| URL: | cdn-cookielaw.org |
| Full analysis: | https://app.any.run/tasks/21d064f2-e79d-4c34-b3f7-3843dfad870c |
| Verdict: | Malicious activity |
| Analysis date: | July 24, 2025, 23:25:25 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 4E5AF9E392B3AD182F19F5BF700BDF13 |
| SHA1: | EAE55654AF5C94D250C0BB2C049AF7BD824A09E1 |
| SHA256: | ACAC7F0192EF9AD1C9F3ABDA827EEE9B3CFFFEAC07158EB04190EE59B8374349 |
| SSDEEP: | 3:IKKjs7f:3KYr |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1520 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=7500,i,13125363514878026656,18099393537125145758,262144 --variations-seed-version --mojo-platform-channel-handle=7516 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 3836 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=7256,i,13125363514878026656,18099393537125145758,262144 --variations-seed-version --mojo-platform-channel-handle=7416 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 4232 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4300,i,13125363514878026656,18099393537125145758,262144 --variations-seed-version --mojo-platform-channel-handle=3948 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 5084 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2784,i,13125363514878026656,18099393537125145758,262144 --variations-seed-version --mojo-platform-channel-handle=2228 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 5416 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6928,i,13125363514878026656,18099393537125145758,262144 --variations-seed-version --mojo-platform-channel-handle=1452 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 5528 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=7232,i,13125363514878026656,18099393537125145758,262144 --variations-seed-version --mojo-platform-channel-handle=7404 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 5564 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x304,0x308,0x30c,0x2fc,0x314,0x7ffc444df208,0x7ffc444df214,0x7ffc444df220 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 5808 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "cdn-cookielaw.org" | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 6004 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --always-read-main-dll --field-trial-handle=7064,i,13125363514878026656,18099393537125145758,262144 --variations-seed-version --mojo-platform-channel-handle=6980 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 6344 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3620,i,13125363514878026656,18099393537125145758,262144 --variations-seed-version --mojo-platform-channel-handle=3672 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| (PID) Process: | (5808) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (5808) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (5808) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (5808) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (5808) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (5808) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (5808) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: 1C53E86C4B992F00 | |||
