File name:

WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe

Full analysis: https://app.any.run/tasks/d7b73038-5a7e-4305-befd-47ab308b857f
Verdict: Malicious activity
Analysis date: January 20, 2024, 08:16:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C353F9C678EA37375EB1542D29B23B2F

SHA1:

1DF5FB74DD84DD973CE91C01935CAA743BC9590A

SHA256:

B070797029681E05D41C6A8A1219C6DAD375443C58A824288623020658A63FDF

SSDEEP:

98304:zf13rs3o8yb5FD+0lUpO4dVjgFPDRdtoM3CQNpfcmoHuUoxppO094L13HJ0jn5rL:NlA6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
  • SUSPICIOUS

    • Reads Internet Explorer settings

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Reads the Internet Settings

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Reads Microsoft Outlook installation path

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Executable content was dropped or overwritten

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Drops 7-zip archiver for unpacking

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Creates/Modifies COM task schedule object

      • uninstall.exe (PID: 1824)
    • Searches for installed software

      • uninstall.exe (PID: 1824)
    • Creates a software uninstall entry

      • uninstall.exe (PID: 1824)
  • INFO

    • Checks supported languages

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
      • uninstall.exe (PID: 1824)
      • wmpnscfg.exe (PID: 3308)
    • Checks proxy server information

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Reads the machine GUID from the registry

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Reads the computer name

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
      • uninstall.exe (PID: 1824)
      • wmpnscfg.exe (PID: 3308)
    • Creates files in the program directory

      • WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe (PID: 2080)
    • Application launched itself

      • msedge.exe (PID: 1848)
      • msedge.exe (PID: 2668)
    • Manual execution by a user

      • msedge.exe (PID: 2668)
      • wmpnscfg.exe (PID: 3308)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:08:11 15:54:17+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 187392
InitializedDataSize: 316416
UninitializedDataSize: -
EntryPoint: 0x1c869
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 7.0.3.0
ProductVersionNumber: 7.0.3.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Email: inFo@Dr-FarFar.CoM
Website: https://www.Dr-FarFar.com
Comments: www.Dr-FarFar.com
CompanyName: Dr.FarFar | www.Dr-FarFar.com
FileDescription: WinRAR Full Activated [ViP]
FileVersion: 7.0.3
InternalName: WinRAR.exe
LegalCopyright: Copyright © Dr.FarFar
LegalTrademarks: WinRAR Full Activated [ViP]
OriginalFileName: WinRAR.exe
ProductName: WinRAR Full Activated [ViP]
ProductVersion: 7.0.3
AssemblyVersion: 7.0.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
17
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar v7.00 b3 official release (32-bit) pre-activated - unlocked.exe msedge.exe no specs uninstall.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs winrar v7.00 b3 official release (32-bit) pre-activated - unlocked.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe" C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeexplorer.exe
User:
admin
Company:
Dr.FarFar | www.Dr-FarFar.com
Integrity Level:
MEDIUM
Description:
WinRAR Full Activated [ViP]
Exit code:
3221226540
Version:
7.0.3
Modules
Images
c:\users\admin\appdata\local\temp\winrar v7.00 b3 official release (32-bit) pre-activated - unlocked.exe
c:\windows\system32\ntdll.dll
952"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1560 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
980"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1256 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1000"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2324 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1824"C:\Program Files\WinRAR\uninstall.exe" /setupC:\Program Files\WinRAR\uninstall.exeWinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
Uninstall WinRAR
Exit code:
0
Version:
7.0.3
Modules
Images
c:\program files\winrar\uninstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1848"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&cad=rja&uact=8&ved=2ahUKEwisysKe7q_mAhVG-YUKHVZDAZ4QFjABegQIBxAC&url=https%3A%2F%2Fwww.dr-farfar.com%2F&usg=AOvVaw22hlzBu7hxTxcihgNzrn0CC:\Program Files\Microsoft\Edge\Application\msedge.exeWinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2080"C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe" C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe
explorer.exe
User:
admin
Company:
Dr.FarFar | www.Dr-FarFar.com
Integrity Level:
HIGH
Description:
WinRAR Full Activated [ViP]
Exit code:
0
Version:
7.0.3
Modules
Images
c:\users\admin\appdata\local\temp\winrar v7.00 b3 official release (32-bit) pre-activated - unlocked.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\rsaenh.dll
2172"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6d5af598,0x6d5af5a8,0x6d5af5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2176"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2332 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2260"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1456 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
2 657
Read events
2 545
Write events
110
Delete events
2

