URL:

install.justaskjackyapp.com

Full analysis: https://app.any.run/tasks/c6f1cdee-3b70-4c76-b4d0-4da478bb0040
Verdict: Malicious activity
Analysis date: July 31, 2025, 21:29:05
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto-sch-xml
inno
installer
delphi
Indicators:
MD5:

0DADB7BFA7BBB31A8CF250909F3E574F

SHA1:

BE03C41900ACE2E018694B1600D844B9EF632A6F

SHA256:

B2B879C7FB4E16107F471DD994E3EE59E018563F0B7F93D381AEA4E64B4F1C59

SSDEEP:

3:KWirLEXO1DGKI:KWice1BI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 4836)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • justaskjacky.exe (PID: 7236)
      • justaskjacky.tmp (PID: 2808)
    • Reads the Windows owner or organization settings

      • justaskjacky.tmp (PID: 2808)
    • Process drops legitimate windows executable

      • justaskjacky.tmp (PID: 2808)
    • The process executes via Task Scheduler

      • cmd.exe (PID: 1980)
    • Reads security settings of Internet Explorer

      • justaskjacky.tmp (PID: 2808)
      • dfsvc.exe (PID: 7532)
    • Starts CMD.EXE for commands execution

      • node.exe (PID: 2276)
      • justaskjacky.tmp (PID: 2808)
    • Executes application which crashes

      • JustAskJacky.exe (PID: 1244)
      • JustAskJacky.exe (PID: 7736)
      • JustAskJacky.exe (PID: 7672)
      • JustAskJacky.exe (PID: 2632)
      • JustAskJacky.exe (PID: 7400)
      • JustAskJacky.exe (PID: 3588)
    • Executes script using NodeJS

      • node.exe (PID: 2276)
    • Reads Internet Explorer settings

      • dfsvc.exe (PID: 7532)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 7636)
      • justaskjacky.tmp (PID: 2808)
      • justaskjacky.exe (PID: 7236)
      • node.exe (PID: 2276)
      • JustAskJacky.exe (PID: 1244)
      • JustAskJacky.exe (PID: 7736)
      • JustAskJacky.exe (PID: 7672)
      • JustAskJacky.exe (PID: 2632)
      • dfsvc.exe (PID: 7532)
      • JustAskJacky.exe (PID: 7400)
      • JustAskJacky.exe (PID: 3588)
    • Application launched itself

      • msedge.exe (PID: 4320)
    • Reads the computer name

      • identity_helper.exe (PID: 7636)
      • justaskjacky.tmp (PID: 2808)
      • JustAskJacky.exe (PID: 1244)
      • node.exe (PID: 2276)
      • JustAskJacky.exe (PID: 7736)
      • JustAskJacky.exe (PID: 7672)
      • JustAskJacky.exe (PID: 2632)
      • dfsvc.exe (PID: 7532)
      • JustAskJacky.exe (PID: 3588)
      • JustAskJacky.exe (PID: 7400)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 4320)
      • msedge.exe (PID: 2728)
    • Reads Environment values

      • identity_helper.exe (PID: 7636)
      • node.exe (PID: 2276)
      • dfsvc.exe (PID: 7532)
    • Create files in a temporary directory

      • justaskjacky.exe (PID: 7236)
      • justaskjacky.tmp (PID: 2808)
      • dfsvc.exe (PID: 7532)
    • Reads the machine GUID from the registry

      • justaskjacky.tmp (PID: 2808)
      • JustAskJacky.exe (PID: 1244)
      • JustAskJacky.exe (PID: 7736)
      • JustAskJacky.exe (PID: 7672)
      • JustAskJacky.exe (PID: 2632)
      • dfsvc.exe (PID: 7532)
      • JustAskJacky.exe (PID: 3588)
      • JustAskJacky.exe (PID: 7400)
    • Reads the software policy settings

      • justaskjacky.tmp (PID: 2808)
      • WerFault.exe (PID: 7284)
      • WerFault.exe (PID: 700)
      • WerFault.exe (PID: 3580)
      • WerFault.exe (PID: 7676)
      • WerFault.exe (PID: 7428)
      • WerFault.exe (PID: 504)
      • slui.exe (PID: 1944)
    • Creates files or folders in the user directory

