ANY.RUN Interactive Sandbox
- Full browser-level visibility into phishing
- Huge database of samples and IOCs
- Interactivity in a safe environment
- Actionable Tier 1 reports
Get full visibility into malware and phishing behavior in a safe environment.
| URL: | https://protect2.fireeye.com/v1/url?k=31323334-501d2dca-31172852-454455534531-6a67eecd34b632d4&q=1&e=538b2213-6367-4cc1-97de-c5d9d63fb8d7&u=https%3A%2F%2Fzr5k0r6lyp5ri1h.s3.amazonaws.com%2F1axb2k%2Fh5k2uexit3kckfr.html%3FAWSAccessKeyId%3DAKIAQE43JZLH7N4DDJUT%26Signature%3D3bydouCUK5OLW319CBPcBR6A3k4%253D%26Expires%3D1757447441 |
| Full analysis: | https://app.any.run/tasks/f8632242-e9fd-44a9-ba5b-80af454ac25e |
| Verdict: | Malicious activity |
| Analysis date: | September 03, 2025, 17:54:54 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | F00672ABCB40E08CE47C19681F2E27D9 |
| SHA1: | CF553EE1F90F2D8380108C3BF17F83A64518115F |
| SHA256: | A77E8D056D837D615530F45D6D52A7BF4B553721AD222B97067229112E284322 |
| SSDEEP: | 6:2WbClEpLXrORgwB7TeYcElRVZzNJkoEoSF8OPky2YxsHuxA6AYpqADbXWIk:2bEpLXrpsyOzZs6Syo2vHuxHbXWh |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 432 | C:\WINDOWS\TEMP\{783AFAF0-9BDF-4E8E-AB6E-D88EC7B79E53}\_is149.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{89533077-5F09-4986-BBF2-19178B9082DA} | C:\Windows\Temp\{783AFAF0-9BDF-4E8E-AB6E-D88EC7B79E53}\_is149.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Flexera Integrity Level: SYSTEM Description: InstallShield (R) 64-bit Setup Engine Exit code: 0 Version: 27.0.122 Modules
| |||||||||||||||
| 516 | msiexec /norestart /i "setup.msi" /qn /l*v "C:\WINDOWS\TEMP\PreVer.log.txt" CA_EXTPATH=1 USERINFO="hidewindow=1,notray=1" | C:\Windows\SysWOW64\msiexec.exe | — | PreVerCheck.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 700 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2792,i,14321879558124440819,14980845603658091184,262144 --variations-seed-version --mojo-platform-channel-handle=2908 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1096 | "C:\WINDOWS\sysnative\cmd.exe" /C "C:\WINDOWS\system32\wevtutil.exe" um "C:\ProgramData\Splashtop\Common\Event\stevt_srs_provider.man" | C:\Windows\System32\cmd.exe | — | SetupUtil.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1300 | C:\WINDOWS\TEMP\{783AFAF0-9BDF-4E8E-AB6E-D88EC7B79E53}\_is149.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{818E5101-451D-4B1A-95DE-61ECAA9704C1} | C:\Windows\Temp\{783AFAF0-9BDF-4E8E-AB6E-D88EC7B79E53}\_is149.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Flexera Integrity Level: SYSTEM Description: InstallShield (R) 64-bit Setup Engine Exit code: 0 Version: 27.0.122 Modules
| |||||||||||||||
| 1324 | C:\WINDOWS\TEMP\{783AFAF0-9BDF-4E8E-AB6E-D88EC7B79E53}\_is149.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{1D787ECA-4D48-4B68-80D2-54E71FA660C3} | C:\Windows\Temp\{783AFAF0-9BDF-4E8E-AB6E-D88EC7B79E53}\_is149.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Flexera Integrity Level: SYSTEM Description: InstallShield (R) 64-bit Setup Engine Exit code: 0 Version: 27.0.122 Modules
| |||||||||||||||
| 1388 | C:\WINDOWS\TEMP\{FB0934B1-EAC6-4D59-8B42-BC29F55E2703}\_is4442.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{AD86F999-B245-4500-9935-E0BEA25FB2E1} | C:\Windows\Temp\{FB0934B1-EAC6-4D59-8B42-BC29F55E2703}\_is4442.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Flexera Integrity Level: SYSTEM Description: InstallShield (R) 64-bit Setup Engine Exit code: 0 Version: 27.0.122 Modules
| |||||||||||||||
