URL:

https://modmenuz.com/gta-5/kiddion-modest-menu/

Full analysis: https://app.any.run/tasks/592de677-4ab3-4928-8712-4f710fbea56f
Verdict: Malicious activity
Analysis date: February 08, 2025, 12:41:58
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

6FDDCC5DA06D49902E3A595F5D8E35A6

SHA1:

E214B94BE7974A867ACC98A5C78A5D42B9D22A94

SHA256:

A690A652E5F026A1224B00E473AB66923E64FCA40C25BEEBF36E4D75548A9E3A

SSDEEP:

3:N8jIJyRMA6dGWu+K:20ARMA6q1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Kiddion's Modest Menu.exe (PID: 7376)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Kiddion's Modest Menu.exe (PID: 7376)
    • Process drops legitimate windows executable

      • Kiddion's Modest Menu.exe (PID: 7376)
    • Reads security settings of Internet Explorer

      • Kiddion's Modest Menu.exe (PID: 7376)
    • Application launched itself

      • Kiddions Modest Menu.exe (PID: 624)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 3780)
    • Manual execution by a user

      • Kiddion's Modest Menu.exe (PID: 7376)
    • Checks supported languages

      • identity_helper.exe (PID: 7860)
      • Kiddion's Modest Menu.exe (PID: 7376)
      • Kiddions Modest Menu.exe (PID: 4500)
      • Kiddions Modest Menu.exe (PID: 624)
      • Kiddions Modest Menu.exe (PID: 7552)
      • Kiddions Modest Menu.exe (PID: 7176)
      • Kiddions Modest Menu.exe (PID: 3532)
    • Reads the computer name

      • Kiddion's Modest Menu.exe (PID: 7376)
      • identity_helper.exe (PID: 7860)
      • Kiddions Modest Menu.exe (PID: 624)
      • Kiddions Modest Menu.exe (PID: 4500)
      • Kiddions Modest Menu.exe (PID: 3532)
    • Reads Environment values

      • identity_helper.exe (PID: 7860)
      • Kiddions Modest Menu.exe (PID: 624)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 3780)
    • Create files in a temporary directory

      • Kiddion's Modest Menu.exe (PID: 7376)
      • Kiddions Modest Menu.exe (PID: 624)
    • Creates files or folders in the user directory

      • Kiddion's Modest Menu.exe (PID: 7376)
      • Kiddions Modest Menu.exe (PID: 624)
      • Kiddions Modest Menu.exe (PID: 3532)
    • The sample compiled with english language support

      • Kiddion's Modest Menu.exe (PID: 7376)
    • Process checks computer location settings

      • Kiddion's Modest Menu.exe (PID: 7376)
      • Kiddions Modest Menu.exe (PID: 624)
      • Kiddions Modest Menu.exe (PID: 7552)
      • Kiddions Modest Menu.exe (PID: 7176)
    • Reads product name

      • Kiddions Modest Menu.exe (PID: 624)
    • Checks proxy server information

      • Kiddions Modest Menu.exe (PID: 624)
    • Reads the machine GUID from the registry

