| URL: | https://sites.google.com/view/clau-ver-un-24 |
| Full analysis: | https://app.any.run/tasks/3664a9c7-4955-48b8-a4da-f2f83266fb39 |
| Verdict: | Malicious activity |
| Threats: | ClickFix is a sophisticated social engineering technique that tricks users into manually executing malicious commands on their devices. It masquerades as a "quick fix" for fake technical issues, CAPTCHA verifications, or error messages, often hijacking the clipboard to paste harmful PowerShell or terminal commands. This user-assisted approach helps it bypass traditional security controls, leading to infostealers like Lumma Stealer, RATs, and other malware. |
| Analysis date: | June 03, 2026, 23:17:25 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 08A7160A2B569A32CAA767F4ECAEA610 |
| SHA1: | BD6D18A5521B93E2F845CECF049135980943641B |
| SHA256: | C460C423D63AE4CE302CCEB5C2CF1BCB171C8A3985B8BA9776EF7CC7CF71711C |
| SSDEEP: | 3:N8BhLJ3u1iGn:2J+Nn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 656 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6368,i,10372455336201361136,8134458495444944852,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6888 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1604 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2820,i,10372455336201361136,8134458495444944852,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=2828 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1860 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5664,i,10372455336201361136,8134458495444944852,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5648 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2112 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --disable-quic --onnx-enabled-for-ee --string-annotations --always-read-main-dll --field-trial-handle=5588,i,10372455336201361136,8134458495444944852,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5600 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2200 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3652,i,10372455336201361136,8134458495444944852,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=3660 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2936 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=1500,i,10372455336201361136,8134458495444944852,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=7148 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 3612 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2264,i,10372455336201361136,8134458495444944852,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=2256 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 4516 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6888,i,10372455336201361136,8134458495444944852,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6644 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 5916 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=10 --always-read-main-dll --field-trial-handle=4548,i,10372455336201361136,8134458495444944852,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5552 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 6436 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6684,i,10372455336201361136,8134458495444944852,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6384 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7888 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1594e7.TMP | — | |
MD5:— | SHA256:— | |||
| 7888 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7888 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1594f6.TMP | — | |
MD5:— | SHA256:— | |||
| 7888 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7888 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF159506.TMP | — | |
MD5:— | SHA256:— | |||
| 7888 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7888 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF159506.TMP | — | |
MD5:— | SHA256:— | |||
| 7888 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7888 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF159506.TMP | — | |
MD5:— | SHA256:— | |||
| 7888 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAFUWohyJgUzPcAAAAAAAU%3D | US | binary | 959 b | whitelisted |
— | — | GET | 200 | 23.11.40.157:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D | NL | binary | 314 b | whitelisted |
