File name:

notificación_judicial__demanda_penal_por_daños__fiscalía_general_20_1N9XP2.svg

Full analysis: https://app.any.run/tasks/5425c3a9-dab4-48df-a503-cbb23c8cff7f
Verdict: Malicious activity
Threats:

HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses.

Analysis date: September 03, 2025, 17:44:20
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
qrcode
auto
generic
hijackloader
loader
amsi-bypass
stealer
Indicators:
MIME: image/svg+xml
File info: SVG Scalable Vector Graphics image
MD5:

B680902109369B56D43506B9D6308C98

SHA1:

5096EFDB96EB04837C078C79E2A5C5CA580BBA03

SHA256:

AD970085556CA674590105BD533EFA75D512BA4A9259C702B161CB3AD8EA0A7A

SSDEEP:

49152:CYocyAl7W7Z7BZ3NYS7grrpEVPam7nXgZUhKxjl3n4IHoPzhMTP/D6hDXajONg0o:h

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GENERIC has been found (auto)

      • WinRAR.exe (PID: 4512)
    • HIJACKLOADER has been detected (YARA)

      • 03 BOLETA JUDICIAL.exe (PID: 7632)
      • 03 BOLETA JUDICIAL.exe (PID: 4844)
      • 03 BOLETA JUDICIAL.exe (PID: 4552)
      • 03 BOLETA JUDICIAL.exe (PID: 8308)
      • 03 BOLETA JUDICIAL.exe (PID: 5028)
    • Executing a file with an untrusted certificate

      • PhotonDrive32.exe (PID: 4044)
      • PhotonDrive32.exe (PID: 8068)
      • PhotonDrive32.exe (PID: 5824)
      • PhotonDrive32.exe (PID: 2648)
      • PhotonDrive32.exe (PID: 8456)
    • Actions looks like stealing of personal data

      • PhotonDrive32.exe (PID: 4044)
  • SUSPICIOUS

    • Contacting a server suspected of hosting an CnC

      • PhotonDrive32.exe (PID: 4044)
    • Executable content was dropped or overwritten

      • 03 BOLETA JUDICIAL.exe (PID: 7632)
      • 03 BOLETA JUDICIAL.exe (PID: 8308)
    • Possibly patching Antimalware Scan Interface function (YARA)

      • PhotonDrive32.exe (PID: 4044)
      • PhotonDrive32.exe (PID: 5824)
      • PhotonDrive32.exe (PID: 2648)
      • PhotonDrive32.exe (PID: 8456)
    • Connects to unusual port

      • PhotonDrive32.exe (PID: 4044)
  • INFO

    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 7136)
      • explorer.exe (PID: 4456)
    • Reads Environment values

      • identity_helper.exe (PID: 7640)
      • identity_helper.exe (PID: 7792)
    • Reads the computer name

      • identity_helper.exe (PID: 7640)
      • identity_helper.exe (PID: 7792)
      • 03 BOLETA JUDICIAL.exe (PID: 7632)
      • PhotonDrive32.exe (PID: 4044)
      • 03 BOLETA JUDICIAL.exe (PID: 4844)
      • 03 BOLETA JUDICIAL.exe (PID: 4552)
      • PhotonDrive32.exe (PID: 8068)
      • Chime.exe (PID: 8168)
      • PhotonDrive32.exe (PID: 5824)
      • Chime.exe (PID: 8124)
      • Chime.exe (PID: 8300)
      • 03 BOLETA JUDICIAL.exe (PID: 8308)
      • 03 BOLETA JUDICIAL.exe (PID: 5028)
      • PhotonDrive32.exe (PID: 2648)
      • PhotonDrive32.exe (PID: 8456)
    • Checks supported languages

      • identity_helper.exe (PID: 7640)
      • identity_helper.exe (PID: 7792)
      • 03 BOLETA JUDICIAL.exe (PID: 7632)
      • PhotonDrive32.exe (PID: 4044)
      • 03 BOLETA JUDICIAL.exe (PID: 4844)
      • 03 BOLETA JUDICIAL.exe (PID: 4552)
      • PhotonDrive32.exe (PID: 8068)
      • Chime.exe (PID: 8168)
      • PhotonDrive32.exe (PID: 5824)
      • Chime.exe (PID: 8124)
      • Chime.exe (PID: 8300)
      • 03 BOLETA JUDICIAL.exe (PID: 8308)
      • 03 BOLETA JUDICIAL.exe (PID: 5028)
      • PhotonDrive32.exe (PID: 2648)
      • PhotonDrive32.exe (PID: 8456)
    • Application launched itself

