File name:

EmulatorHub.zip

Full analysis: https://app.any.run/tasks/048d745c-0019-4686-a224-481d965e0df3
Verdict: Malicious activity
Analysis date: June 07, 2025, 21:56:18
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

1D329FFB007E52D859153368639F7BED

SHA1:

DF1C3D0BDD9E5A69EC0B0ADD1E6E9183C6144C93

SHA256:

B50FEC51F9A4FC3341FCE4445A7960B859F4E149F38402F9ADA3FB9F1593A4D3

SSDEEP:

98304:7e89tUKcxmX3g5VhxNWYgsBFqSmS0w2Wruvx4HLyQsEVVldsk8+AbBwy13j8fpul:UBFOK45tCHF1KxJJMA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2652)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2652)
      • EmulatorHub.exe (PID: 5548)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 2652)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2652)
      • msedge.exe (PID: 6920)
      • msedge.exe (PID: 6344)
      • msedge.exe (PID: 2284)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 2652)
      • msedge.exe (PID: 6920)
      • msedge.exe (PID: 6344)
      • msedge.exe (PID: 2284)
    • Checks supported languages

      • EmulatorHub.exe (PID: 5548)
      • identity_helper.exe (PID: 5588)
      • identity_helper.exe (PID: 3684)
    • Creates files in the program directory

      • EmulatorHub.exe (PID: 5548)
    • Reads the computer name

      • EmulatorHub.exe (PID: 5548)
      • identity_helper.exe (PID: 5588)
      • identity_helper.exe (PID: 3684)
    • Application launched itself

      • msedge.exe (PID: 1452)
      • msedge.exe (PID: 6344)
      • msedge.exe (PID: 2088)
    • Manual execution by a user

      • msedge.exe (PID: 6344)
    • Connects to unusual port

      • msedge.exe (PID: 2284)
    • Reads Environment values

      • identity_helper.exe (PID: 5588)
      • identity_helper.exe (PID: 3684)
    • Reads the software policy settings

      • slui.exe (PID: 5552)
      • slui.exe (PID: 2088)
    • Checks proxy server information

      • slui.exe (PID: 2088)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 6344)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:11:13 12:15:28
ZipCRC: 0x7798f956
ZipCompressedSize: 769737
ZipUncompressedSize: 1437056
ZipFileName: clrjit.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
233
Monitored processes
99
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe emulatorhub.exe no specs emulatorhub.exe conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
208"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4460 --field-trial-handle=2360,i,9608376222244698514,5610749406096076171,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
632"C:\Users\admin\AppData\Local\Temp\Rar$EXa2652.19970\EmulatorHub.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2652.19970\EmulatorHub.exeWinRAR.exe
User:
admin
Company:
Marcin Szeniak
Integrity Level:
MEDIUM
Description:
WinUpdateHelper
Exit code:
3221226540
Version:
5.8.2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2652.19970\emulatorhub.exe
c:\windows\system32\ntdll.dll
660\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeEmulatorHub.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
672"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=7336 --field-trial-handle=2360,i,9608376222244698514,5610749406096076171,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
704"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5136 --field-trial-handle=2368,i,10922741001453367200,1545606378191669911,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
924"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=3504 --field-trial-handle=2368,i,10922741001453367200,1545606378191669911,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1088"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5152 --field-trial-handle=2360,i,9608376222244698514,5610749406096076171,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1188"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5856 --field-trial-handle=2360,i,9608376222244698514,5610749406096076171,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1268"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5064 --field-trial-handle=2368,i,10922741001453367200,1545606378191669911,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1300"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6300 --field-trial-handle=2360,i,9608376222244698514,5610749406096076171,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
13 782
Read events
13 720
Write events
62
Delete events
0

Modification events

(PID) Process:(2652) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2652) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2652) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2652) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\EmulatorHub.zip
(PID) Process:(2652) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2652) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2652) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2652) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1452) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1452) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
Executable files
46
Suspicious files
616
Text files
107
Unknown types
0