      • Kiddions Modest Menu.exe (PID: 624)
    • Reads the software policy settings

      • Kiddions Modest Menu.exe (PID: 624)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
179
Monitored processes
49
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs kiddion's modest menu.exe msedge.exe no specs msedge.exe no specs kiddions modest menu.exe no specs kiddions modest menu.exe no specs kiddions modest menu.exe kiddions modest menu.exe no specs kiddions modest menu.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4488 --field-trial-handle=2584,i,9032491131613175723,3456403578485618442,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
624"C:\Users\admin\AppData\Roaming\Kiddion's Modest Menu\Kiddions Modest Menu.exe" C:\Users\admin\AppData\Roaming\Kiddion's Modest Menu\Kiddions Modest Menu.exeKiddion's Modest Menu.exe
User:
admin
Company:
Jia Hao
Integrity Level:
MEDIUM
Description:
Kiddions Modest Menu
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\kiddion's modest menu\kiddions modest menu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
900"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5156 --field-trial-handle=2584,i,9032491131613175723,3456403578485618442,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2324"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --no-appcompat-clear --mojo-platform-channel-handle=4120 --field-trial-handle=2584,i,9032491131613175723,3456403578485618442,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3532"C:\Users\admin\AppData\Roaming\Kiddion's Modest Menu\Kiddions Modest Menu.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\kiddions-modest-menu-nativefier-db65e4" --mojo-platform-channel-handle=1996 --field-trial-handle=1692,i,12200353941729707038,6039216388935863839,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Roaming\Kiddion's Modest Menu\Kiddions Modest Menu.exe
Kiddions Modest Menu.exe
User:
admin
Company:
Jia Hao
Integrity Level:
MEDIUM
Description:
Kiddions Modest Menu
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\kiddion's modest menu\kiddions modest menu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3780"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://modmenuz.com/gta-5/kiddion-modest-menu/"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4500"C:\Users\admin\AppData\Roaming\Kiddion's Modest Menu\Kiddions Modest Menu.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\kiddions-modest-menu-nativefier-db65e4" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1576 --field-trial-handle=1692,i,12200353941729707038,6039216388935863839,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2C:\Users\admin\AppData\Roaming\Kiddion's Modest Menu\Kiddions Modest Menu.exeKiddions Modest Menu.exe
User:
admin
Company:
Jia Hao
Integrity Level:
LOW
Description:
Kiddions Modest Menu
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\kiddion's modest menu\kiddions modest menu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4648"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5900 --field-trial-handle=2584,i,9032491131613175723,3456403578485618442,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6204"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x308,0x30c,0x310,0x304,0x318,0x7ff818535fd8,0x7ff818535fe4,0x7ff818535ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6452"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2576 --field-trial-handle=2584,i,9032491131613175723,3456403578485618442,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
12 451
Read events
12 403
Write events
30
Delete events
18

Modification events

(PID) Process:(3780) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3780) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3780) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3780) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(3780) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
1AF3F115378C2F00
(PID) Process:(3780) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
D8BEFF15378C2F00
(PID) Process:(3780) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\459528
Operation:writeName:WindowTabManagerFileMappingId
Value:
{DF29C015-10C3-4543-A25A-0046B129DE83}
(PID) Process:(3780) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\459528
Operation:writeName:WindowTabManagerFileMappingId
Value:
{59C1CBD9-15F3-4A68-84AD-986D457EE1D5}
(PID) Process:(3780) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\459528
Operation:writeName:WindowTabManagerFileMappingId
Value:
{EFD700C3-1C9F-4833-AC5A-33091BD65D44}
(PID) Process:(3780) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\459528
Operation:writeName:WindowTabManagerFileMappingId
Value:
{39FB3683-73F7-48BE-AA4E-1F20F943FC28}
Executable files
14
Suspicious files
378
Text files
59
Unknown types
1