      • msedge.exe (PID: 5084)
      • firefox.exe (PID: 952)
      • firefox.exe (PID: 5460)
    • Manual execution by a user

      • msedge.exe (PID: 8048)
      • WinRAR.exe (PID: 4512)
      • 03 BOLETA JUDICIAL.exe (PID: 7632)
      • 03 BOLETA JUDICIAL.exe (PID: 4844)
      • 03 BOLETA JUDICIAL.exe (PID: 4552)
      • firefox.exe (PID: 952)
      • 03 BOLETA JUDICIAL.exe (PID: 8308)
      • 03 BOLETA JUDICIAL.exe (PID: 5028)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 5084)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 4512)
      • 03 BOLETA JUDICIAL.exe (PID: 7632)
    • Reads the software policy settings

      • slui.exe (PID: 8076)
      • PhotonDrive32.exe (PID: 4044)
    • Checks proxy server information

      • slui.exe (PID: 8076)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4512)
    • Creates files in the program directory

      • 03 BOLETA JUDICIAL.exe (PID: 7632)
    • Create files in a temporary directory

      • 03 BOLETA JUDICIAL.exe (PID: 7632)
      • 03 BOLETA JUDICIAL.exe (PID: 4844)
      • 03 BOLETA JUDICIAL.exe (PID: 4552)
      • Chime.exe (PID: 8168)
      • 03 BOLETA JUDICIAL.exe (PID: 8308)
      • 03 BOLETA JUDICIAL.exe (PID: 5028)
    • Reads the machine GUID from the registry

      • PhotonDrive32.exe (PID: 4044)
      • PhotonDrive32.exe (PID: 8068)
      • PhotonDrive32.exe (PID: 5824)
      • PhotonDrive32.exe (PID: 2648)
      • PhotonDrive32.exe (PID: 8456)
    • Creates files or folders in the user directory

      • 03 BOLETA JUDICIAL.exe (PID: 7632)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 5460)
      • OpenWith.exe (PID: 9084)
      • OpenWith.exe (PID: 2428)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.svg | Scalable Vector Graphics (var.1) (62.5)
.html | HyperText Markup Language (37.5)

