File name:

uiso9_cn_9.7.0.3476.exe

Full analysis: https://app.any.run/tasks/fe64348c-1451-4c58-8b78-e88e0c77bcd9
Verdict: Malicious activity
Analysis date: April 29, 2025, 01:52:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

E67B238FD307435CE05DD36ABB7BD681

SHA1:

BA4D127BD4BD953544BF2949252578AE612FFAE7

SHA256:

A46EF9291B3ACA45CCBD5A9FF7DCF1F9958A1033BF5B212C19D6D4D550C050D6

SSDEEP:

98304:Z4adL7Mfb5kBv2ro9m4yFO+2dXs0tgvue1/uW2PG5B0Uhxt1Kc8jrj6iPxZDR4H/:3P1VK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • uiso9_cn_9.7.0.3476.exe (PID: 2480)
      • uiso9_cn_9.7.0.3476.exe (PID: 2408)
      • IsoCmd.exe (PID: 2612)
    • Registers / Runs the DLL via REGSVR32.EXE

      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • uiso9_cn_9.7.0.3476.exe (PID: 2480)
      • uiso9_cn_9.7.0.3476.exe (PID: 2408)
      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
    • Reads the Windows owner or organization settings

      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
    • Drops a system driver (possible attempt to evade defenses)

      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
    • Reads the Internet Settings

      • UltraISO.exe (PID: 3104)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 752)
    • There is functionality for taking screenshot (YARA)

      • UltraISO.exe (PID: 3104)
  • INFO

    • Reads the computer name

      • uiso9_cn_9.7.0.3476.tmp (PID: 2812)
      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
      • IsoCmd.exe (PID: 2612)
      • UltraISO.exe (PID: 3104)
    • Checks supported languages

      • uiso9_cn_9.7.0.3476.exe (PID: 2480)
      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
      • uiso9_cn_9.7.0.3476.exe (PID: 2408)
      • uiso9_cn_9.7.0.3476.tmp (PID: 2812)
      • IsoCmd.exe (PID: 2612)
      • UltraISO.exe (PID: 3104)
    • Create files in a temporary directory

      • uiso9_cn_9.7.0.3476.exe (PID: 2408)
      • uiso9_cn_9.7.0.3476.exe (PID: 2480)
    • Detects InnoSetup installer (YARA)

      • uiso9_cn_9.7.0.3476.exe (PID: 2480)
      • uiso9_cn_9.7.0.3476.tmp (PID: 2812)
      • uiso9_cn_9.7.0.3476.exe (PID: 2408)
      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
    • Compiled with Borland Delphi (YARA)

      • uiso9_cn_9.7.0.3476.tmp (PID: 2812)
      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
      • UltraISO.exe (PID: 3104)
    • Creates files in the program directory

      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
    • The sample compiled with english language support

      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
    • The sample compiled with chinese language support

      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
    • Application launched itself

      • msedge.exe (PID: 2392)
      • msedge.exe (PID: 2952)
    • Manual execution by a user

      • msedge.exe (PID: 2952)
    • Creates a software uninstall entry

      • uiso9_cn_9.7.0.3476.tmp (PID: 1336)
    • Process checks whether UAC notifications are on

