File name:

jjsploit_8.17.7_x64_en-US.msi

Full analysis: https://app.any.run/tasks/54fa8c10-c963-4885-a73e-a2623f23b399
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: February 28, 2026, 12:11:26
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
loader
github
roblox
qrcode
arch-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: jjsploit, Author: wearedevs, Keywords: Installer, Comments: This installer database contains the logic and data required to install jjsploit., Template: x64;0, Revision Number: {8394103A-0A4A-4372-BC41-8CCBED0B1E7D}, Create Time/Date: Tue Feb 10 15:22:10 2026, Last Saved Time/Date: Tue Feb 10 15:22:10 2026, Number of Pages: 450, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
MD5:

E04EE1D026F44051B3D3A464A2D29ADE

SHA1:

4695189629E708C1951319B1ADCDAD3E06939F04

SHA256:

C47F34E3B353518F5A81800B2E1EBBC0E0A14AFBC843D760C5D187F3D8262E93

SSDEEP:

98304:nWXBSo/hT/x2GB19dkM1j5IlUATheB6vneck2V9WOHtfuMIE9tqQJ7H3qrQFFduh:aUXtq2O4HIeSp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Run PowerShell with an invisible window

      • powershell.exe (PID: 8240)
    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 5472)
    • Potential DLL hijacking behavior detected

      • msedgewebview2.exe (PID: 2372)
      • msedgewebview2.exe (PID: 8944)
      • msedgewebview2.exe (PID: 5804)
    • Scans artifacts that could help determine the target

      • msedgewebview2.exe (PID: 6804)
      • msedgewebview2.exe (PID: 8252)
      • msedgewebview2.exe (PID: 752)
  • SUSPICIOUS

    • Manipulates environment variables

      • powershell.exe (PID: 8240)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6596)
    • Starts process via Powershell

      • powershell.exe (PID: 8240)
    • Starts POWERSHELL.EXE for commands execution

      • msiexec.exe (PID: 8388)
    • Downloads file from URI via Powershell

      • powershell.exe (PID: 8240)
    • The process bypasses the loading of PowerShell profile settings

      • msiexec.exe (PID: 8388)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 8240)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 8240)
      • MicrosoftEdgeWebview2Setup.exe (PID: 3332)
      • MicrosoftEdgeUpdate.exe (PID: 5472)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 5536)
      • setup.exe (PID: 6940)
      • jjsploit.exe (PID: 8920)
      • RobloxPlayerInstaller.exe (PID: 5448)
      • msedgewebview2.exe (PID: 8404)
      • msedgewebview2.exe (PID: 8780)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebview2Setup.exe (PID: 3332)
      • MicrosoftEdgeUpdate.exe (PID: 5472)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 5472)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7368)
      • MicrosoftEdgeUpdate.exe (PID: 6568)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7312)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8796)
    • Application launched itself

      • setup.exe (PID: 6940)
      • msedgewebview2.exe (PID: 6804)
      • MicrosoftEdgeUpdate.exe (PID: 4140)
      • msedgewebview2.exe (PID: 8224)
      • jjsploit.exe (PID: 8920)
      • msedgewebview2.exe (PID: 8252)
      • jjsploit.exe (PID: 8480)
      • msedgewebview2.exe (PID: 752)
    • Searches for installed software

      • setup.exe (PID: 6940)
      • msedgewebview2.exe (PID: 752)
    • Changes default file association

      • RobloxPlayerInstaller.exe (PID: 5448)
    • Executes application which crashes

      • RobloxPlayerBeta.exe (PID: 3376)
      • RobloxPlayerBeta.exe (PID: 9004)
      • RobloxPlayerBeta.exe (PID: 6704)
  • INFO

    • Drops script file

      • msedge.exe (PID: 8416)
      • msedge.exe (PID: 8372)
      • powershell.exe (PID: 8240)
      • setup.exe (PID: 6940)
      • msedge.exe (PID: 8904)
      • RobloxPlayerInstaller.exe (PID: 5448)
    • Reads the computer name

