| File name: | 2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.7z |
| Full analysis: | https://app.any.run/tasks/d87b069a-cc53-4070-9589-04d3ad53dd9b |
| Verdict: | Malicious activity |
| Analysis date: | August 05, 2025, 22:30:55 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 4D3ED5AA2CB4873DDA78074E5DEEEAC5 |
| SHA1: | 86016E53D69A4934590796E80E280D7F31D844C9 |
| SHA256: | B0DA76BB138F9EC2AE310F42F8DC6319E5CA0E26961A51C26355A1FE8CCBCD00 |
| SSDEEP: | 24576:GqeYaELc3i9mq70KOAF0agPDS//bh1gpuVV6442b1UHQBJ031YbwDSDfr62NALbs:GqeYxw3i9mq70KOAF0agPDS//bh1gpu5 |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
| FileVersion: | 7z v0.04 |
|---|---|
| ModifyDate: | 2018:11:05 23:48:40+00:00 |
| ArchivedFileName: | 2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 608 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --disable-quic --mojo-platform-channel-handle=3020 --field-trial-handle=1252,i,15564688148092048826,3927384468521435051,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1120 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=36 --mojo-platform-channel-handle=5580 --field-trial-handle=1252,i,15564688148092048826,3927384468521435051,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1168 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=2896 --field-trial-handle=1252,i,15564688148092048826,3927384468521435051,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1224 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=33 --mojo-platform-channel-handle=5188 --field-trial-handle=1252,i,15564688148092048826,3927384468521435051,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1828 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xf0,0x6d15f598,0x6d15f5a8,0x6d15f5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1852 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1600 --field-trial-handle=1252,i,15564688148092048826,3927384468521435051,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1884 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument C:\Users\admin\Desktop\ReadMe-MIG.html | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1980 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --mojo-platform-channel-handle=2928 --field-trial-handle=1252,i,15564688148092048826,3927384468521435051,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2052 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.7z | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2120 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3260 --field-trial-handle=1252,i,15564688148092048826,3927384468521435051,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.7z | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2052 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb2052.37107\2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.exe | executable | |
