URL:

cleverfiles.com

Full analysis: https://app.any.run/tasks/1122793b-4ff0-44bf-a724-a7ed18e44ba3
Verdict: Malicious activity
Analysis date: December 09, 2024, 08:00:57
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

4EBBBE30B1F8D8BA9FE6191ECC20E20A

SHA1:

9F4640EE35B403380282B3F45BCCAB108ABA402A

SHA256:

B8E96C418B066B0EE6312286DCC7AD475A4472AC8636710D31EB26195BF716E7

SSDEEP:

3:7QMVKn:dVKn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • DiskDrillSetup.5.7.915.0.exe (PID: 7196)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 4392)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 1416)
    • Searches for installed software

      • disk-drill-win.exe (PID: 7448)
      • VC_redist.x64.exe (PID: 6280)
      • VC_redist.x64.exe (PID: 7828)
      • DokanSetup.exe (PID: 7176)
    • Reads security settings of Internet Explorer

      • disk-drill-win.exe (PID: 7448)
      • vc_redist.14.38.33135.x64.exe (PID: 3724)
      • VC_redist.x64.exe (PID: 7828)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 6860)
      • DokanSetup.1.5.1.1000.exe (PID: 5200)
      • msiexec.exe (PID: 2356)
    • Executable content was dropped or overwritten

      • disk-drill-win.exe (PID: 7460)
      • disk-drill-win.exe (PID: 7448)
      • vc_redist.14.38.33135.x64.exe (PID: 5488)
      • vc_redist.14.38.33135.x64.exe (PID: 3724)
      • DiskDrillSetup.5.7.915.0.exe (PID: 7196)
      • VC_redist.x64.exe (PID: 5004)
      • VC_redist.x64.exe (PID: 7828)
      • VC_redist.x64.exe (PID: 6280)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 6956)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 6860)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 4392)
      • DokanSetup.1.5.1.1000.exe (PID: 5200)
      • DokanSetup.1.5.1.1000.exe (PID: 7912)
      • DokanSetup.exe (PID: 7176)
      • rundll32.exe (PID: 1556)
      • rundll32.exe (PID: 6852)
      • rundll32.exe (PID: 4392)
    • Starts itself from another location

      • disk-drill-win.exe (PID: 7448)
      • vc_redist.14.38.33135.x64.exe (PID: 3724)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 6860)
      • DokanSetup.1.5.1.1000.exe (PID: 5200)
    • Starts a Microsoft application from unusual location

      • vc_redist.14.38.33135.x64.exe (PID: 3724)
      • VC_redist.x64.exe (PID: 5004)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 6860)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 4392)
    • Process drops legitimate windows executable

      • disk-drill-win.exe (PID: 7448)
      • vc_redist.14.38.33135.x64.exe (PID: 5488)
      • vc_redist.14.38.33135.x64.exe (PID: 3724)
      • DiskDrillSetup.5.7.915.0.exe (PID: 7196)
      • VC_redist.x64.exe (PID: 5004)
      • msiexec.exe (PID: 2356)
      • VC_redist.x64.exe (PID: 6280)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 6956)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 6860)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 4392)
    • Checks Windows Trust Settings

      • disk-drill-win.exe (PID: 7448)
      • msiexec.exe (PID: 2356)
    • Creates a software uninstall entry

      • DiskDrillSetup.5.7.915.0.exe (PID: 7196)
      • VC_redist.x64.exe (PID: 5004)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 4392)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 2356)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 2356)
    • Application launched itself

      • VC_redist.x64.exe (PID: 5244)
      • VC_redist.x64.exe (PID: 7828)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 2356)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 2356)
      • msiexec.exe (PID: 7144)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 6704)
    • Uses TASKKILL.EXE to kill process