| 1520 | sc failure Syncro reset= 60 actions= restart/5000/restart/10000/restart/60000 | C:\Windows\System32\sc.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Service Control Manager Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1524 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1528 | C:\WINDOWS\TEMP\{783AFAF0-9BDF-4E8E-AB6E-D88EC7B79E53}\_is149.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{8B42B96D-6120-4744-B1B5-628B418C87B9} | C:\Windows\Temp\{783AFAF0-9BDF-4E8E-AB6E-D88EC7B79E53}\_is149.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Flexera Integrity Level: SYSTEM Description: InstallShield (R) 64-bit Setup Engine Exit code: 0 Version: 27.0.122 Modules
| |||||||||||||||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: 2A1B72967F9C2F00 | |||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\459548 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {8E73D6D4-6686-4D56-A57A-300897734253} | |||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\459548 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {0DFD4A14-12E9-43E1-98EC-65382702E247} | |||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\459548 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {61172A1D-7809-4A93-B9CE-044583D00932} | |||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\459548 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {C036778A-BA12-4230-95F5-A5C41A657B85} | |||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\459548 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {F2F6B42D-894B-4B31-8C2C-5804E3145027} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF18e4ae.TMP | — | |
MD5:— | SHA256:— | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF18e4bd.TMP | — | |
MD5:— | SHA256:— | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF18e4cd.TMP | — | |
MD5:— | SHA256:— | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF18e4ec.TMP | — | |
MD5:— | SHA256:— | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF18e4ec.TMP | — | |
MD5:— | SHA256:— | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3672 | msedge.exe | GET | 200 | 150.171.27.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:fnPjydrmMUrU6jlWNIrnbIm5N-nTpPXY65YXZZxljjI&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | US | text | 101 b | whitelisted |
2704 | svchost.exe | GET | 200 | 104.81.99.218:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | PL | binary | 471 b | whitelisted |
1268 | svchost.exe | GET | 200 | 2.18.244.211:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | FR | binary | 825 b | whitelisted |
1268 | svchost.exe | GET | 200 | 23.200.213.221:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | FR | binary | 814 b | whitelisted |
6788 | msedge.exe | GET | 200 | 104.81.99.218:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | PL | binary | 471 b | whitelisted |
6788 | msedge.exe | GET | 200 | 104.81.99.218:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | PL | binary | 727 b | whitelisted |
6788 | msedge.exe | GET | 200 | 104.81.99.218:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA361MoYdn9Fs8n8dWU5Vwk%3D | PL | binary | 727 b | whitelisted |
7988 | SIHClient.exe | GET | 200 | 23.200.213.221:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | FR | binary | 419 b | whitelisted |
5548 | svchost.exe | HEAD | 200 | 199.232.214.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1756990313&P2=404&P3=2&P4=bNGW2dgFFV7lN73ONAhBFl9Gv%2fG2BQW7TTnc9DjAoPGUvnfq1hg0t1XPUzl5ZF4l%2bPzJwPkZEc%2bSHI8J2AGbRw%3d%3d | US | — | — | whitelisted |