EXIF

SVG

Data-0a3dfc164c5782be986bd58c: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_daf38c78d63c42122531c41581d31d71fadb7a0918cd814393074aadc8261613731c941aeb9baae631d7b828d58d26b71bd812376c217193098a560ec9b35686
Data-dda9842599eb40851846c3ac: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_5ebd4c0e9adebc5a0c6d85ef4dd0c57300e56c1f78d5e77ab10cd1eff0ac38dc6d73fdfee5bad92f393b801600d4fce966850bf667767465e2d2671eddc88501
Data-5b11c92bdf07de9cf70bb2af: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_c2794f266e7c5fb9bd649a38b5d02fecb4bef13964f4b759b0116cd484d76f5704eca2174dd9cac028c493fe5a997700b30b4afe5598168947dfedaaa422c325
Data-0be83af8fb0357ab33a60e46: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_c8076611bf18fcdcf8a6815a900c4d24a8c37595fa8955c0c0d421bfd5375da224373601512751a56afb67e6d6269e91d143951b479b5a77161ac2a5464a54d3
Data-b8a6785a24eee4e7e6d46023: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_f9d2e312ac06931d0fba3bb0e16a1a88340ead6f7bca630feabc36a8db1bb1e3ab7bbb065adfc06c8e462b50cca7d9a50e2bd9b64df89878489edd3020d6ef6f
Data-a046970d7cf67f3f2c609316: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_63ffb6e52dbc6a36a25facec849e9ba40dc257c94c2488c1d0c510794c75e0daf8edc2a1d6d36ee4bdbcd44027a7accf96394cf94a11c3667ef11020c2699da7
Data-d37f157b614831d7a8aff9ea: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_caafa722a6ea8c597fe80065c522e86bfbe95ba0db5f3c6aaa3ba6f4c7dc6ee9fddfb588a892829290a2357793914fdda910ebe37d88d5871f346049d102c005
Data-1cb155a401d00f3f7f629d3a: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_174e3a300a9602b98e8c8a86f2b3b3e705e8dd75b92734f4192b04b7e91e5be5effaf546a408b764915f5cbaf5b2b341f4a7611684d25cbe487a8723c30b91ca
Data-e9ca67df8f4beccb7ce608d3: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_bda863cc68cbf9695ed3ce8388283fc9185cb6593b7e8f515298ed2d425963cf379af692f0b90c327172044c18f3c7f80cb70d19c507d6cce8ca76fed708e483
Data-5f877da4687dd57d4e5b5f9d: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_b5a2626c32b0dea79aa46a5b355e3b59792ef452fd8932b1dd3ba3a27e567cdf20d30eb49d77680d0d69ec4ae0da3b24d577566a771f5ccb5a656527ac9eed53
Data-cb19dcc4b6f5a1778d581ced: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_c7245fc0a846d8b3f1ed516ea3065fe90dadb9478c7b0a055ebd7a0dbb103ba3772452d70554d1b48f16a023a0c4c62e180311472a4cc310b3b0eacaf15dd174
Data-6f68ef3f1b6496516f1d2375: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_3210a2d9d13e79beba3e8b660e4a664c16673372477a963326ac52502f6c48af338a6f615767991d4c6c4c96a32e2bed6c774719f6fd6c152bc6ad16738b814e
Data-59623f1593b779fb616c4e6f: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_4096e1d86cff910244bd25efb6ca5920ae1663ed7958d10867549d12981ad390dfb4c5b3efe4f9d1fdbaef2b95e3a31a32601fc906e49e71e36bc5d40661f6f2
Data-cf78334743c43d7796ed4f8a: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_3d756a846fe1ebc35ea14742b3fb104d4862d696ffdee29981da3a377729a13fc3fd5e3e8644c7299ed0242a24b60b9aa10cc5ffab56349642cc3d6807229706
Data-c3572fd8eb4f301993a18f3f: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_5f29f84dea9f684f16d9763e9abd5ad6c7ebbcb1c3398885cc0d3db781334a4bfc0204fc52cd4a136e55c856716ef26860da9829161aef01cb078cfad5c21b70
Data-1353e6db1f3b31047b26bad5: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_09253b698e44f2b5b59bf478e32239db08672d8d4c2b1924f9e69ff23be6687153c370d1bc78083f0f08995a4b1221b5d99635c0d42417f3d3b425e20dc9d315
Data-0cdfe7cdf852bc16446c4acc: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_711f527ad11635913867f22dea8baff74335f69c3185a5a7039edde77a0fb3e6c9212652669cc3f7fa898af24b84a77c9dcf7e167a81b4c173684fa64feb1f6e
Data-c0849c7841866516f82d310c: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_170ee6c8756915da7b653cc369a0103efddbfeec6dc780f1e3eaa17213d27aa40727ccb48ad7874c009be1aec510a39175629080125ec503cfe40882316e1daa
Data-a26c05a73319afe6fc251ffe: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_870730196ba9162f3066a4dcde8d5edcaa26facc94e13f9958d9aa87e6ca08200580b48cabb8d9fefee5a40d792e67aba21855fcc4bd2d8f2379122d939fd47a
Data-7c7921ac3804f5f9f4a4d6e9: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_3e2913ef17098dc16a581fb43419a65f3d9b36a007bda54be320a9262df042c0e5044ccf9ee4beaa2b4d5aa4626f9818926eb988b8367e7cc5165d3e088d1abd
Data-872928722da1fbc409cb5e58: 92b921ebfeb2_52ac6942e12a4845be80352bd473797f_25f17634618b474a_f4de52f7a2c91c5171984d54d07793b8ddf0c5392a273c54bfd2c10d883bbcc2a8afd8c108e66c10139897d171600baad1ee4939c7aa3d37a9d823a78d52ab90
Onclick: openDocument()
Style: cursor: pointer;
SVGVersion: 1.1
ViewBox: 0.0 0.0 960.0 720.0
Fill: none
Stroke: none
Stroke-linecap: square
Stroke-miterlimit: 10
Xmlns: http://www.w3.org/2000/svg
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
230
Monitored processes
80
Malicious processes
7
Suspicious processes
4

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
512"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3660,i,14876989736683132369,13698303433534927723,262144 --variations-seed-version --mojo-platform-channel-handle=3620 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
620"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=1280,i,14876989736683132369,13698303433534927723,262144 --variations-seed-version --mojo-platform-channel-handle=5288 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
952"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\crypt32.dll
1180"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2456,i,14876989736683132369,13698303433534927723,262144 --variations-seed-version --mojo-platform-channel-handle=2436 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1520"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=1532,i,14876989736683132369,13698303433534927723,262144 --variations-seed-version --mojo-platform-channel-handle=6108 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1636"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_collections.mojom.CollectionsDataManager --lang=en-US --service-sandbox-type=collections --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6500,i,14876989736683132369,13698303433534927723,262144 --variations-seed-version --mojo-platform-channel-handle=5788 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1740"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5096 -prefsLen 39068 -prefMapHandle 5080 -prefMapSize 272997 -jsInitHandle 3868 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4836 -initialChannelId {6b4e3759-69eb-42cf-a172-344f6f502000} -parentPid 5460 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5460" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2124"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x304,0x308,0x30c,0x2fc,0x314,0x7ffc444bf208,0x7ffc444bf214,0x7ffc444bf220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2200C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2428C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
25 377
Read events
25 336
Write events
41
Delete events
0

