URL:

https://samfw.com/SamFwToolSetup_v5.4.zip

Full analysis: https://app.any.run/tasks/de281be5-5011-48b3-b397-e52708dd162f
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 06, 2026, 04:52:02
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
evasion
delphi
inno
installer
phishing
loader
Indicators:
MD5:

E03159635DE1156D296770F402B2D204

SHA1:

92C281D6F7CB1854C58488ED659533F31521F0E6

SHA256:

CE373C65752E7BBC267C670DCA97A5BE8403E226363EBFDCE26201A58423B5F4

SSDEEP:

3:N8JtyKG1zpGQ5MV:2LE1zpGQm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Detects Cygwin installation

      • 7za.exe (PID: 4116)
    • Executing a file with an untrusted certificate

      • SamFwTool.exe (PID: 7004)
      • ss_conn_service.exe (PID: 4992)
      • ss_conn_service2.exe (PID: 7972)
    • PHISHING has been detected (SURICATA)

      • msedge.exe (PID: 1612)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SamFwToolSetup.exe (PID: 3664)
      • SamFwToolSetup.tmp (PID: 5204)
      • SamFwToolSetup.exe (PID: 8428)
      • SamFwToolSetup.tmp (PID: 8864)
      • SamFwToolSetup.exe (PID: 824)
      • 7za.exe (PID: 4116)
      • SamFwToolSetup.exe (PID: 3636)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
      • Setup.exe (PID: 1844)
    • Reads the Windows owner or organization settings

      • SamFwToolSetup.tmp (PID: 8864)
      • SamFwToolSetup.tmp (PID: 5204)
    • Drops 7-zip archiver for unpacking

      • SamFwToolSetup.tmp (PID: 5204)
      • 7za.exe (PID: 4116)
    • Drops a system driver (possible attempt to evade defenses)

      • 7za.exe (PID: 4116)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
      • Setup.exe (PID: 1844)
      • drvinst.exe (PID: 12064)
      • drvinst.exe (PID: 12120)
      • drvinst.exe (PID: 12164)
      • drvinst.exe (PID: 12196)
      • drvinst.exe (PID: 12232)
      • drvinst.exe (PID: 1904)
      • drvinst.exe (PID: 12264)
      • drvinst.exe (PID: 10328)
      • drvinst.exe (PID: 10864)
      • drvinst.exe (PID: 11560)
      • drvinst.exe (PID: 9852)
      • drvinst.exe (PID: 11600)
      • drvinst.exe (PID: 11720)
      • drvinst.exe (PID: 10060)
      • drvinst.exe (PID: 10232)
      • drvinst.exe (PID: 11524)
      • drvinst.exe (PID: 10976)
      • drvinst.exe (PID: 10740)
      • drvinst.exe (PID: 10600)
      • drvinst.exe (PID: 11148)
      • drvinst.exe (PID: 11340)
      • drvinst.exe (PID: 11500)
      • drvinst.exe (PID: 11836)
      • drvinst.exe (PID: 10248)
      • drvinst.exe (PID: 11392)
      • drvinst.exe (PID: 10908)
      • drvinst.exe (PID: 10628)
      • drvinst.exe (PID: 11052)
      • drvinst.exe (PID: 11060)
      • drvinst.exe (PID: 11884)
      • drvinst.exe (PID: 11920)
      • drvinst.exe (PID: 6096)
      • drvinst.exe (PID: 6156)
      • drvinst.exe (PID: 2708)
      • drvinst.exe (PID: 7860)
      • drvinst.exe (PID: 12116)
      • drvinst.exe (PID: 12228)
      • drvinst.exe (PID: 12236)
      • drvinst.exe (PID: 12192)
      • drvinst.exe (PID: 12264)
      • drvinst.exe (PID: 1904)
      • drvinst.exe (PID: 11716)
      • drvinst.exe (PID: 7672)
      • drvinst.exe (PID: 10028)
      • drvinst.exe (PID: 6696)
      • drvinst.exe (PID: 10044)
      • drvinst.exe (PID: 9436)
      • drvinst.exe (PID: 11040)
      • drvinst.exe (PID: 11144)
      • drvinst.exe (PID: 12088)
      • drvinst.exe (PID: 12144)
      • drvinst.exe (PID: 12180)
      • drvinst.exe (PID: 12220)
      • drvinst.exe (PID: 12228)
      • drvinst.exe (PID: 8704)
      • drvinst.exe (PID: 9424)
      • drvinst.exe (PID: 10340)
      • drvinst.exe (PID: 9616)
      • drvinst.exe (PID: 7412)
      • drvinst.exe (PID: 11616)
      • drvinst.exe (PID: 4196)
      • drvinst.exe (PID: 4924)
      • drvinst.exe (PID: 10280)
    • The process creates files with name similar to system file names