Dropped files

PID
Process
Filename
Type
2652WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2652.19970\hostfxr.dllexecutable
MD5:A4431266F13F98D48A2F2B10FD2D8A71
SHA256:88945E1FD1B63C3D941F67E6CF161680F1288C97FB7AC6028D2645477708F124
2652WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2652.19970\clrjit.dllexecutable
MD5:92795535F2855D02685A78985D2F3D28
SHA256:7399B0EFE5B3D0A9656F35A7317C9210DFDA4374FBBA7B2FD07671A5855A9345
2652WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2652.19970\Microsoft.Win32.Primitives.dllexecutable
MD5:CC3035B444919AAF960F226B256C612A
SHA256:C5892083EF60BEAF9551F8DF3DCF4FED0FC2CE96A289AB1B1835979A1DB88FD2
2652WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2652.19970\EmulatorHub.exeexecutable
MD5:A614A895161A44B174F8B0C5E0D94ADF
SHA256:D6F67C596A3017FAB0F6908F38DE0F996FE8742DC7131D491343D128D96564F6
2652WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2652.19970\mscorrc.dllexecutable
MD5:BDECE42256D2FEECA61137600FEA776C
SHA256:77059063FB0EC24504FFA21AC9EE3C7D2D93601E75CDCF868A591023351E2120
2652WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2652.19970\README.txttext
MD5:3A06935DDF57B2FACEC08DEA3D29740C
SHA256:77CFCB6BA324785DE19110F03E7DF78ED523A61F747824B296B924D584F9D154
2652WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2652.19970\hostpolicy.dllexecutable
MD5:04AEBB8B06CBFA10DE7225F2AE76F98F
SHA256:BFC1C6DD5EED11E15882A3D9E85C63A942A10F81C82D21BB0E7A190BA2D49A91
2652WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2652.19970\System.Linq.dllexecutable
MD5:4038F1C2BB864A85D045CB5CA7BB90BA
SHA256:8F526784997A07AA611BCE91BB33937DD4A686980AF6B857B24AD39CC1BFEC2A
1452msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF121db2.TMP
MD5:
SHA256:
2652WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2652.19970\System.Private.CoreLib.dllexecutable
MD5:C8EBFCFD8C7A69E30D45B4498ECE29D0
SHA256:620A4B11FB37AB997950870B06FEE3038C5922A052E06871B9C1A7E1A19C1262
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
59
TCP/UDP connections
96
DNS requests
128
Threats
13

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.193:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8012
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6028
svchost.exe
HEAD
200
208.89.74.19:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/d6657c24-83fb-4293-9f47-78f2c45a989f?P1=1749890238&P2=404&P3=2&P4=Lt8uHhoYVmFrfHW0%2fmzsPqOkFSrMIUv9%2fXYxwQCacyzRfVbxfWdqXcyfJ614YfaY2BT8z87HvgCdNKh7ud8zfg%3d%3d
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6028
svchost.exe
GET
206
208.89.74.19:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/d6657c24-83fb-4293-9f47-78f2c45a989f?P1=1749890238&P2=404&P3=2&P4=Lt8uHhoYVmFrfHW0%2fmzsPqOkFSrMIUv9%2fXYxwQCacyzRfVbxfWdqXcyfJ614YfaY2BT8z87HvgCdNKh7ud8zfg%3d%3d
unknown
whitelisted
6028
svchost.exe
GET
206
208.89.74.19:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/d6657c24-83fb-4293-9f47-78f2c45a989f?P1=1749890238&P2=404&P3=2&P4=Lt8uHhoYVmFrfHW0%2fmzsPqOkFSrMIUv9%2fXYxwQCacyzRfVbxfWdqXcyfJ614YfaY2BT8z87HvgCdNKh7ud8zfg%3d%3d
unknown
whitelisted
6028
svchost.exe
GET
206
208.89.74.19:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/d6657c24-83fb-4293-9f47-78f2c45a989f?P1=1749890238&P2=404&P3=2&P4=Lt8uHhoYVmFrfHW0%2fmzsPqOkFSrMIUv9%2fXYxwQCacyzRfVbxfWdqXcyfJ614YfaY2BT8z87HvgCdNKh7ud8zfg%3d%3d
unknown
whitelisted
6028
svchost.exe
GET
206
208.89.74.19:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b96d4ca8-86b5-4bcc-9b2f-8200e97368c2?P1=1749818640&P2=404&P3=2&P4=mXoKkZE%2fpuq6jXFxm4S2CwQYABw79PVIo8o9TobyT%2bnlcLNqO%2fdfsTW5C6S9gva3NeA7XkeIwwWZNNkgcvgYJw%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2088
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.193:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
7552
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6344
msedge.exe
239.255.255.250:1900
whitelisted
2284
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2284
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.193
  • 23.48.23.156
  • 23.48.23.145
  • 23.48.23.190
  • 23.48.23.194
  • 23.48.23.143
  • 23.48.23.183
  • 23.48.23.180
  • 23.48.23.147
whitelisted
google.com
  • 142.250.186.110
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
igk.filexspace.com
  • 104.21.112.1
  • 104.21.96.1
  • 104.21.80.1
  • 104.21.64.1
  • 104.21.48.1
  • 104.21.32.1
  • 104.21.16.1
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.253.45
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
okrius.live
  • 172.67.165.172
  • 104.21.11.83
unknown

Threats

PID
Process
Class
Message
2284
msedge.exe
Potentially Bad Traffic
ET INFO DNS Query for Suspicious .icu Domain
2284
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2284
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2284
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2284
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2284
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2284
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2284
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2284
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2284
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
No debug info