Dropped files

PID
Process
Filename
Type
3780msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1366ac.TMP
MD5:
SHA256:
3780msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
3780msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1366bc.TMP
MD5:
SHA256:
3780msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
3780msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF1366cc.TMP
MD5:
SHA256:
3780msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
3780msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1366bc.TMP
MD5:
SHA256:
3780msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
3780msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF13671a.TMP
MD5:
SHA256:
3780msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
76
DNS requests
63
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4504
svchost.exe
HEAD
200
23.48.23.27:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1739203894&P2=404&P3=2&P4=ge1TcWWB5pilYpo0Y%2bFRryvuqf7KugemcY33KkT0LH0pSZF9Hen%2fMxSQ5bHh7fzeAcxQj8vgrfJ6F8NI89%2fvgg%3d%3d
unknown
whitelisted
3772
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3772
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4504
svchost.exe
GET
206
23.48.23.27:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1739203894&P2=404&P3=2&P4=ge1TcWWB5pilYpo0Y%2bFRryvuqf7KugemcY33KkT0LH0pSZF9Hen%2fMxSQ5bHh7fzeAcxQj8vgrfJ6F8NI89%2fvgg%3d%3d
unknown
whitelisted
4504
svchost.exe
GET
206
23.48.23.27:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1739203894&P2=404&P3=2&P4=ge1TcWWB5pilYpo0Y%2bFRryvuqf7KugemcY33KkT0LH0pSZF9Hen%2fMxSQ5bHh7fzeAcxQj8vgrfJ6F8NI89%2fvgg%3d%3d
unknown
whitelisted
4504
svchost.exe
GET
206
23.48.23.27:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1739203894&P2=404&P3=2&P4=ge1TcWWB5pilYpo0Y%2bFRryvuqf7KugemcY33KkT0LH0pSZF9Hen%2fMxSQ5bHh7fzeAcxQj8vgrfJ6F8NI89%2fvgg%3d%3d
unknown
whitelisted
4504
svchost.exe
GET
206
23.48.23.27:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1739203894&P2=404&P3=2&P4=ge1TcWWB5pilYpo0Y%2bFRryvuqf7KugemcY33KkT0LH0pSZF9Hen%2fMxSQ5bHh7fzeAcxQj8vgrfJ6F8NI89%2fvgg%3d%3d
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4504
svchost.exe
GET
206
23.48.23.27:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1739203894&P2=404&P3=2&P4=ge1TcWWB5pilYpo0Y%2bFRryvuqf7KugemcY33KkT0LH0pSZF9Hen%2fMxSQ5bHh7fzeAcxQj8vgrfJ6F8NI89%2fvgg%3d%3d
unknown
whitelisted
4504
svchost.exe
GET
206
23.48.23.27:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/6ca9004c-2afd-40c0-a9b1-4fec460952e5?P1=1739203895&P2=404&P3=2&P4=czt%2fzsbBCbs0knsWzwGnKReL9dWeY7wCNpFAsTJz0A7KzGuXG3KmiazodFIC4iNaTrhdVNjv58HyiUhGd9Da0A%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6464
msedge.exe
188.114.97.3:443
modmenuz.com
shared
6464
msedge.exe
104.17.24.14:443
cdnjs.cloudflare.com
whitelisted
6464
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3780
msedge.exe
239.255.255.250:1900
whitelisted
6464
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6464
msedge.exe
13.107.253.45:443
edge-mobile-static.azureedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6464
msedge.exe
13.107.6.158:443
business.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6464
msedge.exe
23.48.23.51:443
bzib.nelreports.net
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
modmenuz.com
  • 188.114.97.3
  • 188.114.96.3
unknown
business.bing.com
  • 13.107.6.158
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.253.45
whitelisted
bzib.nelreports.net
  • 23.48.23.51
  • 23.48.23.26
whitelisted
www.bing.com
  • 92.123.104.38
  • 92.123.104.34
  • 92.123.104.32
whitelisted
cdnjs.cloudflare.com
  • 104.17.24.14
  • 104.17.25.14
whitelisted
cdn.jsdelivr.net
  • 146.75.121.229
  • 104.18.186.31
  • 104.18.187.31
whitelisted
xpaywalletcdn.azureedge.net
  • 13.107.253.45
whitelisted

Threats

PID
Process
Class
Message
6464
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
6464
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6464
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
6464
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
3532
Kiddions Modest Menu.exe
Misc activity
ET INFO Observed Cloudflare Page Developer Domain (pages .dev in TLS SNI)
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Pages platform for frontend developers to collaborate and deploy websites (pages .dev)
2192
svchost.exe
Misc activity
ET INFO DNS Query to Cloudflare Page Developer Domain (pages .dev)
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
No debug info