      • msiexec.exe (PID: 8388)
      • msiexec.exe (PID: 6828)
      • MicrosoftEdgeUpdate.exe (PID: 5472)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8796)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7368)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7312)
      • MicrosoftEdgeUpdate.exe (PID: 5048)
      • MicrosoftEdgeUpdate.exe (PID: 6568)
      • MicrosoftEdgeUpdate.exe (PID: 6992)
      • MicrosoftEdgeUpdate.exe (PID: 4140)
      • MicrosoftEdgeUpdate.exe (PID: 8572)
      • MicrosoftEdgeUpdateCore.exe (PID: 2376)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 5536)
      • setup.exe (PID: 6940)
      • jjsploit.exe (PID: 1456)
      • jjsploit.exe (PID: 6476)
      • msedgewebview2.exe (PID: 6804)
      • msedgewebview2.exe (PID: 2372)
      • MicrosoftEdgeUpdate.exe (PID: 5208)
      • msedgewebview2.exe (PID: 2096)
      • jjsploit.exe (PID: 8920)
      • msedgewebview2.exe (PID: 8224)
      • jjsploit.exe (PID: 8480)
      • msedgewebview2.exe (PID: 8252)
      • msedgewebview2.exe (PID: 8944)
      • msedgewebview2.exe (PID: 6600)
      • jjsploit.exe (PID: 3092)
      • msedgewebview2.exe (PID: 752)
      • msedgewebview2.exe (PID: 5804)
      • msedgewebview2.exe (PID: 7100)
      • identity_helper.exe (PID: 7812)
      • RobloxPlayerInstaller.exe (PID: 5448)
      • msedgewebview2.exe (PID: 7560)
      • identity_helper.exe (PID: 7408)
    • An automatically generated document

      • msiexec.exe (PID: 8392)
    • Manages system restore points

      • SrTasks.exe (PID: 4952)
    • Checks supported languages

      • msiexec.exe (PID: 6828)
      • msiexec.exe (PID: 8388)
      • MicrosoftEdgeWebview2Setup.exe (PID: 3332)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8796)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7368)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7312)
      • MicrosoftEdgeUpdate.exe (PID: 5048)
      • MicrosoftEdgeUpdate.exe (PID: 6568)
      • MicrosoftEdgeUpdate.exe (PID: 5472)
      • MicrosoftEdgeUpdate.exe (PID: 4140)
      • MicrosoftEdgeUpdate.exe (PID: 6992)
      • MicrosoftEdgeUpdateCore.exe (PID: 2376)
      • MicrosoftEdgeUpdate.exe (PID: 8572)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 5536)
      • setup.exe (PID: 6940)
      • setup.exe (PID: 2392)
      • jjsploit.exe (PID: 1456)
      • jjsploit.exe (PID: 6476)
      • msedgewebview2.exe (PID: 6804)
      • msedgewebview2.exe (PID: 2232)
      • msedgewebview2.exe (PID: 2372)
      • msedgewebview2.exe (PID: 7348)
      • msedgewebview2.exe (PID: 2096)
      • msedgewebview2.exe (PID: 8412)
      • MicrosoftEdgeUpdate.exe (PID: 5208)
      • jjsploit.exe (PID: 8920)
      • msedgewebview2.exe (PID: 7056)
      • msedgewebview2.exe (PID: 8224)
      • msedgewebview2.exe (PID: 4312)
      • jjsploit.exe (PID: 8480)
      • msedgewebview2.exe (PID: 1188)
      • msedgewebview2.exe (PID: 8944)
      • msedgewebview2.exe (PID: 6600)
      • msedgewebview2.exe (PID: 8252)
      • msedgewebview2.exe (PID: 6332)
      • msedgewebview2.exe (PID: 3996)
      • msedgewebview2.exe (PID: 752)
      • jjsploit.exe (PID: 3092)
      • msedgewebview2.exe (PID: 8888)
      • msedgewebview2.exe (PID: 2996)
      • msedgewebview2.exe (PID: 5804)
      • msedgewebview2.exe (PID: 7100)
      • msedgewebview2.exe (PID: 1612)
      • identity_helper.exe (PID: 7812)
      • msedgewebview2.exe (PID: 3376)
      • RobloxPlayerInstaller.exe (PID: 5448)
      • msedgewebview2.exe (PID: 5728)
      • msedgewebview2.exe (PID: 7144)
      • RobloxPlayerBeta.exe (PID: 3376)
      • msedgewebview2.exe (PID: 3644)
      • msedgewebview2.exe (PID: 7560)
      • RobloxPlayerBeta.exe (PID: 6704)
      • msedgewebview2.exe (PID: 8404)
      • identity_helper.exe (PID: 7408)
      • RobloxPlayerBeta.exe (PID: 9004)
      • msedgewebview2.exe (PID: 8780)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 8388)
      • msiexec.exe (PID: 8392)
      • msedge.exe (PID: 8416)
    • Disables trace logs