| (PID) Process: | (5808) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\524868 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {63D07DE7-60E0-4DBE-A6D3-09BA559C45A2} | |||
| (PID) Process: | (5808) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\524868 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {7878D0AE-2A08-4468-8D82-D55A4ED706A4} | |||
| (PID) Process: | (5808) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\524868 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {1D139661-FD15-4B78-B79D-EF4E47F1BCA4} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5808 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF18d973.TMP | — | |
MD5:— | SHA256:— | |||
| 5808 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5808 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF18d982.TMP | — | |
MD5:— | SHA256:— | |||
| 5808 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5808 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF18d982.TMP | — | |
MD5:— | SHA256:— | |||
| 5808 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5808 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF18d992.TMP | — | |
MD5:— | SHA256:— | |||
| 5808 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5808 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF18d9a2.TMP | — | |
MD5:— | SHA256:— | |||
| 5808 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF18d973.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6680 | msedge.exe | GET | 200 | 2.23.227.205:80 | http://r10.i.lencr.org/ | unknown | — | — | whitelisted |
6680 | msedge.exe | GET | 200 | 150.171.28.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:1HiC5L3GvwumimzTmMNX5m2kmdCVVYtFonM5cg7yZmk&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | unknown | — | — | whitelisted |
6680 | msedge.exe | GET | 200 | 103.224.182.206:80 | http://cuyuzu.com/jscheck.php?enc=3b6toGpCgmNnH4TF3EzHjH49fm5JNENqWkM4eTVxSWQ5Q3BCblF4WldNeitTZDV2OHZXdU1ENXl4dDE0UmtsVEdMOUZTQWdsZWh5eGdSaU9RRGlKbkNkWXNlRy9kQVdSUVhnK2RQcUVpblpnYWFITThEQzlzNTAxMUVzaU1YakQ5MkQ1UksyWVppdHBRZzNhQnpEamxSbHVrSDUxZk1rMlcvVGdNUHpnNk1ubTUzbVBocFI2cm5IT0NmRjRkVE02VmM1aUtTUTE1TExyNXZsc3dFM1JrSkVQdVZ6c05lcmFRenpGajN5VStyNlNPbWlSdHBrUks0bVhLWkZFZndzb3I4eENIdSt1cXNhV1RHNSt3UHhqZ01qV3R4WFZVaGdPc2RURmhMRTZlcklua05GYTFkVFAzSnVkNWpKM1BhL0ExdklZMVl2YU1SRThvSllzKzUrUU11WitxdkxOKzRNcEgxSGZxcElYbVhQSWtnQWl4SWhjb1VvWmZTZXk4YUloUllzbXc4dThYb0Npd3pzU0tvT3pzeU8xWkplOHd2dU1lR0lvR3grMFd3d0NJcTVPWmdaanBDZUgyb3JlZmJ2NUdPQlk5MGV4aHUxYVFsS1pWazJzSXlaN3lwWlhUZ0k2dDlTN0MrM1o0OEhKZ3IwNG9wMFVsL1NhRkxaYThCTVdmUU9WZXVlSGN5Nzg1SXlRYmxiaWdWblBnN2tsVk9DaXdVQ0Jad0ZHUTRUR21GUnVJcksrMGY4bWJ2cGk2ZnBLTk9OMFNKZ0RJbGxUS09iSkl5bmtyQytqWkRWS0pZRlY5VVZyUjBrcE9RQTQ3Z3Y3Y3NiZG5laXZDNkdKd25aT0JGYzdHSjk0YUN1VW9XWWZxZzg0d3lGbXNWdEprbDRVZ2NvOVA5ZkxjaFJVSWRHeUQzbWdpTU1ZZTMrL0NtcW5MZUZXanAzTktHaWk2cXphQVFDemt4OTJJdDZyZ2EyQncxbjA3N1BCL0t1ZlUzSWxsRENiY2w3ZEQ0dkEycWhZVlNmc1FEeGw2L3ZlKzc0THN1ZkhodG9CM1J0K3l1WlZCc0JnNldzdDJ0c1Q0N0RFeFgydGZIUHJZMWtEVHcyeFFsWFhaK3JkSEYyeXlBaFgrbVVkVDUvOFVRMUJmU0VjWmU2aEhhSFhTK3VINFdmdGZ1bnJtRVJ1d0UzcloySHVaVFJlWEVpY0lFOWlxZGlNOWhLV3pBamM5YXkvT3Q0ckYwV0RzM0l4cHVzcDR3QjdvQ21Zcmh1RTZTaG9kOGhWK2F0eDgzMEFkZmJFQ1FZcVdkSVZ6MWVjdDZaMVJCKzNWVEk4dDltTS80eDBCbFAvTU1TMGp3TForYUVxbGhvRDN4V25Pa1hMb0dnMjJ5WGduVkpsNTlHMUw4bnA4L0ZRRU5kZ3NqSUpBQ21LaU5Cc1VlU0txT2d2YVFBeXVnPQ%3D%3D&rand=0.8932226407859394&vs=1272:602&ds=1280:720&sl=0:0&os=f&nos=f&if=f&sc=f&gpu=Google%20Inc.%20(Google)%20-%20ANGLE%20(Google,%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE)),%20SwiftShader%20driver)&fp=-1 | unknown | — | — | unknown |
6680 | msedge.exe | GET | 200 | 103.224.182.206:80 | http://cuyuzu.com/xr.php?e=LosmRztMX6RpVOlb1V%2F6Rn49fnVTVlNKWkVNMjYyMGdvaWpWdkExNFNtbDBIZlE3SXYvMkVIR0hQNXVrOXMwa0hHWG1nY1FzdTYweHRBdGdkZ3dBR25Na21HUjJGWGZhdzV1OTdFR29zd2JxcG4zckRQWGVFM28va1NNQm1PRjZEUkF3L1ZGVG8zVytsMC8rY1Njd2hLS25lRm41Vk5wSFhjNm03bkpleVhBKzdiWGRPSmNQRG4vV3RPQjlSYXRBNHhPcEtxN0J1Qzc2QTlLR1EwNnlreWgrYzVES2dlcmZPMERHMWJDRWY1aktTcUkzNFdPdndDVDMyWkhORmpldEFENW5zOXNJS3pmMkdrd0h1VEg4WTV4ODdWZmZaL0NVT0JIcUQwSGpJMUovRGlEdWVkRU1XL0JLeU1mYXpLK25hdDQ0YVg3OCtqaFEzRFRubWxDR1M1ZGtERkVYTHVlT083UnFCSStCeHVSYUNmUFhKK1VYVUJyYVZjb1NHZ2dJanhBdDErdUlFMVRJeFlEN21hTzZBcmNubTVMZWV3VmtOajVkV1p1eUZxUUJRYTRVeFQwOHBrVmVES1d3TFRvS2cvZDdZc25YNU1SVHFRT3NxQ2hYS1JZMTV0L2M2QlhnNEhXWHpwYi9Ld3lJTGRpOEluc0FlMzhUN2dsZE9za3JWQ1ZzeXN3N2hnaTdhSmU5S3VLM0hmSGFiZXdjMDY2T1ZROTVCNVdrdEs5dmN2UHc3RVkwVnhOV1NlOFlUUU5ZMzRia29vdEUyY1prblV3QXBXNTdDVTB1YnRPWUgvR0JJbE5tSndNN3VaVXNyZTBzRGpob3JmZ2taL1FiUFJ3cXNobDRpQlJKQ2lTakpwV3pBUU9nOTExeUJGWGdyUE9LM2RTSXNjVVZWc1pONENFZi9iQUtQWnYxUHF6V05XYUhLUThFdG9qMm00Yi9mdUtmdG9tVjA1MHV3aFVTMTZGY211b0JadVcvRHFtb2pGVmVHa0tnWGZoSk1YNXNaVHRuYW5YVzFWMFlod2N0dUo1ZWg2eHk5d3N3MVQxd3AySjBhVlN6bnVMMVF4cUFzUlVFYjFYS3U5SjhpdkxxZm8vMGpEMFRWeXdibVhMTXBiVzVlS1Y1OXVCWWJNaGNGTVg4NysxSER3SFhreDNDa3ZQeGFuaTJ1VGd5NmNKZ01jVEdiMmJ2U3NSSzJBM3BTeTlOS1ZEZXIyYTVmcUI4cWVzQ3BKeno2L1ByZ2cyTlR2RVFLWWlCcmRiN1NOS2lFdjZocXViMEd5R052ZjJuclpmQTBiTjVMRWNIYSs3TGtSM0JiSGdzc2FvQkE9PQ%3D%3D | unknown | — | — | unknown |
6680 | msedge.exe | GET | 200 | 23.209.209.135:80 | http://x1.i.lencr.org/ | unknown | — | — | whitelisted |
6680 | msedge.exe | GET | — | 103.224.182.206:80 | http://cuyuzu.com/favicon.ico | unknown | — | — | unknown |
6680 | msedge.exe | GET | 302 | 103.224.182.206:80 | http://cuyuzu.com/r.php?u=https%3A%2F%2Fdxtrck.com%2Fclick%3Fkey%3Ddcb2f34c30b0beb279b3%26c%3D0.040%26t1%3D1737380511%26t2%3D4%26t3%3D0.040%26t4%3D1%26t5%3D1%26t6%3Ds&s=j&enc=3b6toGpCgmNnH4TF3EzHjH49fm5JNENqWkM4eTVxSWQ5Q3BCblF4WldNeitTZDV2OHZXdU1ENXl4dDE0UmtsVEdMOUZTQWdsZWh5eGdSaU9RRGlKbkNkWXNlRy9kQVdSUVhnK2RQcUVpblpnYWFITThEQzlzNTAxMUVzaU1YakQ5MkQ1UksyWVppdHBRZzNhQnpEamxSbHVrSDUxZk1rMlcvVGdNUHpnNk1ubTUzbVBocFI2cm5IT0NmRjRkVE02VmM1aUtTUTE1TExyNXZsc3dFM1JrSkVQdVZ6c05lcmFRenpGajN5VStyNlNPbWlSdHBrUks0bVhLWkZFZndzb3I4eENIdSt1cXNhV1RHNSt3UHhqZ01qV3R4WFZVaGdPc2RURmhMRTZlcklua05GYTFkVFAzSnVkNWpKM1BhL0ExdklZMVl2YU1SRThvSllzKzUrUU11WitxdkxOKzRNcEgxSGZxcElYbVhQSWtnQWl4SWhjb