URL:

https://wiki.vrpirates.club/downloads/rookie/rookie_2.29.2_portable.zip

Full analysis: https://app.any.run/tasks/926186b4-7283-4f24-a37c-80b5824c628a
Verdict: Malicious activity
Analysis date: August 23, 2024, 16:35:12
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
github
antivm
Indicators:
MD5:

D439BA327D41C56AE817302112BA9643

SHA1:

99660CFB5AD13FB16667D29EE379BCF1C381C112

SHA256:

A304EBDA5CA11F8F3B6FB0968060FBE6F91B28E07C4F9AA67F9AF3E8BA6DF4FD

SSDEEP:

3:N8dj2UL46K43LX+hLV:2LL4h4yhh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7904)
      • AndroidSideloader v2.29.2.exe (PID: 3272)
      • AndroidSideloader v2.29.2.exe (PID: 6372)
    • Executable content was dropped or overwritten

      • 7z.exe (PID: 5500)
      • AndroidSideloader v2.29.2.exe (PID: 3272)
    • Drops the executable file immediately after the start

      • 7z.exe (PID: 5500)
      • AndroidSideloader v2.29.2.exe (PID: 3272)
    • Application launched itself

      • adb.exe (PID: 3164)
      • AndroidSideloader v2.29.2.exe (PID: 3272)
    • Drops 7-zip archiver for unpacking

      • AndroidSideloader v2.29.2.exe (PID: 3272)
    • There is functionality for VM detection (antiVM strings)

      • rclone.exe (PID: 7344)
    • Reads the date of Windows installation

      • AndroidSideloader v2.29.2.exe (PID: 3272)
  • INFO

    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 6572)
    • Reads Environment values

      • identity_helper.exe (PID: 8008)
      • AndroidSideloader v2.29.2.exe (PID: 3272)
      • AndroidSideloader v2.29.2.exe (PID: 6372)
    • Checks supported languages

      • identity_helper.exe (PID: 8008)
      • AndroidSideloader v2.29.2.exe (PID: 3272)
      • adb.exe (PID: 3164)
      • adb.exe (PID: 7216)
      • 7z.exe (PID: 5500)
      • 7z.exe (PID: 2992)
      • rclone.exe (PID: 7600)
      • rclone.exe (PID: 7344)
      • adb.exe (PID: 8156)
      • 7z.exe (PID: 1812)
      • AndroidSideloader v2.29.2.exe (PID: 6372)
    • Reads the computer name

      • identity_helper.exe (PID: 8008)
      • AndroidSideloader v2.29.2.exe (PID: 3272)
      • 7z.exe (PID: 5500)
      • 7z.exe (PID: 2992)
      • rclone.exe (PID: 7600)
      • rclone.exe (PID: 7344)
      • 7z.exe (PID: 1812)
      • adb.exe (PID: 8156)
      • AndroidSideloader v2.29.2.exe (PID: 6372)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7904)
    • Reads the machine GUID from the registry

      • AndroidSideloader v2.29.2.exe (PID: 3272)
      • rclone.exe (PID: 7344)
      • AndroidSideloader v2.29.2.exe (PID: 6372)
    • Creates files or folders in the user directory

      • AndroidSideloader v2.29.2.exe (PID: 3272)
    • Create files in a temporary directory

      • AndroidSideloader v2.29.2.exe (PID: 3272)
      • 7z.exe (PID: 2992)
      • rclone.exe (PID: 7344)
      • 7z.exe (PID: 1812)
      • adb.exe (PID: 8156)
    • Disables trace logs

      • AndroidSideloader v2.29.2.exe (PID: 3272)
    • Checks proxy server information

      • AndroidSideloader v2.29.2.exe (PID: 3272)
    • Reads the software policy settings

      • AndroidSideloader v2.29.2.exe (PID: 3272)
      • rclone.exe (PID: 7344)
    • Process checks computer location settings

      • AndroidSideloader v2.29.2.exe (PID: 3272)
    • Application launched itself

      • msedge.exe (PID: 6572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
196
Monitored processes
60
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe androidsideloader v2.29.2.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs 7z.exe conhost.exe no specs 7z.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs conhost.exe no specs adb.exe no specs msedge.exe no specs msedge.exe no specs rclone.exe no specs conhost.exe no specs THREAT rclone.exe conhost.exe no specs msedge.exe no specs msedge.exe no specs 7z.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs androidsideloader v2.29.2.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4492 --field-trial-handle=2404,i,11657030209430888161,7703234082553932571,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
872"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7028 --field-trial-handle=2404,i,11657030209430888161,7703234082553932571,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
888"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6284 --field-trial-handle=2404,i,11657030209430888161,7703234082553932571,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1436"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3056 --field-trial-handle=2404,i,11657030209430888161,7703234082553932571,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1812"7z.exe" x "C:\Users\admin\AppData\Local\Temp\Rar$EXa7904.25385\meta.7z" -y -o"C:\Users\admin\AppData\Local\Temp\Rar$EXa7904.25385\meta" -p"gL59VfgPxoHR" -bsp1C:\Users\admin\AppData\Local\Temp\Rar$EXa7904.25385\7z.exeAndroidSideloader v2.29.2.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
23.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7904.25385\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2480\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe7z.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2992"7z.exe" x "C:\Users\admin\AppData\Local\Temp\Rar$EXa7904.25385\rclone.zip" -y -o"C:\Users\admin\AppData\Local\Temp\Rar$EXa7904.25385" -bsp1C:\Users\admin\AppData\Local\Temp\Rar$EXa7904.25385\7z.exeAndroidSideloader v2.29.2.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
23.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7904.25385\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
3164"C:\RSL\platform-tools\adb.exe" start-serverC:\RSL\platform-tools\adb.exeAndroidSideloader v2.29.2.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\rsl\platform-tools\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3272"C:\Users\admin\AppData\Local\Temp\Rar$EXa7904.25385\AndroidSideloader v2.29.2.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7904.25385\AndroidSideloader v2.29.2.exe
WinRAR.exe
User:
admin
Company:
Rookie.AndroidSideloader
Integrity Level:
MEDIUM
Description:
AndroidSideloader
Exit code:
4294967295
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7904.25385\androidsideloader v2.29.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4668"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5744 --field-trial-handle=2404,i,11657030209430888161,7703234082553932571,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
33 540
Read events
33 142
Write events
395
Delete events
3

