| URL: | directsourcing-lab.com | 
| Full analysis: | https://app.any.run/tasks/96abbec1-fe1c-4a1c-8723-a5cbea485ed5 | 
| Verdict: | Malicious activity | 
| Analysis date: | October 05, 2025, 13:25:37 | 
| OS: | Windows 10 Professional (build: 19044, 64 bit) | 
| Tags: | |
| Indicators: | |
| MD5: | 420C7C50006B805481D834FEBC418496 | 
| SHA1: | C642ED0D0C8CB48AE2076139C78857326F269C2C | 
| SHA256: | C8A455968A23BCBAA2323A6718FA4CAD1165D31822DFF99616D0ECD4FE508CC1 | 
| SSDEEP: | 3:gt2cyT:gMtT | 
PID  | CMD  | Path  | Indicators  | Parent process  | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 828 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6948,i,17624941090128338961,8491779693248335734,262144 --variations-seed-version --mojo-platform-channel-handle=5816 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
  | |||||||||||||||
| 1216 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x304,0x308,0x30c,0x2fc,0x314,0x7ffba2e4f208,0x7ffba2e4f214,0x7ffba2e4f220 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
  | |||||||||||||||
| 2120 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2256,i,17624941090128338961,8491779693248335734,262144 --variations-seed-version --mojo-platform-channel-handle=2252 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
  | |||||||||||||||
| 2360 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=6036,i,17624941090128338961,8491779693248335734,262144 --variations-seed-version --mojo-platform-channel-handle=5904 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
  | |||||||||||||||
| 2564 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "directsourcing-lab.com" | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
  | |||||||||||||||
| 3116 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=7136,i,17624941090128338961,8491779693248335734,262144 --variations-seed-version --mojo-platform-channel-handle=5892 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
  | |||||||||||||||
| 6388 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2396,i,17624941090128338961,8491779693248335734,262144 --variations-seed-version --mojo-platform-channel-handle=2276 /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
  | |||||||||||||||
| 6480 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5732,i,17624941090128338961,8491779693248335734,262144 --variations-seed-version --mojo-platform-channel-handle=5896 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
  | |||||||||||||||
| 6480 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=6440,i,17624941090128338961,8491779693248335734,262144 --variations-seed-version --mojo-platform-channel-handle=3068 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
  | |||||||||||||||
| 7244 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3676,i,17624941090128338961,8491779693248335734,262144 --variations-seed-version --mojo-platform-channel-handle=3700 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
  | |||||||||||||||
| (PID) Process: | (2564) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262672 | 
| Operation: | write | Name: | WindowTabManagerFileMappingId | 
Value: {A9373375-8C83-4BAA-A1B5-5D6A9A9FB550}  | |||
| (PID) Process: | (2564) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262672 | 
| Operation: | write | Name: | WindowTabManagerFileMappingId | 
Value: {846C65A9-0052-4F24-A317-EB31548F827E}  | |||
| (PID) Process: | (2564) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon | 
| Operation: | write | Name: | failed_count | 
Value: 0  | |||
| (PID) Process: | (2564) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon | 
| Operation: | write | Name: | state | 
Value: 2  | |||
| (PID) Process: | (2564) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon | 
| Operation: | write | Name: | state | 
Value: 1  | |||
| (PID) Process: | (2564) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics | 
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly | 
Value: 0  | |||
| (PID) Process: | (2564) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault | 
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 | 
Value: BD101A8EFF9E2F00  | |||
| (PID) Process: | (2564) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262672 | 
| Operation: | write | Name: | WindowTabManagerFileMappingId | 
Value: {F8E1D107-F2E5-413D-BDD4-0CE077D965F4}  | |||
| (PID) Process: | (2564) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262672 | 
| Operation: | write | Name: | WindowTabManagerFileMappingId | 
Value: {A532C17E-2FEF-460A-AB68-3C747BB239BC}  | |||
| (PID) Process: | (2564) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262672 | 
| Operation: | write | Name: | WindowTabManagerFileMappingId | 
Value: {AC60A38F-B637-4E49-A315-5FAA308089D6}  | |||
PID  | Process  | Filename  | Type  | |
|---|---|---|---|---|
| 2564 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1711a3.TMP | — | |
MD5:—  | SHA256:—  | |||
| 2564 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:—  | SHA256:—  | |||