MD5:8D75650DA4C3D053FBE0E84BAD55C068 | SHA256:2539FFB7DBF707E0D4031BFCDA075CA7BF06007FC558457CA74432A90579C071 | |||
| 4040 | 2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.exe | C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk | lnk | |
MD5:6B504FEBA1FBC427E19A1807C088498E | SHA256:6DE3D25E102B48F80425AAA60720FB8BE794A16051248AB8C43575491CFA17C4 | |||
| 4040 | 2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.exe | C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk | lnk | |
MD5:0332C0AA48A537D7BC9BD21895BCF90A | SHA256:D2BEAFBC21522038FEDA729653B6582C587BC4C60C762EE2AB65EEE8434E561A | |||
| 4040 | 2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.exe | C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk | lnk | |
MD5:71C496234020CD5C9E2DD4D1008C9982 | SHA256:1BCCDF9925848B4162F80950B0F1C216DBFC67BB56D9329CC2EDF6C630EEC507 | |||
| 4040 | 2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.exe | C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Edge.lnk | lnk | |
MD5:6D167FC04217609A34C3EDD206ED83E8 | SHA256:7CD6D844CC86EE429B3ACA4CD50E97C15ACAC8416E12DB278967521EBA0626BC | |||
| 4040 | 2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.exe | C:\Users\Public\Desktop\Google Chrome.lnk | lnk | |
MD5:71AA9F76209D9B1D9DC8D603D338C879 | SHA256:CFC2C88F05EB3309B8F3E5682333CB2A1397B54FBE633B70DFA88D35A3926CAF | |||
| 4040 | 2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\ReadMe-MIG.html | html | |
MD5:B03EE1CCF5F02F8CF8742DCEC3FFE2F0 | SHA256:D22E25E7B13E887DD9A43764303AD269903E559809974E9AB143E11B1F1A6C49 | |||
| 4040 | 2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.exe | C:\Users\admin\AppData\Local\Temp\ReadMe-MIG.html | html | |
MD5:B03EE1CCF5F02F8CF8742DCEC3FFE2F0 | SHA256:D22E25E7B13E887DD9A43764303AD269903E559809974E9AB143E11B1F1A6C49 | |||
| 4040 | 2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.exe | C:\Users\Public\Desktop\Microsoft Edge.lnk | lnk | |
MD5:519FB868FFBD785590DD60555E2E571E | SHA256:80F312CD7F8A8138ED9449BB9F29F052BA762F7A87EF2E0570B8E4420848CD31 | |||
| 4040 | 2539ffb7dbf707e0d4031bfcda075ca7bf06007fc558457ca74432a90579c071.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\status_icon_check_200.png.locked-MIG | binary | |