      • justaskjacky.tmp (PID: 2808)
      • node.exe (PID: 2276)
      • WerFault.exe (PID: 7284)
      • WerFault.exe (PID: 3580)
      • WerFault.exe (PID: 700)
      • WerFault.exe (PID: 7676)
      • dfsvc.exe (PID: 7532)
      • WerFault.exe (PID: 7428)
      • WerFault.exe (PID: 504)
    • Creates a software uninstall entry

      • justaskjacky.tmp (PID: 2808)
    • The sample compiled with english language support

      • justaskjacky.tmp (PID: 2808)
    • Compiled with Borland Delphi (YARA)

      • justaskjacky.exe (PID: 7236)
      • justaskjacky.tmp (PID: 2808)
    • Reads product name

      • node.exe (PID: 2276)
    • Detects InnoSetup installer (YARA)

      • justaskjacky.exe (PID: 7236)
      • justaskjacky.tmp (PID: 2808)
    • Checks proxy server information

      • WerFault.exe (PID: 7284)
      • WerFault.exe (PID: 3580)
      • WerFault.exe (PID: 700)
      • WerFault.exe (PID: 7676)
      • slui.exe (PID: 1944)
      • WerFault.exe (PID: 504)
      • WerFault.exe (PID: 7428)
    • Manual execution by a user

      • JustAskJacky.exe (PID: 7736)
      • JustAskJacky.exe (PID: 7672)
      • JustAskJacky.exe (PID: 2632)
      • rundll32.exe (PID: 7756)
      • notepad.exe (PID: 3884)
      • JustAskJacky.exe (PID: 7400)
      • msedge.exe (PID: 5596)
      • JustAskJacky.exe (PID: 3588)
      • wscript.exe (PID: 6080)
    • Process checks whether UAC notifications are on

      • dfsvc.exe (PID: 7532)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 3884)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
226
Monitored processes
73
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start iexplore.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs justaskjacky.exe justaskjacky.tmp cmd.exe no specs conhost.exe no specs schtasks.exe no specs cmd.exe no specs conhost.exe no specs node.exe conhost.exe no specs msedge.exe no specs justaskjacky.exe msedge.exe no specs cmd.exe no specs conhost.exe no specs reg.exe no specs werfault.exe slui.exe justaskjacky.exe werfault.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs rundll32.exe no specs justaskjacky.exe werfault.exe msedge.exe no specs justaskjacky.exe werfault.exe msedge.exe no specs rundll32.exe no specs dfsvc.exe notepad.exe no specs wscript.exe no specs msedge.exe no specs msedge.exe no specs justaskjacky.exe werfault.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs justaskjacky.exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
504\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
504C:\WINDOWS\SysWOW64\WerFault.exe -u -p 3588 -s 1080C:\Windows\SysWOW64\WerFault.exe
JustAskJacky.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
700C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7672 -s 1256C:\Windows\SysWOW64\WerFault.exe
JustAskJacky.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1180"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2856,i,15467478783232054652,11419871466315514249,262144 --variations-seed-version --mojo-platform-channel-handle=2772 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1212"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x294,0x298,0x29c,0x28c,0x2a4,0x7ffc4347f208,0x7ffc4347f214,0x7ffc4347f220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1244"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3660,i,15467478783232054652,11419871466315514249,262144 --variations-seed-version --mojo-platform-channel-handle=3692 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1244"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=16 --always-read-main-dll --field-trial-handle=3568,i,15467478783232054652,11419871466315514249,262144 --variations-seed-version --mojo-platform-channel-handle=6820 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1244"C:\Users\admin\AppData\Local\Programs\JustAskJacky\JustAskJacky.exe"C:\Users\admin\AppData\Local\Programs\JustAskJacky\JustAskJacky.exe
justaskjacky.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
JustAskJacky
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\programs\justaskjacky\justaskjacky.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1244C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1636"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=8576,i,15467478783232054652,11419871466315514249,262144 --variations-seed-version --mojo-platform-channel-handle=7204 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
34 831
Read events
34 751
Write events
75
Delete events
5

Modification events

(PID) Process:(6360) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6360) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6360) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6360) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(6360) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(6360) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:DisableFirstRunCustomize
Value:
1
(PID) Process:(4320) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(4320) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(4320) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(4320) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
Executable files
24
Suspicious files
255
Text files
161
Unknown types
129