| 2564 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1711b3.TMP | — | |
MD5:—  | SHA256:—  | |||
| 2564 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:—  | SHA256:—  | |||
| 2564 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1711b3.TMP | — | |
MD5:—  | SHA256:—  | |||
| 2564 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:—  | SHA256:—  | |||
| 2564 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1711c3.TMP | — | |
MD5:—  | SHA256:—  | |||
| 2564 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:—  | SHA256:—  | |||
| 2564 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1711d2.TMP | — | |
MD5:—  | SHA256:—  | |||
| 2564 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:—  | SHA256:—  | |||
PID  | Process  | Method  | HTTP Code  | IP  | URL  | CN  | Type  | Size  | Reputation  | 
|---|---|---|---|---|---|---|---|---|---|
6388  | msedge.exe  | GET  | 200  | 150.171.27.11:80  | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:AEr4Pi8CR11ApnB02yeLSQvfbYVftd30VNoGtCZ5Jlk&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855  | unknown  |  —   | —  | whitelisted  | 
1852  | svchost.exe  | GET  | 200  | 172.66.2.5:80  | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D  | unknown  |  —   | —  | whitelisted  | 
1852  | svchost.exe  | GET  | 200  | 172.66.2.5:80  | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D  | unknown  |  —   | —  | whitelisted  | 
8964  | backgroundTaskHost.exe  | GET  | 200  | 172.66.2.5:80  | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D  | unknown  |  —   | —  | whitelisted  | 
8912  | backgroundTaskHost.exe  | GET  | 200  | 172.66.2.5:80  | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D  | unknown  |  —   | —  | whitelisted  | 
8940  | backgroundTaskHost.exe  | GET  | 200  | 172.66.2.5:80  | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D  | unknown  |  —   | —  | whitelisted  | 
PID  | Process  | IP  | Domain  | ASN  | CN  | Reputation  | 
|---|---|---|---|---|---|---|
3572  | RUXIMICS.exe  | 51.124.78.146:443  | settings-win.data.microsoft.com  | MICROSOFT-CORP-MSN-AS-BLOCK  | NL  | whitelisted  | 
4  | System  | 192.168.100.255:137  | —  | —  | —  | whitelisted  | 
6016  | MoUsoCoreWorker.exe  | 51.124.78.146:443  | settings-win.data.microsoft.com  | MICROSOFT-CORP-MSN-AS-BLOCK  | NL  | whitelisted  | 
6388  | msedge.exe  | 150.171.27.11:80  | edge.microsoft.com  | MICROSOFT-CORP-MSN-AS-BLOCK  | US  | whitelisted  | 
6388  | msedge.exe  | 150.171.22.17:443  | config.edge.skype.com  | MICROSOFT-CORP-MSN-AS-BLOCK  | US  | whitelisted  | 
6388  | msedge.exe  | 150.171.27.11:443  | edge.microsoft.com  | MICROSOFT-CORP-MSN-AS-BLOCK  | US  | whitelisted  | 
6388  | msedge.exe  | 188.114.97.3:443  | directsourcing-lab.com  | CLOUDFLARENET  | NL  | whitelisted  | 
6388  | msedge.exe  | 104.126.37.169:443  | copilot.microsoft.com  | Akamai International B.V.  | DE  | whitelisted  | 
4  | System  | 192.168.100.255:138  | —  | —  | —  | whitelisted  | 
6388  | msedge.exe  | 2.16.241.218:443  | www.bing.com  | Akamai International B.V.  | DE  | whitelisted  | 
Domain  | IP  | Reputation  | 
|---|---|---|
settings-win.data.microsoft.com  | 
  | whitelisted  | 
google.com  | 
  | whitelisted  | 
edge.microsoft.com  | 
  | whitelisted  | 
config.edge.skype.com  | 
  | whitelisted  | 
directsourcing-lab.com  | 
  | unknown  | 
copilot.microsoft.com  | 
  | whitelisted  | 
www.bing.com  | 
  | whitelisted  | 
fonts.googleapis.com  | 
  | whitelisted  | 
www.googletagmanager.com  | 
  | whitelisted  | 
connect.facebook.net  | 
  | whitelisted  | 
PID  | Process  | Class  | Message  | 
|---|---|---|---|
6388  | msedge.exe  | Not Suspicious Traffic  | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)  | 
6388  | msedge.exe  | Exploit Kit Activity Detected  | ET EXPLOIT_KIT Malicious TA2726 TDS Domain in DNS Lookup (neutralmarlservices .com)  | 
6388  | msedge.exe  | Exploit Kit Activity Detected  | ET EXPLOIT_KIT Malicious TA2726 TDS Domain in DNS Lookup (neutralmarlservices .com)  | 
6388  | msedge.exe  | Exploit Kit Activity Detected  | ET EXPLOIT_KIT Malicious TA2726 TDS Domain in TLS SNI (neutralmarlservices .com)  | 
6388  | msedge.exe  | Exploit Kit Activity Detected  | ET EXPLOIT_KIT Malicious TA2726 TDS Domain in TLS SNI (neutralmarlservices .com)  | 
6388  | msedge.exe  | Domain Observed Used for C2 Detected  | ET MALWARE TA569 Staging Server Domain in DNS Lookup (vps .denissalazar .com)  | 
6388  | msedge.exe  | Domain Observed Used for C2 Detected  | ET MALWARE TA569 Staging Server Domain in DNS Lookup (vps .denissalazar .com)  | 
6388  | msedge.exe  | Domain Observed Used for C2 Detected  | ET MALWARE TA569 Staging Server Domain in TLS SNI (vps .denissalazar .com)  | 
6388  | msedge.exe  | Misc activity  | ET INFO Observed ZeroSSL SSL/TLS Certificate  | 
6388  | msedge.exe  | Exploit Kit Activity Detected  | ET EXPLOIT_KIT Malicious TA2726 TDS Domain in DNS Lookup (neutralmarlservices .com)  |