download:

/download/CuteWriter.exe

Full analysis: https://app.any.run/tasks/98a02c53-94bf-4b57-82fb-f61e62561b80
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 03, 2024, 18:50:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1F8EA936811D89EF72807E013CB0222C

SHA1:

C61DD0874DF7C84CAA0830FDF3846B50E48B5108

SHA256:

C4D1A0317C200E241B76B891F1AD1D03A380A59E0A640AADA62C38418712E43F

SSDEEP:

98304:p4akESMTHQ4GKXPjHyJUmP07yTurVp8onUq96IgnSZxd6iX886l2qFCiNCFCp4jC:S/thyN5nGl6M

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • CuteWriter.exe (PID: 3964)
      • CuteWriter.exe (PID: 1200)
      • CuteWriter.tmp (PID: 928)
      • Setup.exe (PID: 1116)
      • converter.exe (PID: 1764)
      • Setup.exe (PID: 1796)
    • Creates a writable file in the system directory

      • Setup.exe (PID: 1116)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • CuteWriter.exe (PID: 3964)
      • CuteWriter.exe (PID: 1200)
      • CuteWriter.tmp (PID: 928)
      • Setup.exe (PID: 1116)
      • Setup.exe (PID: 1796)
      • converter.exe (PID: 1764)
    • Process drops legitimate windows executable

      • CuteWriter.tmp (PID: 928)
      • Setup.exe (PID: 1116)
    • Reads the Windows owner or organization settings

      • CuteWriter.tmp (PID: 928)
    • Reads the Internet Settings

      • Setup.exe (PID: 1116)
      • CuteWriter.tmp (PID: 928)
    • Process requests binary or script from the Internet

      • Setup.exe (PID: 1116)
    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 1116)
  • INFO

    • Create files in a temporary directory

      • CuteWriter.exe (PID: 3964)
      • CuteWriter.exe (PID: 1200)
      • CuteWriter.tmp (PID: 928)
      • Setup.exe (PID: 1116)
      • converter.exe (PID: 1764)
    • Reads the computer name

      • CuteWriter.tmp (PID: 3980)
      • CuteWriter.tmp (PID: 928)
      • Setup.exe (PID: 1116)
      • wmpnscfg.exe (PID: 2304)
    • Checks supported languages

      • CuteWriter.exe (PID: 3964)
      • CuteWriter.exe (PID: 1200)
      • CuteWriter.tmp (PID: 3980)
      • CuteWriter.tmp (PID: 928)
      • Setup.exe (PID: 1116)
      • converter.exe (PID: 1764)
      • wmpnscfg.exe (PID: 2304)
      • Setup.exe (PID: 1796)
    • Creates files in the program directory

      • CuteWriter.tmp (PID: 928)
      • Setup.exe (PID: 1116)
      • Setup.exe (PID: 1796)
    • Checks proxy server information

      • Setup.exe (PID: 1116)
    • Reads the machine GUID from the registry

      • Setup.exe (PID: 1116)
    • Creates files or folders in the user directory

      • Setup.exe (PID: 1116)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2304)
      • msedge.exe (PID: 2260)
      • msedge.exe (PID: 3916)
    • Application launched itself

      • msedge.exe (PID: 764)
      • msedge.exe (PID: 3916)
      • msedge.exe (PID: 2260)
    • Creates a software uninstall entry