7880 | msedge.exe | GET | 200 | 192.178.183.94:443 | https://www.gstatic.com/_/atari/_/js/k=atari.vw.en_US.dEf6FeHpS4U.O/am=CCAADgAE/d=0/rs=AGEqA5mX6lJSfr145yoGxNttYZQyVvhfNA/m=sy61,TRvtze | US | text | 852 b | whitelisted |
7880 | msedge.exe | GET | 200 | 192.178.183.94:443 | https://www.gstatic.com/_/atari/_/js/k=atari.vw.en_US.dEf6FeHpS4U.O/am=CCAADgAE/d=0/rs=AGEqA5mX6lJSfr145yoGxNttYZQyVvhfNA/m=rCcCxc,sy5y,gJzDyc,uu7UOe,sy67,uY3Nvd,sy66,soHxf,HYv29e | US | text | 71.0 Kb | whitelisted |
7880 | msedge.exe | GET | 200 | 192.178.183.94:443 | https://www.gstatic.com/_/atari/_/js/k=atari.vw.en_US.dEf6FeHpS4U.O/am=CCAADgAE/d=0/rs=AGEqA5mX6lJSfr145yoGxNttYZQyVvhfNA/m=LLHPdb,sy2x,ws9Tlc,cEt90b,sy72,KUM7Z,MpJwZc,n73qwf,A4UTCb,sy2w,L1AAkb,aW3pY,RyvaUb,sy2s,sy38,owcnme,sy39,sy3a,O6y8ed,mzzZzc,CHCSlb,qAKInc,sy3n,YXyON,sy40,X85Uvc,HIeYee,QxOCld,sy3s,sy3r,iTeaXe,sy63,abQiW,W26a5e,hJUyqe,sy12,sy11,sy10,syv,syu,sy3b,pxq3x,sy3c,syo,sy3d,sy3x,syw,sy29,sy3e,sy4r,sy62,EGNJFf,V3dDOb,sy2v,ENNBBf,syh,syf,syd,syn,syc,sy3h,yf2Bs,sy1c,sy1f,sy1b,sy19,sy1k,sy1h,sy1l,sy1n,sy1o,sy1i,sy1e,sy1a,sy1g,sy1j,sy1p,sy1d,syr,sy36,fmklff,TGYpv,syi,sy22,ruhlUe,XVMNvd,sy42,sy43,sy44,fuVYe,sy6z,yxTchf,sy70,sy71,xQtZb,iSvg6e,N5Lqpc,XDKZTc,sy41,qkPXAf,zPx2U,sy3v,sy3w,sy3t,sy3u,sy3q,sy3y,sy3z,pc62j,qEW1W,oNFsLb,m9oV,sy2z,RAnnUd,i5dxUd,sy2y,sy30,sy31,sy32,sy2e,etBPYb,i5H9N,SU9Rsf,sy33,sy34,sy35,sy2c,sy2f,PHUIyb,qNG0Fc,sys,syt,syx,qTnoBf,NJ1rfe,ywOR5c,sy37,sye,wg1P6b,EcW08c,sy3f,sy3g,t8tqF,qddgKe,sy65,SM1lmd,syy,syz,syq,RRzQxe,sya,sy9,sy14,sy21,yyxWAc,zZvHmd,sy3p,sy3k,sy3o,YV8yqd,sy0,sy1,sy7,sy2d,sy6,sy2b,sy2g,sy2a,sy28,sy2h,sy2i,sy1t,sy4y,syp,sy16,sy20,sy5x,syl,syb,sy4k,sy5q,sy15,fNFZH,sy64,sym,sy4q,sy2j,i16Xfc,sy4e,zJMuOc,RrXLpc,sy45,sy48,sy4f,sy4g,sy4h,tCGzVe,Ej8J2c,odWSx,cgRV2c,sy1z,sy56,o1L5Wb,X4BaPc,vVEdxc,sy4w,sy4x,sy2o,syg,sy3j,sy4m,sy4u,sy4t,sy4v,sy2u,sy17,sy2l,sy49,sy4l,Eb0cbd,vQfDHb,Ko0sOe,lC95Hd,WHVP1b,sy50,sy52,sy53,sy54,sy55,sy51,sy57,sy4z,sy59,sy4o,sy3l,sy58,sy5e,sy5l,sy4p,sy5d,sy5f,sy5g,sy1m,sy5b,sy5c,sy5k,sy5j,sy5m,sy2r,sy5n,G5ZZUb,sy25,sy3m,sy5a,sy4n,zmwrxd,Ik1vNd,sy5h,sy5i,oy3iwb,dBhIIb,sy5o,sy5p,sy5u,sy5r,a9i3ec,CmOog,qYIcH,zTt0Rb,ap0X9d,KgeHHc,NzVYMd,RU5sC,pmbBwd,paqebc,uUwMBf,zRiL5c,AQnEY,jhxjge,ZV9ZUe,Tc7Qif,heobjb,R4KMEc,KlrXId,dW2dhc,sy5s,sy5t,sy5v,UYjpC,sy24,sy26,sy8,sy13,sy1v,sy1w,sy23,gaMBzf,sy27,fVuHhf,j1RDQb,sy3i,sy4,iwfZq,sy5,eEDsnd,sy4j,sy1s,sy47,sy4i,RQOkef,sy4s,Md9ENb,sy46,sy4a,CG0Qwb,syj,VYKRW,RZ9OZ,N0NZx | US | text | 1.89 Mb | whitelisted |
7880 | msedge.exe | POST | 204 | 142.251.20.141:443 | https://csp.withgoogle.com/csp/proto/6b8ce7c01e3dacd3d2c7a8cd322ff979 | US | — | — | whitelisted |
7880 | msedge.exe | POST | 200 | 142.251.14.138:443 | https://sites.google.com/_/view/naLogImpressions?authuser=0 | US | text | 16 b | whitelisted |
7880 | msedge.exe | GET | 200 | 150.171.27.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:eYZIu0Dd9OTNNbxwNPmlHgzbNVZgjXNE4BdMjn3L-1U&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | US | text | 101 b | whitelisted |
7880 | msedge.exe | GET | 200 | 150.171.22.17:443 | https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=71&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0 | US | text | 8.17 Kb | whitelisted |
7880 | msedge.exe | GET | 200 | 150.171.27.11:443 | https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0 | US | text | 132 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5768 | svchost.exe | 48.209.133.15:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
5276 | MoUsoCoreWorker.exe | 48.209.133.15:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8268 | slui.exe | 48.192.1.64:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 184.86.251.19:443 | www.bing.com | AKAMAI-ASN1 | NL | whitelisted |
— | — | 23.11.40.157:80 | ocsp.digicert.com | AKAMAI-AMS | NL | whitelisted |
— | — | 204.79.197.203:80 | oneocsp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
7880 | msedge.exe | 150.171.27.11:80 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7880 | msedge.exe | 150.171.22.17:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
oneocsp.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
sites.google.com |
| whitelisted |
api.edgeoffer.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7880 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Clickfix related Domain (fairpoint29 .com) |
7880 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] ClickFix Related URL (/view/clau-ver-un-24) |
5768 | svchost.exe | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |