File name:

ASCP Online Browser.exe.7z

Full analysis: https://app.any.run/tasks/5cad19a8-9743-4e43-86e2-0ba784ddce72
Verdict: Malicious activity
Analysis date: March 13, 2025, 13:30:52
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
themida
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

EEB1B37211ACCF0FA9362BE8A75FEFFD

SHA1:

9B078F4B6971C57DBBDA4A1A94E8FEADB22C37C3

SHA256:

A18901865F7C37B93531ED8BC501E8B59A413914F3951DE5246F78676312EB65

SSDEEP:

98304:4uiCrG8KfhXSJeRH7h5Ijoot8l0cp7szSHYzYny3kGNsBzMnbIEG2T5IsuFNPzVj:8DwzMz9GahuyMQiLs3CdfYYF9t2u

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 1276)
    • The DLL Hijacking

      • msedgewebview2.exe (PID: 7524)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ASCP Online Browser.exe (PID: 8100)
      • msedgewebview2.exe (PID: 1388)
    • Process drops legitimate windows executable

      • msedgewebview2.exe (PID: 1388)
    • Application launched itself

      • msedgewebview2.exe (PID: 6744)
  • INFO

    • Manual execution by a user

      • ASCP Online Browser.exe (PID: 8100)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1276)
    • Create files in a temporary directory

      • msedgewebview2.exe (PID: 2152)
      • msedgewebview2.exe (PID: 6744)
      • ASCP Online Browser.exe (PID: 8100)
      • msedgewebview2.exe (PID: 7496)
    • Creates files or folders in the user directory

      • ASCP Online Browser.exe (PID: 8100)
      • msedgewebview2.exe (PID: 6744)
    • Themida protector has been detected

      • ASCP Online Browser.exe (PID: 8100)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2025:03:13 13:24:23+00:00
ArchivedFileName: ASCP Online Browser.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
19
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe ascp online browser.exe signinfoconsole.exe no specs conhost.exe no specs signinfoconsole.exe no specs conhost.exe no specs signinfoconsole.exe no specs conhost.exe no specs msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe no specs slui.exe msedgewebview2.exe no specs msedgewebview2.exe msedgewebview2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1276"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ASCP Online Browser.exe.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1388"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\Temp\.WebView2\EBWebView" --webview-exe-name="ASCP Online Browser.exe" --webview-exe-version=15.0.11.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=0 --edge-webview-custom-scheme --no-appcompat-clear --mojo-platform-channel-handle=1676 --field-trial-handle=2152,i,7756118155711250557,9733816921798389188,262144 --enable-features=MojoIpcz --disable-features=OverscrollHistoryNavigation,msExperimentalScrolling --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\msedgewebview2.exe
msedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1568"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\Temp\.WebView2\EBWebView" --webview-exe-name="ASCP Online Browser.exe" --webview-exe-version=15.0.11.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=0 --edge-webview-custom-scheme --no-appcompat-clear --mojo-platform-channel-handle=4916 --field-trial-handle=2152,i,7756118155711250557,9733816921798389188,262144 --enable-features=MojoIpcz --disable-features=OverscrollHistoryNavigation,msExperimentalScrolling --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1812C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2152"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Local\Temp\.WebView2\EBWebView /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\Temp\.WebView2\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\msedgewebview2.exe" --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=122.0.2365.59 --initial-client-data=0x1a4,0x1a8,0x1ac,0x180,0x1b4,0x7ffc89955fd8,0x7ffc89955fe4,0x7ffc89955ff0C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2236"C:\Users\admin\AppData\Local\Temp\OSB\SignInfoConsole.exe" "C:\Users\admin\Desktop\ASCP Online Browser.exe"C:\Users\admin\AppData\Local\Temp\OSB\SignInfoConsole.exeASCP Online Browser.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SignInfoConsole
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\osb\signinfoconsole.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
3100\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSignInfoConsole.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3240\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSignInfoConsole.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4152"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\Temp\.WebView2\EBWebView" --webview-exe-name="ASCP Online Browser.exe" --webview-exe-version=15.0.11.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=0 --edge-webview-custom-scheme --no-appcompat-clear --mojo-platform-channel-handle=3648 --field-trial-handle=2152,i,7756118155711250557,9733816921798389188,262144 --enable-features=MojoIpcz --disable-features=OverscrollHistoryNavigation,msExperimentalScrolling --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4448"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\Temp\.WebView2\EBWebView" --webview-exe-name="ASCP Online Browser.exe" --webview-exe-version=15.0.11.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=0 --edge-webview-custom-scheme --no-appcompat-clear --autoplay-policy=no-user-gesture-required --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=" --mojo-platform-channel-handle=3332 --field-trial-handle=2152,i,7756118155711250557,9733816921798389188,262144 --enable-features=MojoIpcz --disable-features=OverscrollHistoryNavigation,msExperimentalScrolling --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
8 656
Read events
8 594
Write events
49
Delete events
13

Modification events

(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ASCP Online Browser.exe.7z
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
13
Suspicious files
122
Text files
27
Unknown types
3

Dropped files

PID
Process
Filename
Type
1276WinRAR.exeC:\Users\admin\Desktop\ASCP Online Browser.exeexecutable
MD5:7280C31FFEAE61AD2A4554A91078E2C1
SHA256:78102510325C9F30F3F385C3EB94A9C36B1CB3AC480E7C5DCA8BFC3F76C53037
8100ASCP Online Browser.exeC:\Users\admin\AppData\Local\IsolatedStorage\0vamnuua.uzn\ggmf1ljg.2fa\Url.ebdb4ytxmvmgp54yrcuettt1opcvulwt\info.datbinary
MD5:0A53C1D28669E7E0E50FCDF88C8127C5
SHA256:D5755A80F47671E9C3E10C007865D7868432D9942CA2CE7D60510039A281CC5C
8100ASCP Online Browser.exeC:\Users\admin\AppData\Local\Temp\7e70ecb.dllexecutable
MD5:7AFBF68246B7D5E54B7BBE4659DA4925
SHA256:2692CC47E8A4E6E4CB46C19739A337BB7443CFFE6DB4A84AF0B80277697C3288
6744msedgewebview2.exeC:\Users\admin\AppData\Local\Temp\.WebView2\EBWebView\Crashpad\throttle_store.dattext
MD5:9E4E94633B73F4A7680240A0FFD6CD2C
SHA256:41C91A9C93D76295746A149DCE7EBB3B9EE2CB551D84365FFF108E59A61CC304
6744msedgewebview2.exeC:\Users\admin\AppData\Local\Temp\.WebView2\EBWebView\c501180e-90cd-42a2-a021-d3fde119981e.tmpbinary
MD5:7E00FE18A8582C42300B7A11671CDF21
SHA256:2860BFFE77372F1D640A83E10DC925A5D2235372C326AF11BBB85D430047AD20
8100ASCP Online Browser.exeC:\Users\admin\AppData\Local\IsolatedStorage\0vamnuua.uzn\ggmf1ljg.2fa\Url.ebdb4ytxmvmgp54yrcuettt1opcvulwt\identity.datbinary
MD5:AB386429A595937598134627CD24A7E4
SHA256:F14BECDCE1C1F7C7FC53CE1905B2F72878C75D04893E067E9D194EE263B9CA33
6744msedgewebview2.exeC:\Users\admin\AppData\Local\Temp\.WebView2\EBWebView\Variationsbinary
MD5:961E3604F228B0D10541EBF921500C86
SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED
8100ASCP Online Browser.exeC:\Users\admin\AppData\Local\Temp\7e70eca.dllexecutable
MD5:7AFBF68246B7D5E54B7BBE4659DA4925
SHA256:2692CC47E8A4E6E4CB46C19739A337BB7443CFFE6DB4A84AF0B80277697C3288
2236SignInfoConsole.exeC:\Users\admin\AppData\Local\Temp\Tmp3BFC.tmpbinary
MD5:64A2207C471FE5626D00C59B400BDF9C
SHA256:7A85F9A97BC85FC16DC02B68EFB1556767547684702B5A747EA8FF8E91749D67
6800SignInfoConsole.exeC:\Users\admin\AppData\Local\Temp\Tmp33AF.tmpbinary
MD5:64A2207C471FE5626D00C59B400BDF9C
SHA256:7A85F9A97BC85FC16DC02B68EFB1556767547684702B5A747EA8FF8E91749D67
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
44
DNS requests
30
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
8064
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8064
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8100
ASCP Online Browser.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
unknown
7312
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.32.238.34:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
8100
ASCP Online Browser.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
unknown
8100
ASCP Online Browser.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEEkNsD53GoJVFMAtazZydYk%3D
unknown
unknown
4560
svchost.exe
HEAD
200
217.20.57.36:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b649b6c2-4484-495a-96f2-2fd1ee2b66ca?P1=1742406527&P2=404&P3=2&P4=mWiSZ7Vk3Qq%2bjeN1kzlFuKBzsdSg2EbdKcXUTQeatQUNyCeCoPIm2dDjQ%2f1yf%2bY5LYb9r4L5zKYDwVX9MMQNPw%3d%3d
unknown
whitelisted
4560
svchost.exe
GET
206
217.20.57.36:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/2132f61f-f790-4ae6-a355-8cf9a1533800?P1=1742406512&P2=404&P3=2&P4=cVt27z%2fALTPQ0OtE0890takFJ6FFft7z3F%2fbdnUPcxmqI8YOsuMrbXFXiiJYJRm%2bSzpZaka1ZF2MwMiDw0Iuvw%3d%3d
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
23.32.238.34:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
2104
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
6544
svchost.exe
20.190.160.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
unknown
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
7312
backgroundTaskHost.exe
20.31.169.57:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.18.14
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
unknown
crl.microsoft.com
  • 23.32.238.34
  • 2.19.198.194
unknown
client.wns.windows.com
  • 40.115.3.253
unknown
login.live.com
  • 20.190.160.2
  • 20.190.160.5
  • 40.126.32.72
  • 20.190.160.14
  • 20.190.160.132
  • 20.190.160.20
  • 20.190.160.3
  • 40.126.32.134
unknown
ocsp.digicert.com
  • 2.23.77.188
unknown
arc.msn.com
  • 20.31.169.57
unknown
slscr.update.microsoft.com
  • 20.109.210.53
unknown
www.microsoft.com
  • 2.16.253.202
unknown
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
unknown

Threats

PID
Process
Class
Message
8100
ASCP Online Browser.exe
Misc activity
INFO [ANY.RUN] Pearson VUE Client SSL Cert
8100
ASCP Online Browser.exe
Misc activity
INFO [ANY.RUN] Pearson VUE Client SSL Cert
7496
msedgewebview2.exe
Misc activity
INFO [ANY.RUN] Pearson VUE Client SSL Cert
7496
msedgewebview2.exe
Misc activity
INFO [ANY.RUN] Pearson VUE Client SSL Cert
7496
msedgewebview2.exe
Misc activity
INFO [ANY.RUN] Pearson VUE Client SSL Cert
7496
msedgewebview2.exe
Misc activity
INFO [ANY.RUN] Pearson VUE Client SSL Cert
No debug info