      • Setup.exe (PID: 1116)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 40448
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xa5f8
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.0.1.3
ProductVersionNumber: 4.0.1.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Acro Software Inc.
FileDescription: CutePDF Writer Setup
FileVersion: 4.0.1.3
LegalCopyright: Copyright © 2003-2024 Acro Software Inc.
ProductName: CutePDF Writer
ProductVersion: 4.0.1.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
72
Monitored processes
36
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start cutewriter.exe cutewriter.tmp no specs cutewriter.exe cutewriter.tmp setup.exe wmpnscfg.exe no specs converter.exe msedge.exe no specs msedge.exe no specs setup.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
588"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6e59f598,0x6e59f5a8,0x6e59f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
764"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.cutepdf-editor.com/support/writer.aspC:\Program Files\Microsoft\Edge\Application\msedge.exeCuteWriter.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
928"C:\Users\admin\AppData\Local\Temp\is-U4G8F.tmp\CuteWriter.tmp" /SL5="$4012E,5944588,56832,C:\Users\admin\AppData\Local\Temp\CuteWriter.exe" /SPAWNWND=$20134 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\is-U4G8F.tmp\CuteWriter.tmp
CuteWriter.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-u4g8f.tmp\cutewriter.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
956"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2224 --field-trial-handle=1148,i,7398886593225360215,6571129363474581108,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1008"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1420 --field-trial-handle=1148,i,7398886593225360215,6571129363474581108,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1116"C:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\Setup.exe" /inscpw4 -d"C:\Program Files\CutePDF Writer"C:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\Setup.exe
CuteWriter.tmp
User:
admin
Company:
Acro Software Inc.
Integrity Level:
HIGH
Description:
CutePDF Writer Setup
Exit code:
0
Version:
4, 0, 0, 2
Modules
Images
c:\users\admin\appdata\local\temp\is-rl4fs.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1200"C:\Users\admin\AppData\Local\Temp\CuteWriter.exe" /SPAWNWND=$20134 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\CuteWriter.exe
CuteWriter.tmp
User:
admin
Company:
Acro Software Inc.
Integrity Level:
HIGH
Description:
CutePDF Writer Setup
Exit code:
0
Version:
4.0.1.3
Modules
Images
c:\users\admin\appdata\local\temp\cutewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1244"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1256 --field-trial-handle=1148,i,7398886593225360215,6571129363474581108,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1764C:\Users\admin\AppData\Local\Temp\\converter.exe /autoC:\Users\admin\AppData\Local\Temp\converter.exe
Setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\converter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
1796Setup.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\Setup.exe
converter.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\wzse0.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
Total events
11 085
Read events
10 959
Write events
102
Delete events
24

Modification events

(PID) Process:(928) CuteWriter.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
A0030000942486C18A9DDA01
(PID) Process:(928) CuteWriter.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
7BA0DF43896332CAA605473009D00E68F6E65EEF2E13DEFEFAD6A74FDB3000CA
(PID) Process:(928) CuteWriter.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(928) CuteWriter.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\cpwmon32_v40.dll
(PID) Process:(928) CuteWriter.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
354E7F1273E65AF62FDF706296EAA7CD63124290B83C800FE76BBCE5424C2DE9
(PID) Process:(1116) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Acro Software Inc\CutePDF Writer
Operation:writeName:Port Name
Value:
CPW4:
(PID) Process:(1116) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Acro Software Inc\CutePDF Writer
Operation:writeName:Printer Name
Value:
CutePDF Writer
(PID) Process:(1116) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Acro Software Inc\CutePDF Writer
Operation:writeName:Destination Folder
Value:
C:\Program Files\CutePDF Writer
(PID) Process:(1116) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Acro Software Inc\CutePDF Writer
Operation:writeName:Programmatic Access
Value:
0
(PID) Process:(1116) Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
49
Suspicious files
135
Text files
517
Unknown types
108