1VvWmZTZXk4YUloUllzbXc4dThYb0Npd3pzU0tvT3pzeU8xWkplOHd2dU1lR0lvR3grMFd3d0NJcTVPWmdaanBDZUgyb3JlZmJ2NUdPQlk5MGV4aHUxYVFsS1pWazJzSXlaN3lwWlhUZ0k2dDlTN0MrM1o0OEhKZ3IwNG9wMFVsL1NhRkxaYThCTVdmUU9WZXVlSGN5Nzg1SXlRYmxiaWdWblBnN2tsVk9DaXdVQ0Jad0ZHUTRUR21GUnVJcksrMGY4bWJ2cGk2ZnBLTk9OMFNKZ0RJbGxUS09iSkl5bmtyQytqWkRWS0pZRlY5VVZyUjBrcE9RQTQ3Z3Y3Y3NiZG5laXZDNkdKd25aT0JGYzdHSjk0YUN1VW9XWWZxZzg0d3lGbXNWdEprbDRVZ2NvOVA5ZkxjaFJVSWRHeUQzbWdpTU1ZZTMrL0NtcW5MZUZXanAzTktHaWk2cXphQVFDemt4OTJJdDZyZ2EyQncxbjA3N1BCL0t1ZlUzSWxsRENiY2w3ZEQ0dkEycWhZVlNmc1FEeGw2L3ZlKzc0THN1ZkhodG9CM1J0K3l1WlZCc0JnNldzdDJ0c1Q0N0RFeFgydGZIUHJZMWtEVHcyeFFsWFhaK3JkSEYyeXlBaFgrbVVkVDUvOFVRMUJmU0VjWmU2aEhhSFhTK3VINFdmdGZ1bnJtRVJ1d0UzcloySHVaVFJlWEVpY0lFOWlxZGlNOWhLV3pBamM5YXkvT3Q0ckYwV0RzM0l4cHVzcDR3QjdvQ21Zcmh1RTZTaG9kOGhWK2F0eDgzMEFkZmJFQ1FZcVdkSVZ6MWVjdDZaMVJCKzNWVEk4dDltTS80eDBCbFAvTU1TMGp3TForYUVxbGhvRDN4V25Pa1hMb0dnMjJ5WGduVkpsNTlHMUw4bnA4L0ZRRU5kZ3NqSUpBQ21LaU5Cc1VlU0txT2d2YVFBeXVnPQ%3D%3D&vs=1272:602&ds=1280:720&sl=0:0&os=f&nos=f&if=f&sc=f&gpu=Google%20Inc.%20(Google)%20-%20ANGLE%20(Google,%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE)),%20SwiftShader%20driver)&fp=-1 | unknown | — | — | unknown |
4168 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 23.55.110.211:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5468 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1268 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
7064 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6680 | msedge.exe | 150.171.28.11:80 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6680 | msedge.exe | 150.171.22.17:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6680 | msedge.exe | 150.171.28.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6680 | msedge.exe | 2.16.241.220:443 | copilot.microsoft.com | Akamai International B.V. | DE | whitelisted |
6680 | msedge.exe | 103.224.182.215:443 | cdn-cookielaw.org | Trellian Pty. Limited | AU | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
cdn-cookielaw.org |
| unknown |
copilot.microsoft.com |
| whitelisted |
cuyuzu.com |
| unknown |
x1.i.lencr.org |
| whitelisted |
r10.i.lencr.org |
| whitelisted |
www.bing.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6680 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Suspected Phishing Domain (cuyuzu .com) |
6680 | msedge.exe | Possible Social Engineering Attempted | SUSPICIOUS [ANY.RUN] Possible Malicious CrossDomain (*adguard .co .in) |
6680 | msedge.exe | Possible Social Engineering Attempted | SUSPICIOUS [ANY.RUN] Possible Malicious CrossDomain (*adguard .co .in) |
6680 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
6680 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
— | — | Potentially Bad Traffic | ET INFO Possible Chrome Plugin install |
6680 | msedge.exe | Possible Social Engineering Attempted | SUSPICIOUS [ANY.RUN] Possible Malicious CrossDomain (*adguard .co .in) |
6680 | msedge.exe | Possible Social Engineering Attempted | SUSPICIOUS [ANY.RUN] Possible Malicious CrossDomain (*adguard .co .in) |