      • powershell.exe (PID: 8240)
    • The sample compiled with english language support

      • powershell.exe (PID: 8240)
      • MicrosoftEdgeUpdate.exe (PID: 5472)
      • MicrosoftEdgeWebview2Setup.exe (PID: 3332)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 5536)
      • setup.exe (PID: 6940)
      • jjsploit.exe (PID: 8920)
      • msedge.exe (PID: 8416)
      • RobloxPlayerInstaller.exe (PID: 5448)
      • msedgewebview2.exe (PID: 8404)
    • The executable file from the user directory is run by the Powershell process

      • MicrosoftEdgeWebview2Setup.exe (PID: 3332)
    • Create files in a temporary directory

      • MicrosoftEdgeWebview2Setup.exe (PID: 3332)
      • msedgewebview2.exe (PID: 6804)
      • msedgewebview2.exe (PID: 8252)
      • msedgewebview2.exe (PID: 752)
      • RobloxPlayerInstaller.exe (PID: 5448)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 5472)
      • MicrosoftEdgeUpdate.exe (PID: 4140)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 5536)
      • setup.exe (PID: 6940)
      • setup.exe (PID: 2392)
      • msedgewebview2.exe (PID: 6804)
      • msedgewebview2.exe (PID: 2232)
      • msedgewebview2.exe (PID: 2096)
      • jjsploit.exe (PID: 6476)
      • jjsploit.exe (PID: 8920)
      • msedgewebview2.exe (PID: 8252)
      • msedgewebview2.exe (PID: 6600)
      • msedgewebview2.exe (PID: 752)
      • msedgewebview2.exe (PID: 7100)
      • RobloxPlayerInstaller.exe (PID: 5448)
      • msedgewebview2.exe (PID: 7560)
    • Launching a file from a Registry key

      • MicrosoftEdgeUpdate.exe (PID: 5472)
    • Checks proxy server information

      • powershell.exe (PID: 8240)
      • MicrosoftEdgeUpdate.exe (PID: 5048)
      • MicrosoftEdgeUpdate.exe (PID: 4140)
      • msedgewebview2.exe (PID: 6804)
      • MicrosoftEdgeUpdate.exe (PID: 5208)
      • jjsploit.exe (PID: 8920)
      • msedgewebview2.exe (PID: 8252)
      • jjsploit.exe (PID: 8480)
      • msedgewebview2.exe (PID: 752)
      • jjsploit.exe (PID: 3092)
      • slui.exe (PID: 8468)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 5048)
      • msedgewebview2.exe (PID: 6804)
      • MicrosoftEdgeUpdate.exe (PID: 5208)
      • msedgewebview2.exe (PID: 8252)
      • msedgewebview2.exe (PID: 752)
      • identity_helper.exe (PID: 7812)
      • identity_helper.exe (PID: 7408)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 5472)
      • MicrosoftEdgeUpdate.exe (PID: 4140)
      • msedgewebview2.exe (PID: 6804)
      • msedgewebview2.exe (PID: 8252)
      • msedgewebview2.exe (PID: 752)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 5472)
      • setup.exe (PID: 6940)
      • msedgewebview2.exe (PID: 6804)
      • msedgewebview2.exe (PID: 8412)
      • msedgewebview2.exe (PID: 4312)
      • msedgewebview2.exe (PID: 8252)
      • msedgewebview2.exe (PID: 6332)
      • msedgewebview2.exe (PID: 752)
      • msedgewebview2.exe (PID: 1612)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 4140)
      • msedgewebview2.exe (PID: 6804)
      • jjsploit.exe (PID: 8920)
      • msedgewebview2.exe (PID: 8252)
      • jjsploit.exe (PID: 8480)
      • msedgewebview2.exe (PID: 752)
      • jjsploit.exe (PID: 3092)
      • RobloxPlayerInstaller.exe (PID: 5448)
      • msedgewebview2.exe (PID: 7560)
    • Manual execution by a user