Modification events

(PID) Process:(4456) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4456) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4456) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5084) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(5084) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(5084) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(5084) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
414C99707F9C2F00
(PID) Process:(5084) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(5084) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\459528
Operation:writeName:WindowTabManagerFileMappingId
Value:
{4F7946B0-8C1A-4F40-8995-55AB2DC95A11}
(PID) Process:(5084) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\459528
Operation:writeName:WindowTabManagerFileMappingId
Value:
{5177EEF9-9A36-41AC-9A89-71D63C1D10E3}
Executable files
18
Suspicious files
546
Text files
93
Unknown types
0

Dropped files

PID
Process
Filename
Type
5084msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF18d666.TMP
MD5:
SHA256:
5084msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF18d666.TMP
MD5:
SHA256:
5084msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
5084msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF18d656.TMP
MD5:
SHA256:
5084msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
5084msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF18d675.TMP
MD5:
SHA256:
5084msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
5084msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
5084msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF18d694.TMP
MD5:
SHA256:
5084msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF18d694.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
49
TCP/UDP connections
132
DNS requests
181
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4984
msedge.exe
GET
200
104.18.38.233:80
http://crt.sectigo.com/SectigoRSAOrganizationValidationSecureServerCA.crt
unknown
binary
1.53 Kb
whitelisted
4984
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:zDBrt549yt_d7wPObOq09J0gahocPnJ7yIAUR2X0Sds&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
98 b
whitelisted
7620
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
6240
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
7620
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
407 b
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
1268
svchost.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
7048
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1756990313&P2=404&P3=2&P4=bNGW2dgFFV7lN73ONAhBFl9Gv%2fG2BQW7TTnc9DjAoPGUvnfq1hg0t1XPUzl5ZF4l%2bPzJwPkZEc%2bSHI8J2AGbRw%3d%3d
US
whitelisted
7048
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1756990313&P2=404&P3=2&P4=bNGW2dgFFV7lN73ONAhBFl9Gv%2fG2BQW7TTnc9DjAoPGUvnfq1hg0t1XPUzl5ZF4l%2bPzJwPkZEc%2bSHI8J2AGbRw%3d%3d
US
binary
1.09 Kb
whitelisted
7048
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1756990313&P2=404&P3=2&P4=bNGW2dgFFV7lN73ONAhBFl9Gv%2fG2BQW7TTnc9DjAoPGUvnfq1hg0t1XPUzl5ZF4l%2bPzJwPkZEc%2bSHI8J2AGbRw%3d%3d
US
compressed
764 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4700
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4984
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4984
msedge.exe
150.171.27.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4984
msedge.exe
190.157.218.19:443
sicecon.fiscalia.gov.co
Telmex Colombia S.A.
CO
suspicious
4984
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4984
msedge.exe
92.123.104.53:443
copilot.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.174
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
sicecon.fiscalia.gov.co
  • 190.157.218.19
unknown
copilot.microsoft.com
  • 92.123.104.53
  • 92.123.104.45
whitelisted
crt.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
www.bing.com
  • 2.16.241.207
  • 2.16.241.218
  • 2.16.241.205
  • 2.16.241.222
  • 2.16.241.201
whitelisted
ajax.googleapis.com
  • 142.250.186.138
whitelisted
maxcdn.bootstrapcdn.com
  • 104.18.11.207
  • 104.18.10.207
whitelisted

Threats

PID
Process
Class
Message
4984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
4984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
4984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] BootstrapCDN (maxcdn .bootstrapcdn .com)
4984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] BootstrapCDN (maxcdn .bootstrapcdn .com)
4984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
4984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] BootstrapCDN (maxcdn .bootstrapcdn .com)
4984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
4984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] BootstrapCDN (maxcdn .bootstrapcdn .com)
2200
svchost.exe
Potentially Bad Traffic
ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain
2200
svchost.exe
Misc activity
ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain
No debug info