File name:

regid.1991-06.com.microsoft_Windows-10-Home-Single-Language.swidtag

Full analysis: https://app.any.run/tasks/d0a71e9f-4f41-494c-8d0d-21f6ca4a4b07
Verdict: Malicious activity
Analysis date: January 29, 2025, 23:08:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
Indicators:
MIME: text/xml
File info: XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
MD5:

739A05FF7382BB1456DEC8D66DFC54E0

SHA1:

C815B7272D6594034A41C65D25C89F80B0C270CA

SHA256:

AE67BDC9B04F4D6050557CD39AFEBA2327E61F3B27060781C2EFBBF10B5A6614

SSDEEP:

24:Jd4T7gwAchTGBLOy+B6HcHGuDyeHRuDye6MMFiP6euDyRtz:34T5DVG8y+s8HGuDyeHRuDye6MMFiP66

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • CCleaner64.exe (PID: 7956)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • CCleaner64.exe (PID: 7744)
      • CCleaner64.exe (PID: 7956)
      • CCleaner64.exe (PID: 7592)
    • Reads the date of Windows installation

      • CCleaner64.exe (PID: 7744)
      • CCleaner64.exe (PID: 7592)
      • msiexec.exe (PID: 6712)
    • Application launched itself

      • CCleaner64.exe (PID: 7744)
      • CCleaner64.exe (PID: 7592)
    • Reads Internet Explorer settings

      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
    • Executable content was dropped or overwritten

      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
    • Searches for installed software

      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
      • CCleanerPerformanceOptimizerService.exe (PID: 4428)
    • Checks Windows Trust Settings

      • CCleaner64.exe (PID: 7956)
      • CCleaner64.exe (PID: 7592)
    • The process verifies whether the antivirus software is installed

      • CCleaner64.exe (PID: 7956)
    • Checks for external IP

      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6776)
      • CCleanerPerformanceOptimizerService.exe (PID: 4428)
    • Query current time using 'w32tm.exe'

      • CCleaner64.exe (PID: 7592)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6712)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 6712)
    • Detected use of alternative data streams (AltDS)

      • CCleaner64.exe (PID: 7592)
    • Checks for Java to be installed

      • CCleanerPerformanceOptimizerService.exe (PID: 4428)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 6712)
    • Starts application from unusual location

      • CCleaner64.exe (PID: 7592)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 6576)
      • msedge.exe (PID: 8092)
    • Checks supported languages

      • identity_helper.exe (PID: 7356)
      • identity_helper.exe (PID: 3608)
      • CCleaner64.exe (PID: 7744)
      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
      • msiexec.exe (PID: 6712)
      • CCleanerPerformanceOptimizerService.exe (PID: 4428)
    • Reads the computer name

      • identity_helper.exe (PID: 7356)
      • identity_helper.exe (PID: 3608)
      • CCleaner64.exe (PID: 7744)
      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
      • msiexec.exe (PID: 6712)
      • CCleanerPerformanceOptimizerService.exe (PID: 4428)
    • Reads Environment values

      • identity_helper.exe (PID: 7356)
      • identity_helper.exe (PID: 3608)
      • CCleaner64.exe (PID: 7744)
      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
      • msiexec.exe (PID: 6712)
      • CCleanerPerformanceOptimizerService.exe (PID: 4428)
    • Manual execution by a user

      • CCleaner64.exe (PID: 7744)
      • msiexec.exe (PID: 6904)
    • Process checks computer location settings

      • CCleaner64.exe (PID: 7744)
      • CCleaner64.exe (PID: 7592)
    • Reads the software policy settings

      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
    • Reads CPU info

      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
      • CCleanerPerformanceOptimizerService.exe (PID: 4428)
    • Reads product name

      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
      • msiexec.exe (PID: 6712)
    • Reads the machine GUID from the registry

      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
      • msiexec.exe (PID: 6712)
      • CCleanerPerformanceOptimizerService.exe (PID: 4428)
    • Creates files in the program directory

      • CCleaner64.exe (PID: 7592)
      • CCleaner64.exe (PID: 7956)
      • CCleanerPerformanceOptimizerService.exe (PID: 4428)
    • The sample compiled with english language support