      • 7za.exe (PID: 4116)
    • Starts CMD.EXE for commands execution

      • SamFwTool.exe (PID: 7004)
    • Uses DRIVERQUERY.EXE to obtain a list of installed device drivers

      • cmd.exe (PID: 3952)
    • Reads Internet Explorer settings

      • SamFwTool.exe (PID: 7004)
    • Checks for external IP

      • svchost.exe (PID: 2292)
    • Executes as Windows Service

      • ss_conn_service.exe (PID: 4992)
      • ss_conn_service2.exe (PID: 7972)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 8688)
    • Create files in a temporary directory

      • SamFwToolSetup.exe (PID: 3664)
      • SamFwToolSetup.exe (PID: 8428)
      • SamFwToolSetup.tmp (PID: 8864)
      • SamFwToolSetup.tmp (PID: 5204)
      • SamFwToolSetup.exe (PID: 824)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
      • SamFwToolSetup.exe (PID: 3636)
      • Setup.exe (PID: 1844)
    • Reads security settings of Internet Explorer

      • SamFwToolSetup.tmp (PID: 1984)
      • WinRAR.exe (PID: 6792)
      • SamFwToolSetup.tmp (PID: 4608)
      • SamFwTool.exe (PID: 7004)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
      • Setup.exe (PID: 1844)
    • Reads the computer name

      • SamFwToolSetup.tmp (PID: 1984)
      • identity_helper.exe (PID: 3988)
      • SamFwToolSetup.tmp (PID: 4608)
      • SamFwToolSetup.tmp (PID: 8864)
      • SamFwToolSetup.tmp (PID: 5204)
      • 7za.exe (PID: 4116)
      • SamFwTool.exe (PID: 7004)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
      • Setup.exe (PID: 5284)
      • Setup.exe (PID: 1844)
      • drvinst.exe (PID: 12064)
      • drvinst.exe (PID: 12120)
      • drvinst.exe (PID: 12196)
      • drvinst.exe (PID: 12164)
      • drvinst.exe (PID: 12232)
      • drvinst.exe (PID: 1904)
      • drvinst.exe (PID: 12264)
      • drvinst.exe (PID: 10328)
      • drvinst.exe (PID: 9852)
      • drvinst.exe (PID: 10864)
      • drvinst.exe (PID: 11560)
      • drvinst.exe (PID: 11600)
      • drvinst.exe (PID: 11720)
      • drvinst.exe (PID: 10976)
      • drvinst.exe (PID: 11524)
      • drvinst.exe (PID: 10060)
      • drvinst.exe (PID: 10232)
      • drvinst.exe (PID: 10740)
      • drvinst.exe (PID: 10600)
      • drvinst.exe (PID: 11148)
      • drvinst.exe (PID: 11340)
      • drvinst.exe (PID: 11500)
      • drvinst.exe (PID: 10248)
      • drvinst.exe (PID: 11836)
      • drvinst.exe (PID: 11392)
      • drvinst.exe (PID: 10628)
      • drvinst.exe (PID: 10908)
      • drvinst.exe (PID: 11052)
      • drvinst.exe (PID: 11060)
      • drvinst.exe (PID: 11920)
      • drvinst.exe (PID: 11884)
      • drvinst.exe (PID: 6096)
      • drvinst.exe (PID: 6156)
      • drvinst.exe (PID: 7860)
      • drvinst.exe (PID: 2708)
      • drvinst.exe (PID: 12116)
      • drvinst.exe (PID: 12128)
      • drvinst.exe (PID: 12192)
      • drvinst.exe (PID: 12228)
      • drvinst.exe (PID: 12236)
      • drvinst.exe (PID: 12264)
      • drvinst.exe (PID: 10328)
      • drvinst.exe (PID: 11716)
      • drvinst.exe (PID: 7672)
      • drvinst.exe (PID: 10028)
      • drvinst.exe (PID: 1904)
      • drvinst.exe (PID: 6696)
      • drvinst.exe (PID: 10044)
      • drvinst.exe (PID: 9436)
      • drvinst.exe (PID: 11144)
      • drvinst.exe (PID: 2996)
      • drvinst.exe (PID: 11040)
      • drvinst.exe (PID: 12088)
      • drvinst.exe (PID: 12144)
      • drvinst.exe (PID: 12180)
      • drvinst.exe (PID: 12220)
      • drvinst.exe (PID: 2424)
      • drvinst.exe (PID: 8704)
      • drvinst.exe (PID: 1352)
      • drvinst.exe (PID: 12228)
      • drvinst.exe (PID: 9424)
      • drvinst.exe (PID: 10340)
      • drvinst.exe (PID: 9616)
      • drvinst.exe (PID: 7412)
      • drvinst.exe (PID: 10856)
      • drvinst.exe (PID: 11616)
      • drvinst.exe (PID: 8228)
      • drvinst.exe (PID: 4924)
      • drvinst.exe (PID: 10280)
      • drvinst.exe (PID: 4196)
      • ss_conn_service.exe (PID: 4992)
      • ss_conn_service2.exe (PID: 7972)
    • Reads Environment values