Dropped files

PID
Process
Filename
Type
928CuteWriter.tmpC:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\is-Q413C.tmpexecutable
MD5:CB9A520B70BF242E8B41AD4F70D2BF46
SHA256:AE7C73975E6C4DA06DC378D595CC0E71C482705242845FAB0FE3AF34E0DD875E
928CuteWriter.tmpC:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\is-L2FES.tmpxml
MD5:D8385D9758B759942365B1ACC0E414FE
SHA256:278BCF994BFBD8C625E1FCC67610280200908BA984DC6C99DF5EBAF379754491
928CuteWriter.tmpC:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\cpwmon32_v40.dllexecutable
MD5:118B7719D2CCD16BFC258863FD1CCB46
SHA256:C9965E33337D4CE50F40051EA0385F8FE6CB311A2C64DCCF1FECF367C52CE1C2
928CuteWriter.tmpC:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
928CuteWriter.tmpC:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\is-R1K4U.tmpexecutable
MD5:F61F21FEECD660939F51765F31AC7A68
SHA256:BA0102BB46557BB6DDB58482F7F12811DF772110CF9B2482F945F407106A1AC7
928CuteWriter.tmpC:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\CuteEdit.icoimage
MD5:A68EF3A5FC089796C7275B46A3D5AA68
SHA256:B24E29CDC992531DB2213E85F200E2E659EB78B0C91BFF9C657269DF7992B907
928CuteWriter.tmpC:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\is-EI38J.tmpimage
MD5:A68EF3A5FC089796C7275B46A3D5AA68
SHA256:B24E29CDC992531DB2213E85F200E2E659EB78B0C91BFF9C657269DF7992B907
928CuteWriter.tmpC:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\PDFWrite.rsptext
MD5:FEF862EB25DFDC61A328B941960629EE
SHA256:C21B6FC73A4D92EE282C927699B892A8D7207AC1C78475A530C1D1E4264940D6
928CuteWriter.tmpC:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\cpwmon64_v40.dllexecutable
MD5:F61F21FEECD660939F51765F31AC7A68
SHA256:BA0102BB46557BB6DDB58482F7F12811DF772110CF9B2482F945F407106A1AC7
928CuteWriter.tmpC:\Users\admin\AppData\Local\Temp\is-RL4FS.tmp\CPWSave.exe.manifestxml
MD5:D8385D9758B759942365B1ACC0E414FE
SHA256:278BCF994BFBD8C625E1FCC67610280200908BA984DC6C99DF5EBAF379754491
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
53
DNS requests
43
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1116
Setup.exe
GET
302
64.34.201.145:80
http://download.cutepdf.com/download/converter2.asp
unknown
unknown
1116
Setup.exe
GET
200
64.34.201.145:80
http://download.cutepdf.com/download/gplgs.exe
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
1116
Setup.exe
64.34.201.145:80
download.cutepdf.com
COGECO-PEER1
US
unknown
2260
msedge.exe
239.255.255.250:1900
unknown
2356
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2356
msedge.exe
64.34.201.144:443
www.cutepdf-editor.com
COGECO-PEER1
US
unknown
2356
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2356
msedge.exe
172.217.16.200:443
www.googletagmanager.com
GOOGLE
US
whitelisted
2356
msedge.exe
142.250.185.194:443
pagead2.googlesyndication.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
download.cutepdf.com
  • 64.34.201.145
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.cutepdf-editor.com
  • 64.34.201.144
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
www.googletagmanager.com
  • 172.217.16.200
whitelisted
pagead2.googlesyndication.com
  • 142.250.185.194
whitelisted
googleads.g.doubleclick.net
  • 142.250.186.98
whitelisted
region1.google-analytics.com
  • 216.239.32.36
  • 216.239.34.36
whitelisted
www.bing.com
  • 23.222.16.9
  • 23.222.16.42
  • 23.222.16.16
  • 23.222.16.11
  • 23.222.16.34
  • 23.222.16.19
  • 23.222.16.26
  • 23.222.16.73
  • 23.222.16.67
  • 23.222.16.57
  • 23.222.16.40
  • 23.222.16.66
  • 23.222.16.41
  • 23.222.16.49
  • 23.222.16.50
  • 23.222.16.51
  • 23.222.16.59
  • 23.222.16.58
whitelisted
fundingchoicesmessages.google.com
  • 142.250.181.238
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
msedge.exe
[0503/195208.726:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)