5548 | svchost.exe | GET | 206 | 199.232.214.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1756990313&P2=404&P3=2&P4=bNGW2dgFFV7lN73ONAhBFl9Gv%2fG2BQW7TTnc9DjAoPGUvnfq1hg0t1XPUzl5ZF4l%2bPzJwPkZEc%2bSHI8J2AGbRw%3d%3d | US | binary | 1.09 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1268 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4700 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3672 | msedge.exe | 150.171.22.17:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3672 | msedge.exe | 150.171.27.11:80 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3672 | msedge.exe | 162.159.246.125:443 | protect2.fireeye.com | CLOUDFLARENET | — | whitelisted |
3672 | msedge.exe | 150.171.27.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3672 | msedge.exe | 95.101.136.223:443 | copilot.microsoft.com | Akamai International B.V. | GB | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
protect2.fireeye.com |
| whitelisted |
copilot.microsoft.com |
| whitelisted |
zr5k0r6lyp5ri1h.s3.amazonaws.com |
| shared |
www.bing.com |
| whitelisted |
incredible-platypus-df61b9.netlify.app |
| malicious |
xpaywalletcdn.azureedge.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3672 | msedge.exe | Possible Social Engineering Attempted | ET HUNTING Suspicious Netlify Hosted TLS SNI Request - Possible Phishing Landing |
3672 | msedge.exe | Possible Social Engineering Attempted | ET HUNTING Suspicious Netlify Hosted DNS Request - Possible Phishing Landing |
3672 | msedge.exe | Possible Social Engineering Attempted | ET HUNTING Suspicious Netlify Hosted DNS Request - Possible Phishing Landing |
3672 | msedge.exe | Possible Social Engineering Attempted | ET HUNTING Suspicious Netlify Hosted TLS SNI Request - Possible Phishing Landing |
3672 | msedge.exe | Possible Social Engineering Attempted | ET HUNTING Suspicious Netlify Hosted TLS SNI Request - Possible Phishing Landing |
2200 | svchost.exe | Potentially Bad Traffic | ET REMOTE_ACCESS Observed Remote Management Software Domain in DNS Lookup (syncromsp .com) |
7980 | Syncro.Installer.exe | Potentially Bad Traffic | ET REMOTE_ACCESS Observed Remote Management Software Domain (syncromsp .com in TLS SNI) |
2200 | svchost.exe | Misc activity | ET REMOTE_ACCESS Observed SyncroMSP Remote Management Software Domain in DNS Lookup (kabutoservices .com) |
7980 | Syncro.Installer.exe | Potentially Bad Traffic | ET REMOTE_ACCESS Observed SyncroMSP Remote Management Software Domain (kabutoservices .com in TLS SNI) |
7980 | Syncro.Installer.exe | Potentially Bad Traffic | ET REMOTE_ACCESS Observed Remote Management Software Domain (syncromsp .com in TLS SNI) |
Process | Message |
|---|---|
splashtop-setup.exe | [7228]2025-09-03 17:56:14 [CUtility::OSInfo] OS 10.0(19045) x64:1 (Last=0) |
splashtop-setup.exe | [7228]2025-09-03 17:56:14 [CUnPack::FindHeader] Name:C:\WINDOWS\TEMP\syncro\downloads\splashtop-setup.exe (Last=0) |
splashtop-setup.exe | [7228]2025-09-03 17:56:14 [CUnPack::FindHeader] Sign Size:10376 (Last=0) |
splashtop-setup.exe | [7228]2025-09-03 17:56:14 [CUnPack::FindHeader] Header offset:434176 (Last=183) |
splashtop-setup.exe | [7228]2025-09-03 17:56:14 [CUnPack::UnPackFiles] FreeSpace:233111310336 FileSize:63187968 (Last=0) |
splashtop-setup.exe | [7228]2025-09-03 17:56:14 [CUnPack::UnPackFiles] (1/5)UnPack file name:C:\WINDOWS\TEMP\unpack\setup.msi (63187968) (Last=0) |
splashtop-setup.exe | [7228]2025-09-03 17:56:15 [CUnPack::UnPackFiles] UnPack count:1 len:63187968 File:(null) (Last=0) |
splashtop-setup.exe | [7228]2025-09-03 17:56:15 [CUnPack::UnPackFiles] FreeSpace:233048104960 FileSize:15 (Last=183) |
splashtop-setup.exe | [7228]2025-09-03 17:56:15 [CUnPack::UnPackFiles] (2/5)UnPack file name:C:\WINDOWS\TEMP\unpack\run.bat (15) (Last=122) |
splashtop-setup.exe | [7228]2025-09-03 17:56:15 [CUnPack::UnPackFiles] UnPack count:2 len:15 File:(null) (Last=0) |