      • identity_helper.exe (PID: 3988)
    • Checks supported languages

      • SamFwToolSetup.exe (PID: 3636)
      • identity_helper.exe (PID: 3988)
      • SamFwToolSetup.tmp (PID: 4608)
      • SamFwToolSetup.tmp (PID: 1984)
      • SamFwToolSetup.exe (PID: 8428)
      • SamFwToolSetup.tmp (PID: 8864)
      • SamFwToolSetup.tmp (PID: 5204)
      • SamFwToolSetup.exe (PID: 824)
      • 7za.exe (PID: 4116)
      • SamFwTool.exe (PID: 7004)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
      • Setup.exe (PID: 1844)
      • SamFwToolSetup.exe (PID: 3664)
      • Setup.exe (PID: 5284)
      • drvinst.exe (PID: 12164)
      • drvinst.exe (PID: 12064)
      • drvinst.exe (PID: 12120)
      • drvinst.exe (PID: 12232)
      • drvinst.exe (PID: 12196)
      • drvinst.exe (PID: 1904)
      • drvinst.exe (PID: 12264)
      • drvinst.exe (PID: 10328)
      • drvinst.exe (PID: 9852)
      • drvinst.exe (PID: 10864)
      • drvinst.exe (PID: 11600)
      • drvinst.exe (PID: 11720)
      • drvinst.exe (PID: 10060)
      • drvinst.exe (PID: 10232)
      • drvinst.exe (PID: 11524)
      • drvinst.exe (PID: 10976)
      • drvinst.exe (PID: 10740)
      • drvinst.exe (PID: 10600)
      • drvinst.exe (PID: 11148)
      • drvinst.exe (PID: 11340)
      • drvinst.exe (PID: 11500)
      • drvinst.exe (PID: 11836)
      • drvinst.exe (PID: 10248)
      • drvinst.exe (PID: 11392)
      • drvinst.exe (PID: 10628)
      • drvinst.exe (PID: 10908)
      • drvinst.exe (PID: 11052)
      • drvinst.exe (PID: 11884)
      • drvinst.exe (PID: 11560)
      • drvinst.exe (PID: 11060)
      • drvinst.exe (PID: 11920)
      • drvinst.exe (PID: 6096)
      • drvinst.exe (PID: 6156)
      • drvinst.exe (PID: 2708)
      • drvinst.exe (PID: 12116)
      • drvinst.exe (PID: 7860)
      • drvinst.exe (PID: 12228)
      • drvinst.exe (PID: 12128)
      • drvinst.exe (PID: 12192)
      • drvinst.exe (PID: 12264)
      • drvinst.exe (PID: 1904)
      • drvinst.exe (PID: 11716)
      • drvinst.exe (PID: 12236)
      • drvinst.exe (PID: 10328)
      • drvinst.exe (PID: 7672)
      • drvinst.exe (PID: 6696)
      • drvinst.exe (PID: 10028)
      • drvinst.exe (PID: 9436)
      • drvinst.exe (PID: 10044)
      • drvinst.exe (PID: 11040)
      • drvinst.exe (PID: 12088)
      • drvinst.exe (PID: 11144)
      • drvinst.exe (PID: 2996)
      • drvinst.exe (PID: 12180)
      • drvinst.exe (PID: 12220)
      • drvinst.exe (PID: 2424)
      • drvinst.exe (PID: 12228)
      • drvinst.exe (PID: 12144)
      • drvinst.exe (PID: 8704)
      • drvinst.exe (PID: 1352)
      • drvinst.exe (PID: 9424)
      • drvinst.exe (PID: 10340)
      • drvinst.exe (PID: 9616)
      • drvinst.exe (PID: 7412)
      • drvinst.exe (PID: 10856)
      • drvinst.exe (PID: 8228)
      • drvinst.exe (PID: 11616)
      • drvinst.exe (PID: 4924)
      • drvinst.exe (PID: 10280)
      • ss_conn_service.exe (PID: 4992)
      • drvinst.exe (PID: 4196)
      • ss_conn_service2.exe (PID: 7972)
    • Process checks computer location settings

