-2FrWU3Ep5JwqfCfAjrrU9yAq6nm4XjlBKJX85rFmYrWKL8spjGMv5TMKnZt5lKc46-2FCBxIwIcobdoNd4ZrPER4lDPSCySQM9AyOHmEN4wvPycqH4fkywYya-2BQkICHQBY7hDi3Y9lsV6kIYjyN5U9h1Lv18eOVEXia2x9AACrTZDdu4dt4Eb8N4RcYP-2BIT9xF3xrohwMDH4hQ2SCyfJptlQOHmNWSXQR8T-2BcXAWKR3bMc-3D5suY_8cWMsm8ohRHvur4NHIBRY5weo6bMaaSUQ1kE5eI0KBVVKHW7e9zlwSU-2BTT-2FFICMXul4-2FLVQvFBrUqvd5z3jP4aOe73f4gRk-2BySm69v39NvdOGJDEto4VTtPEkjpXC0-2F7U56PAHjmk-2BaB03C7Powp5eb4uLuu7g50u3ZNyK0Kf5DAdXp-2FycaD-2FdiTi5n5F7pBw-2FTANFYsZAP3lqUef-2FxvHg-3D-3D__;!!H7yp__TR!f25ANXbu4Pdo6JoBTaRxfcNofbo8tyulY2GWEzbwG6wUzgVwDQ7iqwUnaYZcM8Xcq00pmsVeds3arigHBxXOvRzLFVWQYIjhPA$
US
unknown
4280
msedge.exe
GET
302
146.112.255.69:443
https://secure-web.cisco.com/1aGj46NINh7Wxqt7lRyKV8AZx31WEl63Klgq8EuUGYWuYJwP1VBJZ_AtZ7D3KJ2qG7TcPorbQz0eVkRnLYUPEM4ZmgdMLe0-Y3i_sLDXOlXKPgkS0kkOpopxoQlTzfwPD1NFPODTK7WsSFh5EW15vsvNtfb79-i1qDhbD1d00Z8BmVcT33z0t4-MlwV0EvUIIJV3dUPtvFfw1p8wvlISVyprj6h3pHNVBatsvbnk2hR4sTWxnN9Tyw3Gs8_s2ZBGrb7u1-FyWRBmhsCU2XeJxoMgZ8QozjLBnF8T4T9r7aaFDutLkKgNa8t5-0Aq11Fg8-kt6JyeNT8nJpN5eoQldfH2GnlZQc0qA8ivZ02827fybFyNVv3rayPc2N_DLERT07-30AU0y-ykiK9m_5HbYUsE163BLAowNrqBOGjfhhY9pXyMuVO6hb7Bgb8UMWqEi7m-XTa2v0Jt5bHV47GhDLPzur8r0WDs-xsJA9YtVQh8/https%3A%2F%2Fsecure.einco.com.br%2F
US
whitelisted
4280
msedge.exe
GET
304
150.171.27.11:443
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
US
whitelisted
4280
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:_Xsq4s4K94k6wPdd6tEvZtaSDXhPvHa-mjwobb8X_SQ&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
99 b
whitelisted
4280
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
US
text
132 b
whitelisted
4280
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=67&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1778860619&lafgdate=0
US
text
4.14 Kb
whitelisted
4280
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
US
text
267 b
whitelisted
4280
msedge.exe
GET
302
176.34.126.149:443
https://u44145144.ct.sendgrid.net/ls/click?upn=u001.6mgma0ioyCVvMmbhI30xa4YNrO2mZKQUncsKrguHNJLTglcDuy1wNbPZZFDOwsWlw-2Bu9GeXwaGYKo96Qk-2BZ4avlxcjgxvwEZZGwhTskTmplU7xpgyF17ZIAZ4lcbYSfazkiY4uy7r9A0pDkBTOM3WKAiESbR-2FqoIErbUGiayucxxI-2BhxoZ3JFB3hJ155whQz-2FiZwpp1J1iuQQpazdwWCt2fKFZY8fRte48rNwltA5FA-2Fuzc7n3Bv2DKGiSlbdnQ5dI4O48E-2BBYByjduVDCh6Jxb-2BzH-2BbRbf1R8dxiSUVrsX3gbYZb1stdML7K5EGJitA99lPOyaEd7vTpfw0fsFCb6egI6jqhNGj8VBBb0dv3gQMBnyzElNe1SsVeNvVs6LBvmmKsIRVTA4vCeY6cGfGMa11rpS-2BIQ80zeR9Wvj-2Fk3fd3vvTl5cZebw1xyHunVrExMyPXZYVMAa1wyVq-2FbykRnBWSvpsv-2FcnRA8CPQWThJbX2IOi2CeDnmWHi53mF8jG4NjvPvMPc-2BD5DQOX8kTTj00usbcjFoM0tLezp5gWG9Pu133kWkEv-2F-2Ftpg6Ny9BwFyunVVIuXcOKQ9otq0bbNNZnS9T1N7eIxFJISRInVpk3zmzaolJTMLV7hBzlhZOD0hxumv-2Br24fbthzyb5y5YeZSlcailkyuJhF-2B-2FW6XtVhAcBJIvjfbUQ6DTxG8N6iJuii-2Fd3yoPc6CN-2FfCk5ftkbHQoBbxfyPOsWM-2FdWAJZSyQmVRa28FDP49M5pMCcrONSgslmsMmA1nXgYDUzjJeySeTz4h6pv2oQ1HPJyiOn1kJwJMs00E0NTrreKRWyUAfM5vb2fuT5h5Ctb-2BMI3myn3N7CME-2F3XBdo1ScQF00NZaEbu1IxOrX-2BJDwSbNNRjBqFrPDlivJg1dTlGsesNi0PvMMrhzWcAPEapwfjHizEZ3I6mYKpZPAXTPQhWzjxBq2zMoVhzgafLgg9QyooiwqQQy25qYWwYtjP458FBlU-2FPRM8h0nSRITCCsmtRxAk7Bu7-2FrWU3Ep5JwqfCfAjrrU9yAq6nm4XjlBKJX85rFmYrWKL8spjGMv5TMKnZt5lKc46-2FCBxIwIcobdoNd4ZrPER4lDPSCySQM9AyOHmEN4wvPycqH4fkywYya-2BQkICHQBY7hDi3Y9lsV6kIYjyN5U9h1Lv18eOVEXia2x9AACrTZDdu4dt4Eb8N4RcYP-2BIT9xF3xrohwMDH4hQ2SCyfJptlQOHmNWSXQR8T-2BcXAWKR3bMc-3D5suY_8cWMsm8ohRHvur4NHIBRY5weo6bMaaSUQ1kE5eI0KBVVKHW7e9zlwSU-2BTT-2FFICMXul4-2FLVQvFBrUqvd5z3jP4aOe73f4gRk-2BySm69v39NvdOGJDEto4VTtPEkjpXC0-2F7U56PAHjmk-2BaB03C7Powp5eb4uLuu7g50u3ZNyK0Kf5DAdXp-2FycaD-2FdiTi5n5F7pBw-2FTANFYsZAP3lqUef-2FxvHg-3D-3D
US
html
950 b
unknown
4280
msedge.exe
GET
303
34.206.167.183:443
https://shared.outlook.inky.com/link?domain=secure-web.cisco.com&t=h.eJxlklmPokAUhf9Kx6TfBi0ooYp-ahgWRUS0WZQXQyGbIPsiTua_j3Y_TnJfzvmSk9zk-zPrm3z28TZLuq5qPxaLNgz6JqTGkMyDtA3KeVDeFrSvXpecsTYS5N7rDuWHaeNgwbtD2pVzDm7yuMZyb6sntz9po0k7ouadhc5DEtxoTK0iKzDLhuwfIHSyQ6GfbFPeLr1bfNnqIaBOMD23unTc5ceNGWdfIMt2VVndy31uPaLRlGhDMXeStUFu-6UkrOzS7NAORhcRxFMpXUsJkegLAB4Wb05gQfgA3ZLa5qMD5MFerzUHXmyzG5RopCs8Dvn6y5mq5solsFoZjuh37UCKjEkOy9Zy74XBW9MI1RafW8YT1YagnqaUyT2It6T9bTPHULuX29jD-_Jx1cVCwdbS4hvk-4rUd3q2iQ0fdywFhJqmlRhTWcdpU2hYuNAqgw2fj12iFaMWubcPQC3gdPAAgxkUTUSZDGeAjT-ZAWOcJV0-WABREAg2mKgpSzf87cyuyMluZZqDoi6Uo9HU4k69Rkly4qvjtO2dHZcQJMYE21u3llN0o46WzwxA61iycpZITSTdfPQNboArtdS91QT-1Dn7BC--TXiHwjujPO_Hh3mYFj8uzEnzbGe_3mbZSxvS9G1C3fxiQYhfZOHnd_HM394wEfYDngshCPyLj3wS0oRAjvYJw_MsiBY0QhizkOPoOcPyDMLsazl8LWdh8RnmaRfmZZy2XXp_Lb7o5UX_J3__AZsb6Ow.MEQCIG4hDGxUKMEOU7akVAD0XN60_Hq9eqnd7_S2h4ajwOsbAiBoTitA-2jhmjA7cfLzOseglXwy0xyD22XsfdOudKQCgA
US
text
13 b
unknown
4280
msedge.exe
GET
200
92.123.104.37:443
https://www.bing.com/api/shopping/v1/user/shoppingsettings