      • MicrosoftEdgeUpdateCore.exe (PID: 2376)
      • jjsploit.exe (PID: 1456)
      • jjsploit.exe (PID: 6476)
      • msedge.exe (PID: 8416)
      • msedge.exe (PID: 8372)
      • RobloxPlayerBeta.exe (PID: 9004)
      • RobloxPlayerBeta.exe (PID: 6704)
    • Creates a software uninstall entry

      • setup.exe (PID: 6940)
      • RobloxPlayerInstaller.exe (PID: 5448)
    • Application launched itself

      • msedge.exe (PID: 8416)
      • msedge.exe (PID: 8372)
      • msedge.exe (PID: 6424)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 8416)
    • ROBLOX mutex has been found

      • RobloxPlayerInstaller.exe (PID: 5448)
    • Process checks whether UAC notifications are on

      • RobloxPlayerInstaller.exe (PID: 5448)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: jjsploit
Author: wearedevs
Keywords: Installer
Comments: This installer database contains the logic and data required to install jjsploit.
Template: x64;0
RevisionNumber: {8394103A-0A4A-4372-BC41-8CCBED0B1E7D}
CreateDate: 2026:02:10 15:22:10
ModifyDate: 2026:02:10 15:22:10
Pages: 450
Words: 2
Software: Windows Installer XML Toolset (3.14.1.8722)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
286
Monitored processes
118
Malicious processes
8
Suspicious processes
3