MD5:1DD94B5CBEE93C107455C282629048BE | SHA256:77D0FEB499D5B25D6676C8D6957BDFF1A19AEA2990511AAE88984617C2C294A2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4060 | msedge.exe | GET | 302 | 198.134.116.17:80 | http://click-v4.exmainclck.com/click?i=SIpcPkykl-E_0 | unknown | — | — | unknown |
4060 | msedge.exe | GET | 200 | 103.224.182.220:80 | http://zokare.com/ck?dat=lQMeKJvT9BqhWip0ZwHVBH49fnkrbm15bW1lM0pHL3pNS1I1eEVFVUViR3ozWFhwZ005eHNvNGw2Q0tFS1VYT3JYTGZnUmVCdjAyNHQreDM0ejQ4RnJ4S2VmNEcyeTZFVzlZSVJJNHRHVWcrMjNRUWpnRnJzWnNFRncraTQrR2p6dVRsSDkydHdXeDZQYWJkTm9KTGtjbXJSL3l0TnlCUTJUcmN2YTF1VGNlSE1xWGNROFduRWg5WjJQNnU5VlM4UTRNQjFSSnZURjZLM080Wk5QQU1lQm84aUhLK28wNHRtVjlLU2hTU3JnK0FFNjFOK2RoRWtLK3BMa1NYaUdydS9ieXFZbTlGUVV5UlRFNUE3OU1DaW15R29uL0hQWVR1K1lFRGc0bE9McVYzd29iTlZlMDlJZk8zcjN1UDlIcEVZWERQWit5aWNLSkIxNXF6SXRJMll1SzBnSG5idWNRSnp0VnBOSFNtNml6cC96ZU9INUU5ZWw0cHU4QWwrOER4QTQ2dVJGeWNxajJmSURYTWtsWERoeGQwdmtVSENqUUxocTJXYjlrU1I3Mkx0cjdBd2RrREdmN09TZ01UREQvQmY1MWV4czNOQkhLeEZUb2QxYzZQQThhSWpLWlZWdWpHWmtPdWtzYUtVK3hhUGJyNG8vRTY5aUw1ZVN4cnh6bkNyV1hUWHk1RGZLM010MTVYVC9tcmhkQXN3KytpbXNSMzNRUStab3llaGZnVjhuSldyZWVkVlZuWGF1bHRWelpTY0xrdFhDVkxDODBwWTVWdEFIemVsS0prV2lFeEJsdWIzdmw5MlM2QkRyRXE4aGZhUk5FV1ZpVWNWT09ybksvVU5CN0FiQm5Ea3hiMEc2cUZlQTkwWVBXUXRyS3FvRmI2WSt4a3p0ZTFIVUdPZmJMVXJONWxqOHlKeWNYUXVUc0g2b2ZDWFZCOWl6bi9hZ1I2TG1aM09DNUJVdGtabWhibnBCOHp6cXpIcFlRMlFvV1JhVkpxUXVHOEMxOWdRQ21ST2JnUVdBZ3VVTyt6eUdGTXc2UU56UFlSQkJIckVRRUtGdStEWnF0cWZ3bmg3Z3RMdFllOEhKMDFCMXlGSXJ2ekYvcHdieEUybmIxZmRLZFl6L0FnUVN3NXhuU0IvTm5xcWFoSlh2bXRYRjhJd2d2V0Q0RExTWXNSL0oydEhGSFU4SlRmUTNiNUtUK0hRMmNaU3pRVTEzcGk4YU54VWRYTlUzTDVHazlURlFnY0VQcHRlbWJvalJ5YXNpcTFFU3JJdDJ4K01ocDVKWlU4dzZQQ1lrOGZSeEMwUGZFNzE5b0Jrc1hQVGVYZnJXeTYvQXUwRXJSUFJ3TWtNMnc5T2YwOGpPVDJiajlKMzJBL0hEQVZUTXhiOERnQVU1SWNWbE92M25WOUh1S3J1SmRJQnNTRXVnVmxVTm1yMW1PV0QzNU5rWDQ5SHo5TEdBZkRzWnpPdFhDM0pLcEVqemg3Sy9GWGk0WlpFNGI1KzBHdGFZcnBZa2xsU0R4blJ6NGFyM1hZMGNJR0YxeXNVRmNITzB6bDZpWjZyMHQxNlVpK2JOUXdMWS9VL09ja3R1ellKanR6OG5aQkZHY3ppRzRGelVpRitQb2ZIZ2c3NzZDaEJabERJWU9VVDFxbzk3MnlYZmVyc09jQ3BiWG10MEFjc3lKNURQb3JUaTA2T3hOL1FBcW94OEJ5dkFQeTB5ek5GZmhjdnVVdmVYT0hhTko3SSsreTR2M0JRNWcrVldKSmtKcEUvYUIrQVBiRWZiZWdudHprQ0RxMUJpckZzWU1QNXZqWk1CUERPZm1yQ014OU5aS3RocEd5VGlaRjYrNGRYWTRtb0ZYZDYvL1gvV3lZY08wbGZEcW9lai9zM2lsYmQyOHRTc01IL2VKQ0NSdDVwd0hBUVY3a0p1czZ5UEhYVmQwNHFOTFJYdW1yRGlWSGd5VzIrQ0dkSldpQkRwYTJTVE5OK1pXaG5EVzE2NHdYZlZDUFlleDhWMm9rQUFTaXdUV2tYY2RFZ0s4N2liWW9uVlMvNGhkZitxUVlhZDRFZEVtckxGeXZLS2g0T29OcmF3RTBIeGxpTEFXdEpNR2tPQkFiK01TQ2dsTjJoQXNBUU5tM0pOaVk0RjA2YkM4L2VrV0UzOHdsNHkzZmN1TlF1SXhFMVBqTFhjN05IZG5JN3dlRzFBRUJ2a1NyazJ4aC9HcnM2V3R1ekZhdVh4UXNIZmd5d3UwYVF3ZlQ2UEtBakd1OG9HeVZSTlBEYXhDbmJCcE1wUTZQeFJUQ252MmlpVU9EUU1YQWYzSlQyNWczVm96U28yVEZCZldUMFB5MjlidUUvZXJxODJTaU1hMVFnaXBwRHl3cWJIR0VKeVIxbGJJMmZZRWJpRHMvTGoySDBaK0QvcmlMR0kzOHlBVWdJNk1pek9UR0RYTWQzVXJ0ODFveUtJaVM1RXRvOG1NNHl6WVdVVWlNaUZpWCtJanJ0T1JxUmZVYUdCM1Rza3BuTk5kRDVDVjZtU3ExRGE2dFpSTUMrUnZMMGVQQlZIRXhxRT0%3D | unknown | — | — | unknown |
4060 | msedge.exe | GET | — | 103.224.182.220:80 | http://zokare.com/favicon.ico | unknown | — | — | unknown |
4060 | msedge.exe | GET | 200 | 103.224.182.220:80 | http://zokare.com/rec?dat=MtNuvKT80gokwsKKN5skSX49fnhUVjFWdnNnNkR3VFZHcTJoY0h0bmVIMmwyNTBsd0IxK2gyMk5zMWlHSkJvMlpZelplK3JvQStsOHVPbFZLQ1NNNkwvbkM1YW9jLy9vdUNRTWdYSHZYaHJDRjFBS1Q2aGNWU0NROFYxY3RtemxIL0xPQWo3TmxMZTNiM0hFSldqUVIxc2tHUDVwb2V4Sm1uTVk5NnpTZEhIbnMzbTIrZGNFK2tPSmorSFFDeXE5b0Izd1lRQTFSTDl5R0dGTktZWjlHRW1MblFIaDdLWTlYeXhJbXRMT1lMUythRVJJSjNsbGQ0T3JoeGRBMmFkZmsxbUlMUHhZQjZwNmRMNXJKa0srMW5iNWhYR0pWKyt6VzI2OHJpenRpVkljQzZnaldETmg4V1lhVVhFaElkZE1idVgxcFIwT2M3NzRrUEZuTVlDL0E4NEVBRWoyWGhGZ1NRUHR6dEwyTVZWd1doMTBUZWo4ekpPYnM5NUhVakZML0lxYlgwZjNSd1J3dFRSOGZTUHhMb3RQeFBUWlRhSFlIY09jeFZMNk5iMTlmT25QQ3huYTlRNGpYaUZzYjdQZkhtK0xKMEt2WU02RWZjTlZ3MTFxV0g1dHlzRlA0aWw0clhzaHRpaGxlZGtUemVQMjNiYkZPZ0NHR3Bud1Z3WHF1NTg3Y0lVNVhKL1V3M2UxblgwK1RTT3c2ZlQwZG1HTG0rWjN5ZVByNytFVDJVMWEvbEZqb1ovZzdscm10dTVTRVIrMDhHWEF5WXA0bENod0dXS0dHZC9CSnlpV3M2OEFXR2FVZEJPSzVjMnNFMXFQSlEvWVZTa3laeDB1SmNrS0NWbWJra0NvY25PVjVBMkhROER3aXZ2QjlGOFRyRHViR1RjWUxTaU1DS0VTSTlJRzhHbVpyWjgxWlNGaGdOYTlyK3dDNU9pZjN3eUdRZFlFRzg3UzFlMkxFUWNTbFlBMk54d25hR2VnTjZkNmEvemdFOHZDV0tWMjVlaWNERXZCeVBxTmRhU0dPTGFSRUVmdXFPOGFscVVpM1VuMmdmTkZxdkhmcTdSV1UyZ2U3UVZGODVRSUtRTGdjODdHUVg4ZWo1SGpoSDA0TjV5bHhDai93M2FucmVmUVhtUmxqYVA3TS9WRnFSMlZWTlFsOHVZc3pKMFljdVJsdWc3UVMwUnFCU1c0Qk1zR2d0WkhDOG45VGViWkZpUFJNV2MwVmdETTRuaEpIbis3YW1WZk5pbkg5cFUyQVBQaktiL2puVTI3Zm92RFNGS2dZcGI4ajFUWkRYekVQMkdZOVNmenhtN2h6TUFDT3kza0FZbHpnbk84SkJsR1BYUmdlc1BwR2NzTzRzSHpTZlBDTTM2QTFCb29mL0N1RW5XK1JiRE5uU2pNdzJFOWlxQ25JMi9SNEllc1VBNG0zMGlkcmFvUy9CQVJtQ0lMMW5yeEgxd2oxeFkrR1FTTVZHRUxISlVIQlFnWVhFME9LTG9JMUhST2ZoaU9WbzBRWTU0NmZNYTRQSGl6aTdEVjNNRVZlNHhCNmVaVnF2Q2FrOVJZR1kvb0pCdno4Unp5aGcrdm1KTXF1WGxGZFBDL3pZMy9jVmh5UVJBNWdzSEhNU24rbUw5M0pRakRmSTFTNG1KS04yRHFiRlkvK0szYytKdXdMY3ptL2FaVk5zdlhJSjMxb0h6V2N2UzFEamFVUHM2eXcrVkc4S1RReGNwbzFaU3JkMGhBaHZTSGs3VmQ2c04wVDV2TlA4M3dEbERodkpibUZ3ZURmRzdjS0huYmo3dEhicjB1aytJa0pFMWNPV3ZZWGdSNFdubS9QbWdrQWUzbHFlRlFybzY0Mm5SNUhSejhKazdtUE9HZHZyemwzVFVMNjg0QTJIdUR6emtuUCtpelJDTGlXRHpreHpXSWMxZGI0TGlpVUM2THlTMyt4QkR6WlppYXJlNERSMmE0NWlEeGN3VGEwbjFHaVd6Y1BBa3lCUGhVQVZFWGNubnZwNTVnK0dYMEZScnY1aW5sNmRwc2hJSlkzV2dhUUY2ZkxydEpwREx1OC95VmcyS002Mjl4dHlUMXdLSTRZa29yemNtVlNTWVNHUnZYbmRBb0pWL0UvMnRXd0MzOC84NFh4OWlRK2VzZ1Jpa3h2VGVVUzdqSXFuNTIydG02QXgzNThFcE1yNUFiemZtYnlaTjZTd3FmdXIyWHRZS0xhTVdXaTYwVDVaNm1VR3FRanRzSmJNQ2h2dzZQbHBVV0lTcXFJK01tMU1NSk00ZFVja0FWa25JMS9ocTl6YUZuR05DL2wzUGRYMjVVK3JkUTdoZVMzNGJKQWJQWnhIb3pHQWZ5Yy91REpyN1VMakJDMTRPenlIOWhLUjkxeUNSTUUrVVFKUS81dityL0Vka016VnFxemNPMXdlT3QrRFBWQWJGVXgzcllOQmF2ellkaWNXYmJ6d2pEblFvb2NHYlU5RDNReU1VQm53MFJPNlBIcnMzTlFtWkFwYXlNaUdnK1hia09TbXFac3J1T04zalpEMmsycytzdTU1NTRVZDJwVEJEc1BWRUZVQ3dVN21qb0swTHB3eWNQdnlaZFZmY0ptN2NjYjJZQTdoNms1YTQ0NlVMR28yYjZHK0NnWjhMQUVGUWVoQmJnZEltQW1pT3JIdmwybHlyRzlsMVZJM2wybFlQa2NlaTJnPT0%3D&rand=0.6223313355865694&gpu=Google%20Inc.%20(Google)%20-%20ANGLE%20(Google,%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE)),%20SwiftShader%20driver)&vs=1280:621&ds=1280:720&sl=0:0&os=f&nos=f&if=f&sc=f | unknown | — | — | unknown |
4060 | msedge.exe | GET | 302 | 103.224.182.220:80 | http://zokare.com/check?n=https%3A%2F%2Fqoclick.com%2Fclick%3Fkey%3D551188cfe13f734ea457%26t%3D0.034%26t1%3D0.034%26t2%3D1791618707%26t3%3D1%26t4%3D0%26t5%3D1%26t6%3Ds&s=j&enc=MtNuvKT80gokwsKKN5skSX49fnhUVjFWdnNnNkR3VFZHcTJoY0h0bmVIMmwyNTBsd0IxK2gyMk5zMWlHSkJvMlpZelplK3JvQStsOHVPbFZLQ1NNNkwvbkM1YW9jLy9vdUNRTWdYSHZYaHJDRjFBS1Q2aGNWU0NROFYxY3RtemxIL0xPQWo3TmxMZTNiM0hFSldqUVIxc2tHUDVwb2V4Sm1uTVk5NnpTZEhIbnMzbTIrZGNFK2tPSmorSFFDeXE5b0Izd1lRQTFSTDl5R0dGTktZWjlHRW1MblFIaDdLWTlYeXhJbXRMT1lMUythRVJJSjNsbGQ0T3JoeGRBMmFkZmsxbUlMUHhZQjZwNmRMNXJKa0srMW5iNWhYR0pWKyt6VzI2OHJpenRpVkljQzZnaldETmg4V1lhVVhFaElkZE1idVgxcFIwT2M3NzRrUEZuTVlDL0E4NEVBRWoyWGhGZ1NRUHR6dEwyTVZWd1doMTBUZWo4ekpPYnM5NUhVakZML0lxYlgwZjNSd1J3dFRSOGZTUHhMb3RQeFBUWlRhSFlIY09jeFZMNk5iMTlmT25QQ3huYTlRNGpYaUZzYjdQZkhtK0xKMEt2WU02RWZjTlZ3MTFxV0g1dHlzRlA0aWw0clhzaHRpaGxlZGtUemVQMjNiYkZPZ0NHR3Bud1Z3WHF1NTg3Y0lVNVhKL1V3M2UxblgwK1RTT3c2ZlQwZG1HTG0rWjN5ZVByNytFVDJVMWEvbEZqb1ovZzdscm10dTVTRVIrMDhHWEF5WXA0bENod0dXS0dHZC9CSnlpV3M2OEFXR2FVZEJPSzVjMnNFMXFQSlEvWVZTa3laeDB1SmNrS0NWbWJra0NvY25PVjVBMkhROER3aXZ2QjlGOFRyRHViR1RjWUxTaU1DS0VTSTlJRzhHbVpyWjgxWlNGaGdOYTlyK3dDNU9pZjN3eUdRZFlFRzg3UzFlMkxFUWNTbFlBMk54d25hR2VnTjZkNmEvemdFOHZDV0tWMjVlaWNERXZCeVBxTmRhU0dPTGFSRUVmdXFPOGFscVVpM1VuMmdmTkZxdkhmcTdSV1UyZ2U3UVZGODVRSUtRTGdjODdHUVg4ZWo1SGpoSDA0TjV5bHhDai93M2FucmVmUVhtUmxqYVA3TS9WRnFSMlZWTlFsOHVZc3pKMFljdVJsdWc3UVMwUnFCU1c0Qk1zR2d0WkhDOG45VGViWkZpUFJNV2MwVmdETTRuaEpIbis3YW1WZk5pbkg5cFUyQVBQaktiL2puVTI3Zm92RFNGS2dZcGI4ajFUWkRYekVQMkdZOVNmenhtN2h6TUFDT3kza0FZbHpnbk84SkJsR1BYUmdlc1BwR2NzTzRzSHpTZlBDTTM2QTFCb29mL0N1RW5XK1JiRE5uU2pNdzJFOWlxQ25JMi9SNEllc1VBNG0zMGlkcmFvUy9CQVJtQ0lMMW5yeEgxd2oxeFkrR1FTTVZHRUxISlVIQlFnWVhFME9LTG9JMUhST2ZoaU9WbzBRWTU0NmZNYTRQSGl6aTdEVjNNRVZlNHhCNmVaVnF2Q2FrOVJZR1kvb0pCdno4Unp5aGcrdm1KTXF1WGxGZFBDL3pZMy9jVmh5UVJBNWdzSEhNU24rbUw5M0pRakRmSTFTNG1KS04yRHFiRlkvK0szYytKdXdMY3ptL2FaVk5zdlhJSjMxb0h6V2N2UzFEamFVUHM2eXcrVkc4S1RReGNwbzFaU3JkMGhBaHZTSGs3VmQ2c04wVDV2TlA4M3dEbERodkpibUZ3ZURmRzdjS0huYmo3dEhicjB1aytJa0pFMWNPV3ZZWGdSNFdubS9QbWdrQWUzbHFlRlFybzY0Mm5SNUhSejhKazdtUE9HZHZyemwzVFVMNjg0QTJIdUR6emtuUCtpelJDTGlXRHpreHpXSWMxZGI0TGlpVUM2THlTMyt4QkR6WlppYXJlNERSMmE0NWlEeGN3VGEwbjFHaVd6Y1BBa3lCUGhVQVZFWGNubnZwNTVnK0dYMEZScnY1aW5sNmRwc2hJSlkzV2dhUUY2ZkxydEpwREx1OC95VmcyS002Mjl4dHlUMXdLSTRZa29yemNtVlNTWVNHUnZYbmRBb0pWL0UvMnRXd0MzOC84NFh4OWlRK2VzZ1Jpa3h2VGVVUzdqSXFuNTIydG02QXgzNThFcE1yNUFiemZtYnlaTjZTd3FmdXIyWHRZS0xhTVdXaTYwVDVaNm1VR3FRanRzSmJNQ2h2dzZQbHBVV0lTcXFJK01tMU1NSk00ZFVja0FWa25JMS9ocTl6YUZuR05DL2wzUGRYMjVVK3JkUTdoZVMzNGJKQWJQWnhIb3pHQWZ5Yy91REpyN1VMakJDMTRPenlIOWhLUjkxeUNSTUUrVVFKUS81dityL0Vka016VnFxemNPMXdlT3QrRFBWQWJGVXgzcllOQmF2ellkaWNXYmJ6d2pEblFvb2NHYlU5RDNReU1VQm53MFJPNlBIcnMzTlFtWkFwYXlNaUdnK1hia09TbXFac3J1T04zalpEMmsycytzdTU1NTRVZDJwVEJEc1BWRUZVQ3dVN21qb0swTHB3eWNQdnlaZFZmY0ptN2NjYjJZQTdoNms1YTQ0NlVMR28yYjZHK0NnWjhMQUVGUWVoQmJnZEltQW1pT3JIdmwybHlyRzlsMVZJM2wybFlQa2NlaTJnPT0%253D&gpu=Google%20Inc.%20(Google)%20-%20ANGLE%20(Google,%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE)),%20SwiftShader%20driver)&vs=1280:621&ds=1280:720&sl=0:0&os=f&nos=f&if=f&sc=f | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2424 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4060 | msedge.exe | 150.171.22.17:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4060 | msedge.exe | 150.171.28.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4060 | msedge.exe | 92.123.104.62:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
2424 | msedge.exe | 224.0.0.251:5353 | — | — | — | unknown |
4060 | msedge.exe | 103.224.182.238:443 | unlock26ozqwoyfv.onion.casa | Trellian Pty. Limited | AU | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
unlock26ozqwoyfv.onion.to |
| whitelisted |
unlock26ozqwoyfv.onion.nu |
| unknown |
unlock26ozqwoyfv.onion.casa |
| unknown |
zokare.com |
| unknown |
unlock26ozqwoyfv.hiddenservice.net |
| unknown |
click-v4.exmainclck.com |
| unknown |