URL:

aimmy.dev

Full analysis: https://app.any.run/tasks/da3ccbb1-a571-4154-b71c-c5aa40170b09
Verdict: Malicious activity
Analysis date: February 20, 2026, 16:44:31
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
menorah
auto
generic
Indicators:
MD5:

192D72AE13A48FB09E2925260C0A585B

SHA1:

0CCAA226C1E12330D361618BF2F8DAF5323654F4

SHA256:

A126308BA5E1FDD21EE29F2A2181DD63BC784EC0B97A4461375A3DDCA8EA64ED

SSDEEP:

3:lJ:T

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 5544)
    • GENERIC has been found (auto)

      • msiexec.exe (PID: 1524)
    • MENORAH has been detected (YARA)

      • YmmiaV2.exe (PID: 8704)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 8460)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 3304)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 5544)
    • Searches for installed software

      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 8460)
    • Starts a Microsoft application from unusual location

      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 5544)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 8460)
    • Starts itself from another location

      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 8460)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 1524)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 1524)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 1524)
  • INFO

    • Reads Environment values

      • identity_helper.exe (PID: 9076)
    • Drops script file

      • msedge.exe (PID: 8596)
    • Checks supported languages

      • identity_helper.exe (PID: 9076)
      • YmmiaV2.exe (PID: 6668)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 5544)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 3304)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 8460)
      • msiexec.exe (PID: 1524)
      • msiexec.exe (PID: 8660)
      • msiexec.exe (PID: 3716)
      • YmmiaV2.exe (PID: 8704)
      • msiexec.exe (PID: 8468)
      • msiexec.exe (PID: 6904)
    • Reads the computer name

      • identity_helper.exe (PID: 9076)
      • YmmiaV2.exe (PID: 6668)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 8460)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 5544)
      • msiexec.exe (PID: 8660)
      • msiexec.exe (PID: 1524)
      • msiexec.exe (PID: 8468)
      • msiexec.exe (PID: 3716)
      • msiexec.exe (PID: 6904)
      • YmmiaV2.exe (PID: 8704)
    • Application launched itself

      • msedge.exe (PID: 8596)
      • msedge.exe (PID: 7368)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 9188)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 8460)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 3304)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 5544)
      • msiexec.exe (PID: 1524)
    • Manual execution by a user

      • YmmiaV2.exe (PID: 6668)
      • YmmiaV2.exe (PID: 8704)
    • Reads security settings of Internet Explorer

      • YmmiaV2.exe (PID: 6668)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 8460)
      • YmmiaV2.exe (PID: 8704)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 9188)
      • msedge.exe (PID: 8596)
      • msiexec.exe (PID: 1524)
    • Process checks computer location settings

      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 8460)
    • Create files in a temporary directory

      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 3304)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 8460)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 5544)
      • YmmiaV2.exe (PID: 8704)
    • Creates files in the program directory

      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 5544)
      • YmmiaV2.exe (PID: 8704)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 1524)
      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 5544)
      • YmmiaV2.exe (PID: 8704)
    • Creates a software uninstall entry

      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 5544)
      • msiexec.exe (PID: 1524)
    • Launching a file from a Registry key

      • windowsdesktop-runtime-8.0.24-win-x64.exe (PID: 5544)
    • Checks proxy server information

      • YmmiaV2.exe (PID: 8704)
      • slui.exe (PID: 2244)
    • Creates files or folders in the user directory

      • YmmiaV2.exe (PID: 8704)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
203
Monitored processes
45
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs ymmiav2.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs windowsdesktop-runtime-8.0.24-win-x64.exe windowsdesktop-runtime-8.0.24-win-x64.exe windowsdesktop-runtime-8.0.24-win-x64.exe #GENERIC msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs #MENORAH ymmiav2.exe

Process information

PID
CMD
Path
Indicators
Parent process
1524C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1932"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5156,i,8508477156088343317,8426535367266568474,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5200 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2164"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4736,i,8508477156088343317,8426535367266568474,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=4992 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2244C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2748"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5940,i,8508477156088343317,8426535367266568474,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6316 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3164"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=26 --always-read-main-dll --field-trial-handle=5424,i,8508477156088343317,8426535367266568474,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5196 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3304"C:\Users\admin\Downloads\windowsdesktop-runtime-8.0.24-win-x64.exe" C:\Users\admin\Downloads\windowsdesktop-runtime-8.0.24-win-x64.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Desktop Runtime - 8.0.24 (x64)
Exit code:
0
Version:
8.0.24.35722
Modules
Images
c:\users\admin\downloads\windowsdesktop-runtime-8.0.24-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3352"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=7004,i,8508477156088343317,8426535367266568474,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=7692 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3516"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2652,i,8508477156088343317,8426535367266568474,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=2748 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3716C:\Windows\syswow64\MsiExec.exe -Embedding 38A1F7416B3BEC71182831D1C07440ABC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
16 568
Read events
15 617
Write events
905
Delete events
46