Dropped files

PID
Process
Filename
Type
4320msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\7c75b250-2aa2-47bd-8f23-89254ccfebf7.tmpbinary
MD5:7B889401FEBEE1A197E5F4E9489D1211
SHA256:3E48A8AB17E6547FA1B62BF667A3877ABF650B652613524951C4FD0E5285950A
4320msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\702e2b6c374316ca_0binary
MD5:5EEC714E0651D72EAA98441DBB480E67
SHA256:3B667ABEAB6AD7331E859E54AAD6AB859056B13BEB8F1E5BD075533947355261
4320msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\837c88d998e57b1b_0binary
MD5:A01523F58B744BEC2CA224870FE246C0
SHA256:A1A6D1AB59A79964980FE6CCFD8D699A90744C22CFB3CDC772714CAF7E6C8011
4320msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\d25d174be8634d6f_0binary
MD5:C6466E2A23DBA4212B091CBFE3E9EFE6
SHA256:9DD9061B9F32996C52C71F2346758C877A5BEC0BFFAD3357385C88E00D8C34F9
4320msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\6359620c93b0e0b3_0binary
MD5:0062CBF9AC0E37A4A7694A0C57D41358
SHA256:CCB09ABE5326D0E38E2F6D5D1C74AC63546CB110B8F99344C325A6714DC4FA20
4320msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\90ffd6928df6dbd7_0binary
MD5:79147AEE86AC9DF33F9C4F244AF44C9C
SHA256:0512F0A4F8F96E2B60956396040A4EEE5AA0A917AB2BDA98D538161F547A2E92
4320msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\e98b2bf50f135cff_0binary
MD5:73F388583989434794269889B93FB985
SHA256:51AC04D137D5CC9F73C164F111DBE89B236F0CC1F98B35238378E1B4759B51B1
2728msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\f_000260woff2
MD5:545FAAF48FCBA0A93056C615557AFB92
SHA256:1F93AA8ACDDE84C90CD4D42A5962EB8FBF4ECAAED0031B6611B0D145BEA15418
4320msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\94a1b175b07180cd_0binary
MD5:3EBB03DD2116D656636202AD21C52D1C
SHA256:535DAC603A401977EB43BF84900C2EEB4A450B9635BE82D45846EB7B309438D1
4320msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Secure Preferences~RF190546.TMPbinary
MD5:FD0590F7515930B5D8BD648556BB62A9
SHA256:742FC37B1E5D054A7CF3B9A8304A88F003EC442405B0D688E5ACAF74AE8F0066
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
120
DNS requests
121
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.3.109.244:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
1268
svchost.exe
GET
200
23.55.110.211:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
4120
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
420 b
whitelisted
6756
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
4320
msedge.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D
US
binary
1.42 Kb
whitelisted
4120
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
408 b
whitelisted
4320
msedge.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEDPXCKiRQFMZ4qW70zm5rW4%3D
US
binary
765 b
whitelisted
4320
msedge.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRd0JozUYXMqqW4y4zJTrLcMCRSkAQUgTKSQSsozUbIxKLGKjkS7EipPxQCEFc%2F1CnPxDDkbFeXrFuEvL0%3D
US
binary
637 b
whitelisted
7284
WerFault.exe
GET
200
23.55.110.211:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
7284
WerFault.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2064
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2728
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2728
msedge.exe
150.171.27.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2728
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2728
msedge.exe
2.16.241.218:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2728
msedge.exe
18.172.112.79:443
install.justaskjackyapp.com
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 20.106.86.13
whitelisted
google.com
  • 142.250.185.238
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
install.justaskjackyapp.com
  • 18.172.112.79
  • 18.172.112.70
  • 18.172.112.39
  • 18.172.112.50
unknown
copilot.microsoft.com
  • 2.16.241.220
  • 2.16.241.224
whitelisted
www.bing.com
  • 2.16.241.218
  • 2.16.241.201
  • 2.16.241.205
whitelisted
update.googleapis.com
  • 142.250.186.163
whitelisted
clients2.googleusercontent.com
  • 172.217.18.97
whitelisted
edgeassetservice.azureedge.net
  • 13.107.246.45
whitelisted

Threats

PID
Process
Class
Message
2728
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2728
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2728
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2728
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2728
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2728
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Process
Message
JustAskJacky.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
JustAskJacky.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
JustAskJacky.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
JustAskJacky.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
dfsvc.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
JustAskJacky.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.