      • SamFwToolSetup.tmp (PID: 1984)
      • SamFwTool.exe (PID: 7004)
      • SamFwToolSetup.tmp (PID: 4608)
    • The sample compiled with english language support

      • SamFwToolSetup.tmp (PID: 5204)
      • 7za.exe (PID: 4116)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
      • Setup.exe (PID: 1844)
      • drvinst.exe (PID: 12064)
      • drvinst.exe (PID: 12120)
      • drvinst.exe (PID: 12164)
      • drvinst.exe (PID: 12196)
      • drvinst.exe (PID: 12232)
      • drvinst.exe (PID: 1904)
      • drvinst.exe (PID: 12264)
      • drvinst.exe (PID: 10328)
      • drvinst.exe (PID: 9852)
      • drvinst.exe (PID: 10864)
      • drvinst.exe (PID: 11560)
      • drvinst.exe (PID: 11600)
      • drvinst.exe (PID: 11720)
      • drvinst.exe (PID: 10060)
      • drvinst.exe (PID: 10232)
      • drvinst.exe (PID: 11524)
      • drvinst.exe (PID: 10976)
      • drvinst.exe (PID: 10740)
      • drvinst.exe (PID: 10600)
      • drvinst.exe (PID: 11148)
      • drvinst.exe (PID: 11340)
      • drvinst.exe (PID: 11500)
      • drvinst.exe (PID: 11836)
      • drvinst.exe (PID: 10248)
      • drvinst.exe (PID: 11392)
      • drvinst.exe (PID: 10628)
      • drvinst.exe (PID: 10908)
      • drvinst.exe (PID: 11060)
      • drvinst.exe (PID: 11052)
      • drvinst.exe (PID: 11884)
      • drvinst.exe (PID: 11920)
      • drvinst.exe (PID: 6096)
      • drvinst.exe (PID: 6156)
      • drvinst.exe (PID: 7860)
      • drvinst.exe (PID: 2708)
      • drvinst.exe (PID: 12116)
      • drvinst.exe (PID: 12192)
      • drvinst.exe (PID: 12228)
      • drvinst.exe (PID: 12236)
      • drvinst.exe (PID: 12264)
      • drvinst.exe (PID: 7672)
      • drvinst.exe (PID: 11716)
      • drvinst.exe (PID: 10028)
      • drvinst.exe (PID: 6696)
      • drvinst.exe (PID: 10044)
      • drvinst.exe (PID: 9436)
      • drvinst.exe (PID: 11040)
      • drvinst.exe (PID: 2996)
      • drvinst.exe (PID: 12088)
      • SamFwTool.exe (PID: 7004)
      • drvinst.exe (PID: 12144)
      • drvinst.exe (PID: 10340)
      • drvinst.exe (PID: 10856)
      • drvinst.exe (PID: 8228)
      • drvinst.exe (PID: 4196)
    • Detects InnoSetup installer (YARA)

      • SamFwToolSetup.exe (PID: 3636)
      • SamFwToolSetup.tmp (PID: 4608)
      • SamFwToolSetup.tmp (PID: 1984)
      • SamFwToolSetup.exe (PID: 3664)
      • SamFwToolSetup.exe (PID: 8428)
      • SamFwToolSetup.tmp (PID: 8864)
    • Compiled with Borland Delphi (YARA)

      • SamFwToolSetup.exe (PID: 3636)
      • SamFwToolSetup.tmp (PID: 4608)
      • SamFwToolSetup.exe (PID: 3664)
      • SamFwToolSetup.tmp (PID: 1984)
      • SamFwToolSetup.exe (PID: 8428)
      • SamFwToolSetup.tmp (PID: 8864)
    • Creates a software uninstall entry