      • UltraISO.exe (PID: 3104)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (81.5)
.exe | Win32 Executable Delphi generic (10.5)
.exe | Win32 Executable (generic) (3.3)
.exe | Win16/32 Executable Delphi generic (1.5)
.exe | Generic Win/DOS Executable (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41472
InitializedDataSize: 85504
UninitializedDataSize: -
EntryPoint: 0xaa98
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 9.7.0.3476
ProductVersionNumber: 9.7.0.3476
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: EZB Systems, Inc.
FileDescription: UltraISO Setup
FileVersion: 9.7.0.3476
LegalCopyright: (c) EZB Systems, Inc.
ProductName: UltraISO
ProductVersion: 9.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
23
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start uiso9_cn_9.7.0.3476.exe uiso9_cn_9.7.0.3476.tmp no specs uiso9_cn_9.7.0.3476.exe uiso9_cn_9.7.0.3476.tmp regsvr32.exe no specs isocmd.exe no specs ultraiso.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\UltraISO\isoshell.dll"C:\Windows\System32\regsvr32.exeuiso9_cn_9.7.0.3476.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1088"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=1400 --field-trial-handle=1324,i,17106362102874953354,3712258371237010397,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1336"C:\Users\admin\AppData\Local\Temp\is-R923N.tmp\uiso9_cn_9.7.0.3476.tmp" /SL5="$401B2,2148413,128000,C:\Users\admin\AppData\Local\Temp\uiso9_cn_9.7.0.3476.exe" /SPAWNWND=$301AA /NOTIFYWND=$401AE C:\Users\admin\AppData\Local\Temp\is-R923N.tmp\uiso9_cn_9.7.0.3476.tmp
uiso9_cn_9.7.0.3476.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-r923n.tmp\uiso9_cn_9.7.0.3476.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1396"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1396 --field-trial-handle=1316,i,1726462158255183354,7345488161575829348,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2384"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6f3bf598,0x6f3bf5a8,0x6f3bf5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2392"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://cn.ezbsystems.com/ultraiso/order.htmC:\Program Files\Microsoft\Edge\Application\msedge.exeUltraISO.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2408"C:\Users\admin\AppData\Local\Temp\uiso9_cn_9.7.0.3476.exe" /SPAWNWND=$301AA /NOTIFYWND=$401AE C:\Users\admin\AppData\Local\Temp\uiso9_cn_9.7.0.3476.exe
uiso9_cn_9.7.0.3476.tmp
User:
admin
Company:
EZB Systems, Inc.
Integrity Level:
HIGH
Description:
UltraISO Setup
Exit code:
0
Version:
9.7.0.3476
Modules
Images
c:\users\admin\appdata\local\temp\uiso9_cn_9.7.0.3476.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2480"C:\Users\admin\AppData\Local\Temp\uiso9_cn_9.7.0.3476.exe" C:\Users\admin\AppData\Local\Temp\uiso9_cn_9.7.0.3476.exe
explorer.exe
User:
admin
Company:
EZB Systems, Inc.
Integrity Level:
MEDIUM
Description:
UltraISO Setup
Exit code:
0
Version:
9.7.0.3476
Modules
Images
c:\users\admin\appdata\local\temp\uiso9_cn_9.7.0.3476.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2612"C:\Program Files\UltraISO\drivers\isocmd.exe" -iC:\Program Files\UltraISO\drivers\IsoCmd.exeuiso9_cn_9.7.0.3476.tmp
User:
admin
Company:
EZB Systems, Inc.
Integrity Level:
HIGH
Description:
ISO Command
Exit code:
0
Version:
3.12 built by: WinDDK
Modules
Images
c:\program files\ultraiso\drivers\isocmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2652"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6f3bf598,0x6f3bf5a8,0x6f3bf5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
6 109
Read events
6 021
Write events
81
Delete events
7

Modification events

(PID) Process:(1336) uiso9_cn_9.7.0.3476.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\EasyBoot Systems\UltraISO\5.0
Operation:writeName:Shared
Value:
C:\Program Files\Common Files\EZB Systems
(PID) Process:(1336) uiso9_cn_9.7.0.3476.tmpKey:HKEY_CURRENT_USER\Software\EasyBoot Systems\UltraISO\5.0
Operation:writeName:Shared
Value:
C:\Program Files\Common Files\EZB Systems
(PID) Process:(1336) uiso9_cn_9.7.0.3476.tmpKey:HKEY_CURRENT_USER\Software\EasyBoot Systems\UltraISO\5.0
Operation:writeName:XPBurn
Value:
0
(PID) Process:(1336) uiso9_cn_9.7.0.3476.tmpKey:HKEY_CURRENT_USER\Software\EasyBoot Systems\UltraISO\5.0
Operation:writeName:ISOFolder
Value:
C:\Users\admin\Documents\My ISO Files
(PID) Process:(1336) uiso9_cn_9.7.0.3476.tmpKey:HKEY_CURRENT_USER\Software\EasyBoot Systems\UltraISO\5.0
Operation:writeName:UseSkins
Value:
1
(PID) Process:(752) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9653DE66-C5E0-4AEE-ADE5-0197BA68CE2B}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(1336) uiso9_cn_9.7.0.3476.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UltraISO_is1
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files\UltraISO\unins000.exe" /SILENT
(PID) Process:(1336) uiso9_cn_9.7.0.3476.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UltraISO_is1
Operation:writeName:DisplayVersion
Value:
9.7
(PID) Process:(1336) uiso9_cn_9.7.0.3476.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UltraISO_is1
Operation:writeName:Publisher
Value:
EZB Systems, Inc.
(PID) Process:(1336) uiso9_cn_9.7.0.3476.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UltraISO_is1
Operation:writeName:NoModify
Value:
1
Executable files
22
Suspicious files
67
Text files
42
Unknown types
0