NL
text
1.11 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5276
MoUsoCoreWorker.exe
48.209.138.189:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
128.24.231.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
92.123.104.37:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
6260
svchost.exe
48.209.138.189:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
23.11.40.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
4280
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
4280
msedge.exe
150.171.27.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4280
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 128.24.231.65
whitelisted
google.com
  • 192.178.183.139
  • 192.178.183.100
  • 192.178.183.101
  • 192.178.183.138
  • 192.178.183.102
  • 192.178.183.113
whitelisted
www.bing.com
  • 92.123.104.37
  • 92.123.104.49
  • 92.123.104.30
  • 92.123.104.41
  • 92.123.104.45
  • 92.123.104.32
  • 92.123.104.34
  • 92.123.104.50
  • 92.123.104.31
whitelisted
ocsp.digicert.com
  • 23.11.40.157
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
urldefense.com
  • 52.204.90.22
  • 52.71.28.102
  • 52.6.56.188
whitelisted
api.edgeoffer.microsoft.com
  • 150.171.109.194
whitelisted
copilot.microsoft.com
  • 104.18.23.222
  • 104.18.22.222
whitelisted
u44145144.ct.sendgrid.net
  • 176.34.126.149
  • 3.79.169.2
  • 54.229.75.109
  • 63.177.157.111
unknown

Threats

PID
Process
Class
Message
4280
msedge.exe
Misc activity
INFO [ANY.RUN] Possible short link service (sendgrid .net)
4280
msedge.exe
Misc activity
INFO [ANY.RUN] Possible short link service (sendgrid .net)
4280
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Marketing emails platform (.sendgrid .net)
6260
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
4280
msedge.exe
Misc activity
ET INFO Observed DNS Query to .cfd TLD
4280
msedge.exe
Misc activity
ET INFO Observed DNS Query to .cfd TLD
4280
msedge.exe
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Suspected Phishing Domain (jucrookea .com)
4280
msedge.exe
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Tycoon2FA related URL pattern observed (tilda-variant)
4280
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
4280
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
No debug info