Modification events

(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeKey:HKEY_CURRENT_USER\Software\WinRAR SFX
Operation:writeName:C%%Program Files%WinRAR
Value:
C:\Program Files\WinRAR
(PID) Process:(1848) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1848) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1848) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
Executable files
9
Suspicious files
47
Text files
42
Unknown types
0

Dropped files

PID
Process
Filename
Type
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\RarReg.keytext
MD5:11368B2FA7D08A84F4F270A1418B4FC0
SHA256:A23B90E60DCA91DF298F1DE4BCEB13E5A5164824EBBD2CEAE874C70E89F0150E
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\Web.urltext
MD5:F8CC1FBD549B5A9A187FC6AAC948BC45
SHA256:06187D0DEB8B2FAF4B9F51B9006A0D5435CBCBE62F321926DA48E2D3415DABAD
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\License.txttext
MD5:672064CF19DB0B083B981CF0BE7662B0
SHA256:9FC8AA33CCAFA04C1CE4C0A61047B341297D720ADAB1B77F67B5FE59F43BB59F
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\ReadMe.txttext
MD5:00D0A57A6D64EE3DE8F4D5529D6C6447
SHA256:FCD13E1B97AF47B8B923BA97AE15E9731C66093609667C3171D5DD24A6F7F2E6
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exebinary
MD5:
SHA256:
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\RarExt64.dllexecutable
MD5:ADA5F52FF77E4CB15140DA3598B2B928
SHA256:2FA72E2CA7455C9C90548F70E88710B68AF7FB86BDAA6A62D00D6830AD9BC1B1
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\UnRAR.exeexecutable
MD5:C3437BE06208AA4CF8CE2C899293F43A
SHA256:8B24E0D5EFEE0672049EB892902A7C0D35491335C732DA1A5F4F11F77528B8DB
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\7zxa.dllexecutable
MD5:6161EB75F65FABE5D05448FA5D7908B4
SHA256:23D67D4BCD765355C85B831279D61F46B641E7B8F3ED772ADA8C915E5DEA9CB5
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\RarExt.dllexecutable
MD5:8B3137B3E3DEF9B4F540A3FC004FB371
SHA256:26EAB307E36358FE287663CE38E6F27FC8F57DFDC2204BCB82375541C3B7F883
2080WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exeC:\Program Files\WinRAR\Zip32.SFXexecutable
MD5:D71D47C14F48F31B05B76364C1EFADDC
SHA256:F101732A5A10B79837E1D46F92E9A318DDFDBC02CC225B49F2EB0A60CC910615
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
13
DNS requests
14
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2668
msedge.exe
239.255.255.250:1900
whitelisted
2260
msedge.exe
142.250.186.68:443
www.google.com
GOOGLE
US
whitelisted
2260
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2260
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2260
msedge.exe
188.114.97.3:443
www.dr-farfar.com
CLOUDFLARENET
NL
unknown
2260
msedge.exe
20.166.151.106:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2260
msedge.exe
104.126.37.139:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
www.google.com
  • 142.250.186.68
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
www.dr-farfar.com
  • 188.114.97.3
  • 188.114.96.3
unknown
nav-edge.smartscreen.microsoft.com
  • 20.166.151.106
whitelisted
www.bing.com
  • 104.126.37.139
  • 104.126.37.152
  • 104.126.37.170
  • 104.126.37.137
  • 104.126.37.186
  • 104.126.37.171
  • 104.126.37.177
  • 104.126.37.130
  • 104.126.37.145
whitelisted

Threats

No threats detected
No debug info