File name:

WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe

Full analysis: https://app.any.run/tasks/d7b73038-5a7e-4305-befd-47ab308b857f
Verdict: Malicious activity
Analysis date: January 20, 2024, 08:16:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C353F9C678EA37375EB1542D29B23B2F

SHA1:

1DF5FB74DD84DD973CE91C01935CAA743BC9590A

SHA256:

B070797029681E05D41C6A8A1219C6DAD375443C58A824288623020658A63FDF

SSDEEP:

98304:zf13rs3o8yb5FD+0lUpO4dVjgFPDRdtoM3CQNpfcmoHuUoxppO094L13HJ0jn5rL:NlA6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Drops 7-zip archiver for unpacking

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Creates/Modifies COM task schedule object

      • uninstall.exe (PID: 1824)
    • Reads Microsoft Outlook installation path

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Reads the Internet Settings

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Searches for installed software

      • uninstall.exe (PID: 1824)
    • Creates a software uninstall entry

      • uninstall.exe (PID: 1824)
    • Reads Internet Explorer settings

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
  • INFO

    • Reads the computer name

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
      • uninstall.exe (PID: 1824)
      • wmpnscfg.exe (PID: 3308)
    • Checks supported languages

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
      • uninstall.exe (PID: 1824)
      • wmpnscfg.exe (PID: 3308)
    • Creates files in the program directory

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Application launched itself

      • msedge.exe (PID: 1848)
      • msedge.exe (PID: 2668)
    • Checks proxy server information

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3308)
      • msedge.exe (PID: 2668)
    • Reads the machine GUID from the registry

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:08:11 15:54:17+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 187392
InitializedDataSize: 316416
UninitializedDataSize: -
EntryPoint: 0x1c869
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 7.0.3.0
ProductVersionNumber: 7.0.3.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Email: inFo@Dr-FarFar.CoM
Website: https://www.Dr-FarFar.com
Comments: www.Dr-FarFar.com
CompanyName: Dr.FarFar | www.Dr-FarFar.com
FileDescription: WinRAR Full Activated [ViP]
FileVersion: 7.0.3
InternalName: WinRAR.exe
LegalCopyright: Copyright © Dr.FarFar
LegalTrademarks: WinRAR Full Activated [ViP]
OriginalFileName: WinRAR.exe
ProductName: WinRAR Full Activated [ViP]
ProductVersion: 7.0.3
AssemblyVersion: 7.0.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
17
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar v7.00 b3 official release (32-bit) pre-activated - unlocked.exe msedge.exe no specs uninstall.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs winrar v7.00 b3 official release (32-bit) pre-activated - unlocked.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe" C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeexplorer.exe
User:
admin
Company:
Dr.FarFar | www.Dr-FarFar.com
Integrity Level:
MEDIUM
Description:
WinRAR Full Activated [ViP]
Exit code:
3221226540
Version:
7.0.3
Modules
Images
c:\users\admin\appdata\local\temp\winrar v7.00 b3 official release (32-bit) pre-activated - unlocked.exe
c:\windows\system32\ntdll.dll
952"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1560 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
980"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1256 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1000"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2324 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1824"C:\Program Files\WinRAR\uninstall.exe" /setupC:\Program Files\WinRAR\uninstall.exeWinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
Uninstall WinRAR
Exit code:
0
Version:
7.0.3
Modules
Images
c:\program files\winrar\uninstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1848"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&cad=rja&uact=8&ved=2ahUKEwisysKe7q_mAhVG-YUKHVZDAZ4QFjABegQIBxAC&url=https%3A%2F%2Fwww.dr-farfar.com%2F&usg=AOvVaw22hlzBu7hxTxcihgNzrn0CC:\Program Files\Microsoft\Edge\Application\msedge.exeWinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2080"C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe" C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe
explorer.exe
User:
admin
Company:
Dr.FarFar | www.Dr-FarFar.com
Integrity Level:
HIGH
Description:
WinRAR Full Activated [ViP]
Exit code:
0
Version:
7.0.3
Modules
Images
c:\users\admin\appdata\local\temp\winrar v7.00 b3 official release (32-bit) pre-activated - unlocked.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\rsaenh.dll
2172"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6d5af598,0x6d5af5a8,0x6d5af5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2176"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2332 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2260"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1456 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
2 657
Read events
2 545
Write events
110
Delete events
2