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
224"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_collections.mojom.CollectionsDataManager --lang=en-US --service-sandbox-type=collections --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=1624,i,3522770800737212884,16120448897142772308,262144 --variations-seed-version --mojo-platform-channel-handle=5564 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
752"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=jjsploit.exe --webview-exe-version=8.17.7 --user-data-dir="C:\Users\admin\AppData\Local\net.wearedevs\EBWebView" --noerrdialogs --embedded-browser-webview-dpi-awareness=2 --autoplay-policy=no-user-gesture-required --disable-features=msWebOOUI,msPdfOOUI,msSmartScreenProtection --lang=en-US --mojo-named-platform-channel-pipe=3092.4064.14876372659884401305C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exe
jjsploit.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Version:
145.0.3800.82
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.82\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.82\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\version.dll
876"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=11 --always-read-main-dll --field-trial-handle=5676,i,9697322072451736338,4623024258109654244,262144 --variations-seed-version --mojo-platform-channel-handle=5620 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1080"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5888,i,9697322072451736338,4623024258109654244,262144 --variations-seed-version --mojo-platform-channel-handle=5748 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1188C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exe --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Local\net.wearedevs\EBWebView /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\net.wearedevs\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=145.0.7632.117 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exe --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=145.0.3800.82 --initial-client-data=0x184,0x188,0x18c,0x10c,0x194,0x7ffd6eda0f18,0x7ffd6eda0f24,0x7ffd6eda0f30C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
145.0.3800.82
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.82\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.82\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1456"C:\Program Files\jjsploit\jjsploit.exe" C:\Program Files\jjsploit\jjsploit.exe
explorer.exe
User:
admin
Company:
wearedevs
Integrity Level:
MEDIUM
Description:
jjsploit
Version:
8.17.7
Modules
Images
c:\program files\jjsploit\jjsploit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1612"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\net.wearedevs\EBWebView" --webview-exe-name=jjsploit.exe --webview-exe-version=8.17.7 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --autoplay-policy=no-user-gesture-required --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--expose-gc --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --ram-no-pressure-read-main-dll --metrics-shmem-handle=3208,i,13710582380677975906,5572630799565123207,2097152 --field-trial-handle=1828,i,15996359708427372013,16030964151002578426,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --trace-process-track-uuid=3190708990997080739 --mojo-platform-channel-handle=3712 /prefetch:1C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Version:
145.0.3800.82
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.82\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.82\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
2096"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\net.wearedevs\EBWebView" --webview-exe-name=jjsploit.exe --webview-exe-version=8.17.7 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --startup-read-main-dll --metrics-shmem-handle=2152,i,10782951814042813997,15697105479456854076,524288 --field-trial-handle=1884,i,4570391260802320626,5961807020414097388,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=2156 /prefetch:3C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exe
msedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
145.0.3800.82
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.82\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.82\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
2164\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2232C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exe --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Local\net.wearedevs\EBWebView /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\net.wearedevs\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=145.0.7632.117 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exe --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=145.0.3800.82 --initial-client-data=0x190,0x194,0x198,0x16c,0x1a0,0x7ffd686c0f18,0x7ffd686c0f24,0x7ffd686c0f30C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.82\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
145.0.3800.82
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.82\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.82\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
Total events
38 161
Read events
36 526
Write events
1 556
Delete events
79

Modification events

(PID) Process:(8388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000832CCB62ABA8DC01C42000008C1A0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000AF8ECD62ABA8DC01C42000008C1A0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000FE272863ABA8DC01C42000008C1A0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
48000000000000009D264763ABA8DC01C42000008C1A0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000FBD65763ABA8DC01C419000058230000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000FBD65763ABA8DC01C419000004220000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000FBD65763ABA8DC01C4190000300B0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000D9385A63ABA8DC01C419000014230000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(6596) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
Executable files
272
Suspicious files
976
Text files
605
Unknown types
144

Dropped files

PID
Process
Filename
Type
8388msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
8388msiexec.exeC:\Windows\Installer\1e9a1b.msi
MD5:
SHA256:
8388msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:B5577DF885BB5893F8890E0A84621276
SHA256:8DA91C902F887596982FAD6D317BFDF306A1BB6F3B4B65E18C66EF1AF5B49C92
8392msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI5D60.tmpexecutable
MD5:CFBB8568BD3711A97E6124C56FCFA8D9
SHA256:7F47D98AB25CFEA9B3A2E898C3376CC9BA1CD893B4948B0C27CAA530FD0E34CC
8388msiexec.exeC:\Windows\Installer\MSI9CCA.tmpbinary
MD5:71C59B0C565FD68E3CD32D7217698F2E
SHA256:E2890DEB45BD38ADAA80271464DEDAA666C37BD5E68D7A86A1B5555B3A24A9EC
8388msiexec.exeC:\Windows\Temp\~DF2DFA4FF6D60D9F78.TMPbinary
MD5:B0D6C82F390FFC1B9CED333996E59B26
SHA256:AFB1AFF8B4FD1EAE590B726E09EF428A850DF8F97819D47C872526D5DDAB87EF
8388msiexec.exeC:\Program Files\jjsploit\jjsploit.exeexecutable
MD5:7650D2744BA2C4E1B0C1F00CCB571D7C
SHA256:1D0917B788584E0B5F3687632260D0605D3CBD075949D77C810DF907CF13DF53
8388msiexec.exeC:\Program Files\jjsploit\resources\luascripts\jailbreak\walkspeed.luatext
MD5:76D6BC545A92D108FF8A18614A5DB4AD
SHA256:A7931EE89662C563637E1752228923D182F42F3A70286D4FD0A1FFF993C9766D
8388msiexec.exeC:\Program Files\jjsploit\resources\luascripts\general\infinitejump.luatext
MD5:F13B9AD3F7D7EB0827D189699D50490C
SHA256:E81510EB4EE69A72D9087DEFD412453C0C63D2772CAC3749757B842FB126E435
8388msiexec.exeC:\Program Files\jjsploit\resources\luascripts\animations\levitate.luatext
MD5:D09DA2B730602A59C3289B72E63137BB
SHA256:2AF3980171CC17A4D7687B7489FE8B0BB193E5080C0CA76E5501983A0B3EFADB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
540
TCP/UDP connections
277
DNS requests
279
Threats
21