      • SamFwToolSetup.tmp (PID: 5204)
      • Setup.exe (PID: 1844)
    • Creates files in the program directory

      • SamFwToolSetup.tmp (PID: 5204)
      • Setup.exe (PID: 1844)
      • Setup.exe (PID: 5284)
      • ss_conn_service2.exe (PID: 7972)
    • The sample compiled with korean language support

      • 7za.exe (PID: 4116)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
      • Setup.exe (PID: 1844)
    • Checks proxy server information

      • SamFwTool.exe (PID: 7004)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
      • slui.exe (PID: 7972)
    • Reads the machine GUID from the registry

      • SamFwTool.exe (PID: 7004)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
      • drvinst.exe (PID: 12064)
      • drvinst.exe (PID: 12120)
      • drvinst.exe (PID: 12232)
      • drvinst.exe (PID: 1904)
      • drvinst.exe (PID: 12264)
      • drvinst.exe (PID: 10328)
      • drvinst.exe (PID: 9852)
      • drvinst.exe (PID: 10864)
      • drvinst.exe (PID: 11560)
      • drvinst.exe (PID: 11600)
      • drvinst.exe (PID: 11720)
      • drvinst.exe (PID: 10060)
      • drvinst.exe (PID: 10232)
      • drvinst.exe (PID: 10976)
      • drvinst.exe (PID: 11524)
      • drvinst.exe (PID: 10600)
      • drvinst.exe (PID: 10740)
      • drvinst.exe (PID: 11148)
      • drvinst.exe (PID: 12164)
      • drvinst.exe (PID: 11340)
      • drvinst.exe (PID: 10248)
      • drvinst.exe (PID: 11500)
      • drvinst.exe (PID: 11836)
      • drvinst.exe (PID: 11392)
      • drvinst.exe (PID: 10628)
      • drvinst.exe (PID: 10908)
      • drvinst.exe (PID: 11884)
      • drvinst.exe (PID: 11060)
      • drvinst.exe (PID: 11052)
      • drvinst.exe (PID: 11920)
      • drvinst.exe (PID: 6156)
      • drvinst.exe (PID: 6096)
      • drvinst.exe (PID: 7860)
      • drvinst.exe (PID: 2708)
      • drvinst.exe (PID: 12128)
      • drvinst.exe (PID: 12116)
      • drvinst.exe (PID: 12192)
      • drvinst.exe (PID: 12228)
      • drvinst.exe (PID: 12196)
      • drvinst.exe (PID: 12236)
      • drvinst.exe (PID: 12264)
      • drvinst.exe (PID: 1904)
      • drvinst.exe (PID: 10328)
      • drvinst.exe (PID: 11716)
      • drvinst.exe (PID: 7672)
      • drvinst.exe (PID: 10028)
      • drvinst.exe (PID: 10044)
      • drvinst.exe (PID: 6696)
      • drvinst.exe (PID: 9436)
      • drvinst.exe (PID: 11040)
      • drvinst.exe (PID: 11144)
      • drvinst.exe (PID: 2996)
      • drvinst.exe (PID: 12180)
      • drvinst.exe (PID: 12220)
      • drvinst.exe (PID: 12144)
      • drvinst.exe (PID: 12228)
      • drvinst.exe (PID: 2424)
      • drvinst.exe (PID: 8704)
      • drvinst.exe (PID: 1352)
      • drvinst.exe (PID: 10340)
      • drvinst.exe (PID: 9424)
      • drvinst.exe (PID: 7412)
      • drvinst.exe (PID: 10856)
      • drvinst.exe (PID: 9616)
      • drvinst.exe (PID: 8228)
      • drvinst.exe (PID: 11616)
      • drvinst.exe (PID: 4924)
      • drvinst.exe (PID: 4196)
      • drvinst.exe (PID: 10280)
      • ss_conn_service.exe (PID: 4992)
      • ss_conn_service2.exe (PID: 7972)
      • drvinst.exe (PID: 12088)
    • Disables trace logs

      • SamFwTool.exe (PID: 7004)
    • The sample compiled with japanese language support

      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
      • Setup.exe (PID: 1844)
    • There is functionality for taking screenshot (YARA)

      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
    • Creates files or folders in the user directory

      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 6416)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
342
Monitored processes
189
Malicious processes
6
Suspicious processes
3