Modification events

(PID) Process:(6572) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6572) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6572) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(6572) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(6572) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6572) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(6572) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6572) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge
Operation:writeName:UsageStatsInSample
Value:
1
(PID) Process:(6572) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:usagestats
Value:
0
(PID) Process:(6572) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:urlstats
Value:
0
Executable files
17
Suspicious files
245
Text files
1 771
Unknown types
7

Dropped files

PID
Process
Filename
Type
6572msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF11dacd.TMP
MD5:
SHA256:
6572msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6572msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF11dadc.TMP
MD5:
SHA256:
6572msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6572msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF11dadc.TMP
MD5:
SHA256:
6572msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
6572msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF11daec.TMP
MD5:
SHA256:
6572msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6572msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF11daec.TMP
MD5:
SHA256:
6572msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
63
DNS requests
60
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6916
msedge.exe
GET
200
172.64.149.23:80
http://zerossl.crt.sectigo.com/ZeroSSLECCDomainSecureSiteCA.crt
unknown
whitelisted
4084
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8084
svchost.exe
HEAD
200
23.48.23.7:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7b9cac0d-9ca2-42ef-9c46-ce975d51335a?P1=1724991733&P2=404&P3=2&P4=nljw1UCDcE8fNYkziuJwf5QPdh6ZdWU%2bJcpwGHEn%2fHAToeGEFJ7ytYkDxMdwpDeLc3IKALNftfv8p4kxVlJSUw%3d%3d
unknown
whitelisted
8116
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7220
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8084
svchost.exe
GET
206
23.48.23.7:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7b9cac0d-9ca2-42ef-9c46-ce975d51335a?P1=1724991733&P2=404&P3=2&P4=nljw1UCDcE8fNYkziuJwf5QPdh6ZdWU%2bJcpwGHEn%2fHAToeGEFJ7ytYkDxMdwpDeLc3IKALNftfv8p4kxVlJSUw%3d%3d
unknown
whitelisted
8084
svchost.exe
GET
206
23.48.23.7:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7b9cac0d-9ca2-42ef-9c46-ce975d51335a?P1=1724991733&P2=404&P3=2&P4=nljw1UCDcE8fNYkziuJwf5QPdh6ZdWU%2bJcpwGHEn%2fHAToeGEFJ7ytYkDxMdwpDeLc3IKALNftfv8p4kxVlJSUw%3d%3d
unknown
whitelisted
8084
svchost.exe
GET
206
23.48.23.7:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7b9cac0d-9ca2-42ef-9c46-ce975d51335a?P1=1724991733&P2=404&P3=2&P4=nljw1UCDcE8fNYkziuJwf5QPdh6ZdWU%2bJcpwGHEn%2fHAToeGEFJ7ytYkDxMdwpDeLc3IKALNftfv8p4kxVlJSUw%3d%3d
unknown
whitelisted
8084
svchost.exe
GET
206
23.48.23.7:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7b9cac0d-9ca2-42ef-9c46-ce975d51335a?P1=1724991733&P2=404&P3=2&P4=nljw1UCDcE8fNYkziuJwf5QPdh6ZdWU%2bJcpwGHEn%2fHAToeGEFJ7ytYkDxMdwpDeLc3IKALNftfv8p4kxVlJSUw%3d%3d
unknown
whitelisted
8084
svchost.exe
GET
206
23.48.23.7:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7b9cac0d-9ca2-42ef-9c46-ce975d51335a?P1=1724991733&P2=404&P3=2&P4=nljw1UCDcE8fNYkziuJwf5QPdh6ZdWU%2bJcpwGHEn%2fHAToeGEFJ7ytYkDxMdwpDeLc3IKALNftfv8p4kxVlJSUw%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5500
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3180
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6916
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6572
msedge.exe
239.255.255.250:1900
whitelisted
6916
msedge.exe
185.247.224.87:443
wiki.vrpirates.club
Flokinet Ltd
SC
unknown
6916
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6916
msedge.exe
13.107.246.45:443
edge-mobile-static.azureedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6916
msedge.exe
13.107.6.158:443
business.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
wiki.vrpirates.club
  • 185.247.224.87
malicious
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.45
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
bzib.nelreports.net
  • 23.48.23.51
  • 23.48.23.26
whitelisted
zerossl.crt.sectigo.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
www.bing.com
  • 104.126.37.177
  • 104.126.37.170
  • 104.126.37.129
  • 104.126.37.186
  • 104.126.37.176
  • 104.126.37.153
  • 104.126.37.154
  • 104.126.37.130
  • 104.126.37.131
  • 104.126.37.128
  • 104.126.37.146
  • 104.126.37.160
whitelisted
update.googleapis.com
  • 142.250.181.227
whitelisted

Threats

PID
Process
Class
Message
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
3272
AndroidSideloader v2.29.2.exe
Misc activity
ET INFO Observed ZeroSSL SSL/TLS Certificate
No debug info