      • CCleaner64.exe (PID: 7956)
      • CCleaner64.exe (PID: 7592)
      • msiexec.exe (PID: 6712)
    • Checks proxy server information

      • CCleaner64.exe (PID: 7956)
      • CCleaner64.exe (PID: 7592)
    • Creates files or folders in the user directory

      • CCleaner64.exe (PID: 7592)
    • Manages system restore points

      • SrTasks.exe (PID: 7448)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6712)
    • Create files in a temporary directory

      • CCleaner64.exe (PID: 7592)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xml | Generic XML (UTF-8) (72.7)
.txt | Text - UTF-8 encoded (27.2)

EXIF

XMP

Software_identification_tagXmlns: http://standards.iso.org/iso/19770/-2/2009/schema.xsd
Software_identification_tagEntitlement_required_indicator:
Software_identification_tagProduct_title: Windows 10 Home Single Language
Software_identification_tagProduct_versionName: 10.0.26100.2605
Software_identification_tagProduct_versionNumericMajor: 10
Software_identification_tagProduct_versionNumericMinor: -
Software_identification_tagProduct_versionNumericBuild: 26100
Software_identification_tagProduct_versionNumericReview: 2605
Software_identification_tagSoftware_creatorName: Microsoft Corporation
Software_identification_tagSoftware_creatorRegid: regid.1991-06.com.microsoft
Software_identification_tagSoftware_licensorName: Microsoft Corporation
Software_identification_tagSoftware_licensorRegid: regid.1991-06.com.microsoft
Software_identification_tagSoftware_idUnique_id: Windows-10-Home-Single-Language
Software_identification_tagSoftware_idTag_creator_regid: regid.1991-06.com.microsoft
Software_identification_tagTag_creatorName: Microsoft Corporation
Software_identification_tagTag_creatorRegid: regid.1991-06.com.microsoft
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
202
Monitored processes
65
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs ccleaner64.exe no specs ccleaner64.exe ccleaner64.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs w32tm.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs ccleanerperformanceoptimizerservice.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
308"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2652 --field-trial-handle=2296,i,17422439571019930026,3754380647825587758,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
936\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exereg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1328"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5300 --field-trial-handle=2296,i,17422439571019930026,3754380647825587758,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1580"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3284 --field-trial-handle=2296,i,17422439571019930026,3754380647825587758,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1684"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5544 --field-trial-handle=2380,i,4506462659712701500,17779629527678949987,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1704"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=5296 --field-trial-handle=2380,i,4506462659712701500,17779629527678949987,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1804"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3188 --field-trial-handle=2296,i,17422439571019930026,3754380647825587758,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2088"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=4992 --field-trial-handle=2296,i,17422439571019930026,3754380647825587758,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2216"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=4980 --field-trial-handle=2296,i,17422439571019930026,3754380647825587758,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2572"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3288 --field-trial-handle=2296,i,17422439571019930026,3754380647825587758,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
73 585
Read events
70 558
Write events
281
Delete events
2 746

Modification events

(PID) Process:(6368) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6368) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6368) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6368) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(6368) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(6368) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:DisableFirstRunCustomize
Value:
1
(PID) Process:(6576) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6576) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6576) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6576) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
Executable files
761
Suspicious files
1 419
Text files
265
Unknown types
2