Modification events

(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\WinRAR SFX
Operation:writeName:C%%Program Files%WinRAR
Value:
C:\Program Files\WinRAR
(PID) Process:(1848) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1848) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1848) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
Executable files
9
Suspicious files
47
Text files
42
Unknown types
0

Dropped files

PID
Process
Filename
Type
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\Rar.txttext
MD5:DE18B212376C6351232039575C71BDD7
SHA256:5B18E832C6DDB6CBB1E37C41908C133DCD52C99AB768DB9E805A03D04254272F
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\Descript.iontext
MD5:84846ABC52DC17020E4E934D3C94B4E6
SHA256:3449FD40D054C96285FAB92011E732174C7CD000EDA67470376F26F0D431F1F2
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\UnRAR.exeexecutable
MD5:C3437BE06208AA4CF8CE2C899293F43A
SHA256:8B24E0D5EFEE0672049EB892902A7C0D35491335C732DA1A5F4F11F77528B8DB
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\ReadMe.txttext
MD5:00D0A57A6D64EE3DE8F4D5529D6C6447
SHA256:FCD13E1B97AF47B8B923BA97AE15E9731C66093609667C3171D5DD24A6F7F2E6
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\WhatsNew.txttext
MD5:1E20F9C6E797DE34B535C4BD60D2E67B
SHA256:C37C22417D6658B293CD1F963D3E2414BFBA74FC573D2BB597B28706D15F8816
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\7zxa.dllexecutable
MD5:6161EB75F65FABE5D05448FA5D7908B4
SHA256:23D67D4BCD765355C85B831279D61F46B641E7B8F3ED772ADA8C915E5DEA9CB5
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\Web.urltext
MD5:F8CC1FBD549B5A9A187FC6AAC948BC45
SHA256:06187D0DEB8B2FAF4B9F51B9006A0D5435CBCBE62F321926DA48E2D3415DABAD
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\RarFiles.lsttext
MD5:E70E22D45ECB35217D66A4CE30F081FA
SHA256:9EB1099D7231CD24D8740609D3AC6985139F2334730356DF983AB01D7896AD6F
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\Rar.exeexecutable
MD5:C5DF49162C46861E74622A2C5FB98902
SHA256:9849DD08B2C5DE7106F5FBB23B35738842F0169040B1CFEC6EFEE0CEA0EB1510
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\Uninstall.lsttext
MD5:62B9CD76BC35C97AAEA98CCBDEEE04BF
SHA256:39C919F0BF05FB379A4663F9A6C72BEDB6E8E2749DB402408349647E5D29C695
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
13
DNS requests
14
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2668
msedge.exe
239.255.255.250:1900
whitelisted
2260
msedge.exe
142.250.186.68:443
www.google.com
GOOGLE
US
whitelisted
2260
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2260
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2260
msedge.exe
188.114.97.3:443
www.dr-farfar.com
CLOUDFLARENET
NL
unknown
2260
msedge.exe
20.166.151.106:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2260
msedge.exe
104.126.37.139:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
www.google.com
  • 142.250.186.68
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
www.dr-farfar.com
  • 188.114.97.3
  • 188.114.96.3
unknown
nav-edge.smartscreen.microsoft.com
  • 20.166.151.106
whitelisted
www.bing.com
  • 104.126.37.139
  • 104.126.37.152
  • 104.126.37.170
  • 104.126.37.137
  • 104.126.37.186
  • 104.126.37.171
  • 104.126.37.177
  • 104.126.37.130
  • 104.126.37.145
whitelisted

Threats

No threats detected
No debug info