Dropped files

PID
Process
Filename
Type
2408uiso9_cn_9.7.0.3476.exeC:\Users\admin\AppData\Local\Temp\is-R923N.tmp\uiso9_cn_9.7.0.3476.tmpexecutable
MD5:0856978F29AE90DC02A700A33FE0302E
SHA256:E0E512BF5E39C44DB7EDA3A0BA2DBAF91C5B61E5FA233C9D293068F4FCD92E82
2480uiso9_cn_9.7.0.3476.exeC:\Users\admin\AppData\Local\Temp\is-CKKFT.tmp\uiso9_cn_9.7.0.3476.tmpexecutable
MD5:0856978F29AE90DC02A700A33FE0302E
SHA256:E0E512BF5E39C44DB7EDA3A0BA2DBAF91C5B61E5FA233C9D293068F4FCD92E82
1336uiso9_cn_9.7.0.3476.tmpC:\Program Files\UltraISO\drivers\IsoCmd.exeexecutable
MD5:C0618803912BEA2270FF7126772D8090
SHA256:C1098C04A395EFCA09CF27951B51584450A8333555B92F4BAB6D961A85500DB5
1336uiso9_cn_9.7.0.3476.tmpC:\Program Files\UltraISO\drivers\is-OR26V.tmpexecutable
MD5:E89B724CD7CE6E0757B37713A4202927
SHA256:1844214045018304E53FB56B795E994D8AC19F41E50D9872BD42A49F31625520
1336uiso9_cn_9.7.0.3476.tmpC:\Program Files\UltraISO\drivers\bootpart.sysexecutable
MD5:E89B724CD7CE6E0757B37713A4202927
SHA256:1844214045018304E53FB56B795E994D8AC19F41E50D9872BD42A49F31625520
1336uiso9_cn_9.7.0.3476.tmpC:\Program Files\UltraISO\drivers\is-CNVOQ.tmpexecutable
MD5:28B2D49D7C5675BF3E290FFE5445C42D
SHA256:AD54206D9B2AA90157AB21B77F6ACC2885C9A1EABDA3D82DA100EF2718D02124
1336uiso9_cn_9.7.0.3476.tmpC:\Program Files\UltraISO\drivers\bootpt64.sysexecutable
MD5:28B2D49D7C5675BF3E290FFE5445C42D
SHA256:AD54206D9B2AA90157AB21B77F6ACC2885C9A1EABDA3D82DA100EF2718D02124
1336uiso9_cn_9.7.0.3476.tmpC:\Program Files\UltraISO\drivers\bootpart.exeexecutable
MD5:C77843C280A632F7897362D17D31C97F
SHA256:DF6B26CF4BB99523D3F57FFA033EB60E1C4B6CE0FF43676AE028C4F59E669D1C
1336uiso9_cn_9.7.0.3476.tmpC:\Program Files\UltraISO\drivers\is-U1AI8.tmpexecutable
MD5:C77843C280A632F7897362D17D31C97F
SHA256:DF6B26CF4BB99523D3F57FFA033EB60E1C4B6CE0FF43676AE028C4F59E669D1C
1336uiso9_cn_9.7.0.3476.tmpC:\Program Files\UltraISO\drivers\is-40I5H.tmpexecutable
MD5:E489D12FF435AEEF4A5474C47D329590
SHA256:66A01F63EE4F66C0CD5BB9BF20E1722D57CC8252AC126780800806B536F4CEA9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
33
TCP/UDP connections
18
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3696
msedge.exe
GET
200
101.32.241.20:80
http://cn.ezbsystems.com/ultraiso/order.htm
unknown
whitelisted
3696
msedge.exe
GET
200
101.32.241.20:80
http://cn.ezbsystems.com/cimages/ezbsys.gif
unknown
whitelisted
3696
msedge.exe
GET
200
101.32.241.20:80
http://cn.ezbsystems.com/cimages/uiso-title.gif
unknown
whitelisted
3696
msedge.exe
GET
200
101.32.241.20:80
http://cn.ezbsystems.com/images/bg.gif
unknown
whitelisted
3696
msedge.exe
GET
200
101.32.241.20:80
http://cn.ezbsystems.com/images/top_1.jpg
unknown
whitelisted
3696
msedge.exe
GET
200
101.32.241.20:80
http://cn.ezbsystems.com/images/order-title.gif
unknown
whitelisted
3696
msedge.exe
GET
200
101.32.241.20:80
http://cn.ezbsystems.com/images/zf-logo.jpg
unknown
whitelisted
3696
msedge.exe
GET
200
101.32.241.20:80
http://cn.ezbsystems.com/images/gm.gif
unknown
whitelisted
3696
msedge.exe
GET
200
101.32.241.20:80
http://cn.ezbsystems.com/images/lozenge-topleft.gif
unknown
whitelisted
3696
msedge.exe
GET
200
101.32.241.20:80
http://cn.ezbsystems.com/images/left_6.jpg
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
3696
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2952
msedge.exe
239.255.255.250:1900
whitelisted
3696
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3696
msedge.exe
101.32.241.20:80
cn.ezbsystems.com
Tencent Building, Kejizhongyi Avenue
SG
whitelisted
3696
msedge.exe
2.16.241.201:443
www.bing.com
Akamai International B.V.
DE
whitelisted
3696
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
cn.ezbsystems.com
  • 101.32.241.20
whitelisted
www.ezbsystems.com
  • 172.234.30.208
whitelisted
www.regsky.com
  • 111.230.250.29
unknown
www.bing.com
  • 2.16.241.201
  • 2.16.241.218
whitelisted

Threats

No threats detected
No debug info