Dropped files

PID
Process
Filename
Type
6576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF136f96.TMP
MD5:
SHA256:
6576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF136f96.TMP
MD5:
SHA256:
6576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF136fb5.TMP
MD5:
SHA256:
6576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF136fc4.TMP
MD5:
SHA256:
6576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF136fb5.TMP
MD5:
SHA256:
6576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
6576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
47
TCP/UDP connections
150
DNS requests
61
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
104.81.99.218:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6572
svchost.exe
GET
206
199.232.18.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0eacf79d-f97c-4c0a-8b56-aaf4fc94da08?P1=1738720102&P2=404&P3=2&P4=A4DdAUoDGpxES3zQrg543czVIne%2bKXqftt5LX6Ne9tANc7paqlP%2bqW0HaRIOe%2fgIuFaOPHhpt6XJQSkJ4wDbog%3d%3d
unknown
whitelisted
6572
svchost.exe
GET
206
199.232.18.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0eacf79d-f97c-4c0a-8b56-aaf4fc94da08?P1=1738720102&P2=404&P3=2&P4=A4DdAUoDGpxES3zQrg543czVIne%2bKXqftt5LX6Ne9tANc7paqlP%2bqW0HaRIOe%2fgIuFaOPHhpt6XJQSkJ4wDbog%3d%3d
unknown
whitelisted
6572
svchost.exe
GET
206
199.232.18.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0eacf79d-f97c-4c0a-8b56-aaf4fc94da08?P1=1738720102&P2=404&P3=2&P4=A4DdAUoDGpxES3zQrg543czVIne%2bKXqftt5LX6Ne9tANc7paqlP%2bqW0HaRIOe%2fgIuFaOPHhpt6XJQSkJ4wDbog%3d%3d
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
104.85.249.145:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2356
svchost.exe
GET
200
104.85.249.145:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2356
svchost.exe
GET
200
23.59.85.133:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4500
RUXIMICS.exe
GET
200
23.59.85.133:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.59.85.133:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7592
CCleaner64.exe
GET
200
104.85.249.99:80
http://ncc.avast.com/ncc.txt
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5064
SearchApp.exe
2.18.29.201:443
www.bing.com
Akamai International B.V.
PL
whitelisted
4
System
192.168.100.255:138
whitelisted
2356
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
104.81.99.218:80
ocsp.digicert.com
AKAMAI-AS
PL
whitelisted
4712
MoUsoCoreWorker.exe
104.85.249.145:80
crl.microsoft.com
Akamai International B.V.
PL
whitelisted
2356
svchost.exe
104.85.249.145:80
crl.microsoft.com
Akamai International B.V.
PL
whitelisted
4500
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4500
RUXIMICS.exe
23.59.85.133:80
www.microsoft.com
AKAMAI-AS
PL
whitelisted
4712
MoUsoCoreWorker.exe
23.59.85.133:80
www.microsoft.com
AKAMAI-AS
PL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 216.58.215.78
whitelisted
ocsp.digicert.com
  • 104.81.99.218
whitelisted
crl.microsoft.com
  • 104.85.249.145
whitelisted
www.microsoft.com
  • 23.59.85.133
  • 23.200.161.157
whitelisted
config.edge.skype.com
  • 52.123.243.224
whitelisted
edge.microsoft.com
  • 204.79.197.239
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.44
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
bzib.nelreports.net
  • 104.85.249.146
whitelisted

Threats

PID
Process
Class
Message
2192
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
7592
CCleaner64.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
7956
CCleaner64.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
Process
Message
CCleaner64.exe
[2025-01-29 23:09:12.589] [error ] [settings ] [ 7592: 7700] [000000: 0] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner64.exe
[2025-01-29 23:09:12.589] [error ] [ini_access ] [ 7592: 7700] [000000: 0] Incorrect ini_accessor configuration! Fixing relative input path to avoid recursion. Input was: Setup
CCleaner64.exe
Failed to open log file 'C:\Program Files\CCleaner'
CCleaner64.exe
OnLanguage - en
CCleaner64.exe
[2025-01-29 23:09:13.167] [error ] [settings ] [ 7592: 7620] [D2EC45: 356] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner64.exe
[2025-01-29 23:09:13.182] [error ] [Burger ] [ 7592: 7620] [904E07: 253] [23.2.1118.0] [BurgerReporter.cpp] [253] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner64.exe
[2025-01-29 23:09:13.182] [error ] [Burger ] [ 7592: 7620] [904E07: 253] [23.2.1118.0] [BurgerReporter.cpp] [253] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner64.exe
file:///tis/optimizer.tis(1131) : warning :'await' should be used only inside 'async' or 'event'
CCleaner64.exe
file:///tis/optimizer.tis(1288) : warning :'async' does not contain any 'await'
CCleaner64.exe
OnLanguage - en