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
8700
svchost.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
8240
powershell.exe
GET
301
88.221.169.205:443
https://go.microsoft.com/fwlink/p/?LinkId=2124703
US
whitelisted
356
svchost.exe
POST
200
40.126.31.73:443
https://login.live.com/RST2.srf
US
xml
11.1 Kb
whitelisted
8700
svchost.exe
GET
200
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=1&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.70 Kb
whitelisted
356
svchost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
8700
svchost.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
7972
svchost.exe
POST
403
88.221.169.205:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
US
386 b
whitelisted
7972
svchost.exe
POST
403
88.221.169.205:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
US
html
386 b
whitelisted
4020
SIHClient.exe
GET
304
74.178.76.128:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
8700
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8536
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
356
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
356
svchost.exe
23.63.118.230:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
8700
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8700
svchost.exe
2.16.164.72:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 142.250.187.206
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.71
  • 40.126.31.128
  • 40.126.31.131
  • 20.190.159.130
  • 20.190.159.75
  • 40.126.31.129
  • 40.126.31.1
  • 20.190.159.23
  • 20.190.159.131
  • 40.126.31.0
  • 40.126.31.2
  • 20.190.159.68
  • 20.190.159.2
  • 20.190.159.0
whitelisted
ocsp.digicert.com
  • 23.63.118.230
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.120
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.59.18.102
  • 184.30.25.170
  • 88.221.169.152
whitelisted
go.microsoft.com
  • 88.221.169.205
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 199.232.210.172
  • 199.232.214.172
whitelisted
www.bing.com
  • 184.86.251.13
  • 184.86.251.7
  • 184.86.251.14
  • 184.86.251.15
  • 184.86.251.11
  • 184.86.251.10
  • 184.86.251.5
  • 184.86.251.8
  • 184.86.251.9
  • 2.16.241.201
  • 2.16.241.218
  • 2.16.241.205
  • 184.86.251.20
  • 184.86.251.28
  • 184.86.251.27
  • 184.86.251.23
  • 184.86.251.25
  • 184.86.251.19
  • 184.86.251.18
  • 184.86.251.22
  • 184.86.251.21
  • 184.86.251.16
  • 184.86.251.30
  • 184.86.251.4
  • 184.86.251.24
whitelisted

Threats

PID
Process
Class
Message
6768
MoUsoCoreWorker.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
8240
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
8240
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
8240
powershell.exe
Misc activity
ET INFO Request for EXE via Powershell
8240
powershell.exe
Misc activity
ET INFO Packed Executable Download
6084
svchost.exe
Misc activity
ET INFO Packed Executable Download
2096
msedgewebview2.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
2096
msedgewebview2.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
2096
msedgewebview2.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2096
msedgewebview2.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Process
Message
jjsploit.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
jjsploit.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\net.wearedevs directory exists )
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\net.wearedevs\EBWebView directory exists )
msedgewebview2.exe
[0228/071243.984:ERROR:third_party\crashpad\crashpad\util\win\exception_handler_server.cc:529] ConnectNamedPipe: The pipe is being closed. (0xE8)
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\net.wearedevs\EBWebView directory exists )
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\net.wearedevs\EBWebView directory exists )