      • msiexec.exe (PID: 1412)
    • Process drops SQLite DLL files

      • msiexec.exe (PID: 2356)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 8132)
      • identity_helper.exe (PID: 4300)
      • disk-drill-win.exe (PID: 7460)
      • vc_redist.14.38.33135.x64.exe (PID: 3724)
      • msiexec.exe (PID: 2356)
      • VC_redist.x64.exe (PID: 5244)
      • VC_redist.x64.exe (PID: 6280)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 6956)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 6860)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 4392)
      • msiexec.exe (PID: 6980)
      • msiexec.exe (PID: 7068)
      • msiexec.exe (PID: 1356)
      • DokanSetup.exe (PID: 7176)
      • DokanSetup.1.5.1.1000.exe (PID: 5200)
      • msiexec.exe (PID: 7144)
      • dokanctl.exe (PID: 5652)
      • msiexec.exe (PID: 1412)
      • msiexec.exe (PID: 7852)
      • cfbackd.w32.exe (PID: 648)
    • Reads the computer name

      • identity_helper.exe (PID: 8132)
      • disk-drill-win.exe (PID: 7448)
      • DiskDrillSetup.5.7.915.0.exe (PID: 7196)
      • msiexec.exe (PID: 2356)
      • VC_redist.x64.exe (PID: 5004)
      • VC_redist.x64.exe (PID: 6280)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 6956)
      • VC_redist.x64.exe (PID: 7828)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 4392)
      • msiexec.exe (PID: 7068)
      • msiexec.exe (PID: 1356)
      • msiexec.exe (PID: 1412)
      • cfbackd.w32.exe (PID: 648)
    • Reads Environment values

      • identity_helper.exe (PID: 8132)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 6356)
      • msedge.exe (PID: 3508)
      • msedge.exe (PID: 5548)
      • msiexec.exe (PID: 2356)
      • msiexec.exe (PID: 7144)
    • The process uses the downloaded file

      • msedge.exe (PID: 7924)
      • msedge.exe (PID: 3508)
      • disk-drill-win.exe (PID: 7448)
    • Manages system restore points

      • SrTasks.exe (PID: 7940)
    • Create files in a temporary directory

      • disk-drill-win.exe (PID: 7460)
      • disk-drill-win.exe (PID: 7448)
    • Application launched itself

      • msedge.exe (PID: 3508)
      • msiexec.exe (PID: 2356)
    • Creates files in the program directory

      • DiskDrillSetup.5.7.915.0.exe (PID: 7196)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 4392)
    • Checks proxy server information

      • disk-drill-win.exe (PID: 7448)
    • Reads the machine GUID from the registry

      • DiskDrillSetup.5.7.915.0.exe (PID: 7196)
      • disk-drill-win.exe (PID: 7448)
      • msiexec.exe (PID: 2356)
      • VC_redist.x64.exe (PID: 5004)
      • windowsdesktop-runtime-8.0.8-win-x64.exe (PID: 4392)
      • DokanSetup.exe (PID: 7176)
      • msiexec.exe (PID: 7144)
    • Creates files or folders in the user directory

      • disk-drill-win.exe (PID: 7448)
    • Reads the software policy settings

      • disk-drill-win.exe (PID: 7448)
      • msiexec.exe (PID: 2356)
      • rundll32.exe (PID: 4392)
    • Process checks computer location settings

      • vc_redist.14.38.33135.x64.exe (PID: 3724)
      • DokanSetup.1.5.1.1000.exe (PID: 5200)
    • Sends debugging messages

      • msiexec.exe (PID: 2356)
      • rundll32.exe (PID: 4392)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2356)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 4392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
248
Monitored processes
110
Malicious processes
10
Suspicious processes
4

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs disk-drill-win.exe disk-drill-win.exe msedge.exe no specs msedge.exe no specs diskdrillsetup.5.7.915.0.exe SPPSurrogate no specs vssvc.exe no specs msedge.exe no specs srtasks.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe vc_redist.14.38.33135.x64.exe vc_redist.14.38.33135.x64.exe vc_redist.x64.exe SPPSurrogate no specs msiexec.exe vc_redist.x64.exe no specs vc_redist.x64.exe vc_redist.x64.exe windowsdesktop-runtime-8.0.8-win-x64.exe windowsdesktop-runtime-8.0.8-win-x64.exe windowsdesktop-runtime-8.0.8-win-x64.exe msiexec.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs dokansetup.1.5.1.1000.exe msedge.exe no specs dokansetup.1.5.1.1000.exe dokansetup.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs dokanctl.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe no specs rundll32.exe rundll32.exe msiexec.exe no specs msedge.exe no specs taskkill.exe no specs conhost.exe no specs cfbackd.w32.exe no specs conhost.exe rundll32.exe