Modification events

(PID) Process:(9188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(9188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(9188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(9188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\AimmyV2.5.0.zip
(PID) Process:(9188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(9188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(9188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(9188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6668) YmmiaV2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(6668) YmmiaV2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
480
Suspicious files
248
Text files
178
Unknown types
110

Dropped files

PID
Process
Filename
Type
8596msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1e4f85.TMP
MD5:
SHA256:
8596msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
8596msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1e4f95.TMP
MD5:
SHA256:
8596msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
8596msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1e4f95.TMP
MD5:
SHA256:
8596msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
8596msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1e4fa4.TMP
MD5:
SHA256:
8596msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1e4fa4.TMP
MD5:
SHA256:
8596msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
8596msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
354
TCP/UDP connections
129
DNS requests
129
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7284
msedge.exe
GET
301
185.199.110.153:80
http://aimmy.dev/
US
html
162 b
unknown
7284
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
US
binary
295 b
whitelisted
7284
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:Cg1Mir-k5xfmyNPreaV5iJvPo1ngJwOsaMHq6OnUKbY&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
100 b
whitelisted
7284
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=66&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0
US
text
4.30 Kb
whitelisted
7284
msedge.exe
GET
200
185.199.110.153:443
https://aimmy.dev/assets/img/YOLOV8Text.png
US
image
25.7 Kb
unknown
7284
msedge.exe
GET
200
104.18.23.222:443
https://copilot.microsoft.com/c/api/user/eligibility
US
text
25 b
whitelisted
7284
msedge.exe
GET
200
185.199.110.153:443
https://aimmy.dev/assets/img/CuteImage3D3.webp
US
image
57.3 Kb
unknown
7284
msedge.exe
GET
200
185.199.110.153:443
https://aimmy.dev/assets/fonts/fa-brands-400.woff2
US
binary
74.1 Kb
unknown
7284
msedge.exe
GET
200
13.107.213.44:443
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appId=edge-extensions&country=US
US
binary
82 b
whitelisted
7284
msedge.exe
GET
200
185.199.110.153:443
https://aimmy.dev/assets/fonts/fontawesome-all.min.css
US
text
55.7 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
9080
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8568
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7284
msedge.exe
150.171.28.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7284
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7284
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7284
msedge.exe
185.199.110.153:80
aimmy.dev
FASTLY
US
whitelisted
7284
msedge.exe
13.107.213.44:443
api.edgeoffer.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.251.127.101
  • 142.251.127.102
  • 142.251.127.139
  • 142.251.127.113
  • 142.251.127.138
  • 142.251.127.100
whitelisted
self.events.data.microsoft.com
  • 20.189.173.10
  • 20.42.73.25
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
aimmy.dev
  • 185.199.110.153
  • 185.199.109.153
  • 185.199.108.153
  • 185.199.111.153
unknown
api.edgeoffer.microsoft.com
  • 13.107.213.44
  • 13.107.246.44
whitelisted
copilot.microsoft.com
  • 104.18.23.222
  • 104.18.22.222
whitelisted
www.bing.com
  • 92.123.104.29
  • 92.123.104.20
  • 92.123.104.31
  • 92.123.104.18
  • 92.123.104.14
  • 92.123.104.17
  • 92.123.104.19
  • 92.123.104.30
  • 92.123.104.26
whitelisted
cometrbx.xyz
unknown

Threats

PID
Process
Class
Message
9080
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
7284
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access release user assets on GitHub
Process
Message
YmmiaV2.exe
Failed to resolve hostfxr.dll [not found]. Error code: 0x80008083
YmmiaV2.exe
You must install .NET to run this application. App: C:\Users\admin\Desktop\YmmiaV2.exe Architecture: x64 App host version: 8.0.23 .NET location: Not found Learn more: https://aka.ms/dotnet/app-launch-failed Download the .NET runtime: https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.23