Process information

PID
CMD
Path
Indicators
Parent process
648"C:\Program Files\CleverFiles\Disk Drill\cfbackd.w32.exe" -iC:\Program Files\CleverFiles\Disk Drill\cfbackd.w32.exemsiexec.exe
User:
admin
Company:
CleverFiles
Integrity Level:
HIGH
Description:
DiskDrill service
Exit code:
0
Version:
0.1.2.52
Modules
Images
c:\program files\cleverfiles\disk drill\cfbackd.w32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
936"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=31 --mojo-platform-channel-handle=6768 --field-trial-handle=2280,i,2750662622366601647,15280061484450443264,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1296"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=41 --mojo-platform-channel-handle=7048 --field-trial-handle=2280,i,2750662622366601647,15280061484450443264,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1356C:\Windows\syswow64\MsiExec.exe -Embedding 95380E33FC35DF00D6A82E8979156AD1C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1412C:\Windows\syswow64\MsiExec.exe -Embedding C5C7E532454BBD20C06654B0D90033D1 E Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1416C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1556rundll32.exe "C:\WINDOWS\Installer\MSI1718.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1513328 112 msiGaCustomAction!msiGaCustomAction.CustomActions.gaCheckInstallConditionCustomActionC:\Windows\System32\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
2356C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2600"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=8576 --field-trial-handle=2280,i,2750662622366601647,15280061484450443264,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2672"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=8116 --field-trial-handle=2280,i,2750662622366601647,15280061484450443264,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
36 805
Read events
34 363
Write events
1 986
Delete events
456

Modification events

(PID) Process:(3508) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3508) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3508) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3508) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(3508) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
759C7D0C68872F00
(PID) Process:(3508) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
B7F9870C68872F00
(PID) Process:(3508) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328358
Operation:writeName:WindowTabManagerFileMappingId
Value:
{394A7498-E390-49A2-9020-2113D0785D2C}
(PID) Process:(3508) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328358
Operation:writeName:WindowTabManagerFileMappingId
Value:
{B82722E8-83B4-4423-8E73-17FBBB08AE46}
(PID) Process:(3508) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328358
Operation:writeName:WindowTabManagerFileMappingId
Value:
{0AD1AFD7-7D09-4409-A85A-8FF15D5627B4}
(PID) Process:(3508) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328358
Operation:writeName:WindowTabManagerFileMappingId
Value:
{F52BB6C3-0093-4A6A-969B-0366957AA103}
Executable files
700
Suspicious files
837
Text files
348
Unknown types
19

Dropped files

PID
Process
Filename
Type
3508msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1352b7.TMP
MD5:
SHA256:
3508msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
3508msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1352b7.TMP
MD5:
SHA256:
3508msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
3508msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1352b7.TMP
MD5:
SHA256:
3508msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
3508msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1352c7.TMP
MD5:
SHA256:
3508msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
3508msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF135324.TMP
MD5:
SHA256:
3508msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
66
TCP/UDP connections
147
DNS requests
137
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1356
svchost.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1356
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6984
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4444
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4444
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6688
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1733957610&P2=404&P3=2&P4=bnVLrfTUUDrEUB%2bl53zLvWdX0lZxKqGab%2bda1Hn%2bQRWbDkGXOxWlLe20tHGBSaxVoJhqwmBp12BAW96MgNW9XA%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.49.150.241:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
1356
svchost.exe
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
1356
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3508
msedge.exe
239.255.255.250:1900
whitelisted
6356
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6356
msedge.exe
67.225.176.50:80
cleverfiles.com
LIQUIDWEB
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.49.150.241
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 2.16.164.106
  • 2.16.164.49
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
google.com
  • 142.250.186.174
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
cleverfiles.com
  • 67.225.176.50
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.253.45
whitelisted
bzib.nelreports.net
  • 2.22.242.105
  • 2.22.242.11
whitelisted

Threats

No threats detected
Process
Message
msiexec.exe
Failed to release Service
rundll32.exe
Log filename:C:\Users\admin\AppData\Local\Temp\DDInstall.cpccLog.txt
rundll32.exe
c Initialize with App filename:C:\WINDOWS\system32\rundll32.exe