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=25 --always-read-main-dll --field-trial-handle=7660,i,7396078893222380828,1953490949262603116,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6160 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
824"C:\Users\admin\AppData\Local\Temp\Rar$EXa6792.38046\SamFwToolSetup.exe" /SPAWNWND=$120246 /NOTIFYWND=$1A0338 C:\Users\admin\AppData\Local\Temp\Rar$EXa6792.38046\SamFwToolSetup.exe
SamFwToolSetup.tmp
User:
admin
Company:
SamFw.com
Integrity Level:
HIGH
Description:
SamFw Tool Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6792.38046\samfwtoolsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comctl32.dll
c:\windows\syswow64\advapi32.dll
1000"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=24 --always-read-main-dll --field-trial-handle=6252,i,7396078893222380828,1953490949262603116,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5404 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1068"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=43 --always-read-main-dll --field-trial-handle=9208,i,7396078893222380828,1953490949262603116,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=9136 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1320"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=29 --always-read-main-dll --field-trial-handle=7812,i,7396078893222380828,1953490949262603116,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=4036 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1344"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://bit.ly/samfwtoolC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeSamFwTool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1352DrvInst.exe "4" "28" "C:\Users\admin\AppData\Local\Temp\{6b070288-17d6-d446-ba4c-0ffbd88ae075}\ssudrnds.inf" "9" "494471cbf" "00000000000000EC" "WinSta0\Default" "000000000000023C" "208" "C:\Program Files\Samsung\USB Drivers\25_escape"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1388"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=36 --always-read-main-dll --field-trial-handle=8344,i,7396078893222380828,1953490949262603116,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=8488 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1612"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2240,i,7396078893222380828,1953490949262603116,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=2436 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1840"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=56 --always-read-main-dll --field-trial-handle=9700,i,7396078893222380828,1953490949262603116,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=11172 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
276 018
Read events
275 729
Write events
225
Delete events
64

Modification events

(PID) Process:(6792) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6792) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6792) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(6792) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\SamFwToolSetup_v5.4.zip
(PID) Process:(6792) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6792) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6792) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6792) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(5204) SamFwToolSetup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
541400000161C00625ADDC01
(PID) Process:(5204) SamFwToolSetup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
2AE48E27925262303FEA7E35D9A60AE64C4DCBF2DB82292DF8EF649487003088
Executable files
1 383
Suspicious files
1 356
Text files
398
Unknown types
0

Dropped files

PID
Process
Filename
Type
8688msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1e5225.TMP
MD5:
SHA256:
8688msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1e5225.TMP
MD5:
SHA256:
8688msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1e5225.TMP
MD5:
SHA256:
8688msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
8688msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
8688msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
8688msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1e5235.TMP
MD5:
SHA256:
8688msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
8688msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1e5254.TMP
MD5:
SHA256:
8688msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
252
TCP/UDP connections
448
DNS requests
598
Threats
35

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1612
msedge.exe
GET
304
150.171.28.11:443
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
US
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
959 b
whitelisted
1612
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
US
text
295 b
whitelisted
1612
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:-VGC4g_JT6uLg6GbfjpGrQBffd2ZEuSoIbc3MBT6XVs&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
98 b
whitelisted
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
US
binary
313 b
whitelisted
1612
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=66&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0
US
text
4.55 Kb
whitelisted
1612
msedge.exe
GET
200
104.26.7.93:443
https://samfw.com/SamFwToolSetup_v5.4.zip
US
compressed
46.4 Mb
unknown
1612
msedge.exe
GET
200
104.18.22.222:443
https://copilot.microsoft.com/c/api/user/eligibility
US
text
25 b
whitelisted
1612
msedge.exe
GET
200
13.107.213.44:443
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appId=edge-extensions&country=US
US
binary
82 b
whitelisted
1612
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-US&acceptformat=crx3,puff&x=id%3Djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3D1.2.1%26installedby%3Dother%26uc%26ping%3Dr%253D77%2526e%253D1
US
xml
413 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1324
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
8700
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
92.123.104.32:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
162.159.142.9:80
ocsp.digicert.com
CLOUDFLARENET
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3412
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
1612
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
self.events.data.microsoft.com
  • 52.168.112.66
  • 13.69.239.74
whitelisted
www.bing.com
  • 92.123.104.32
  • 92.123.104.31
  • 92.123.104.59
  • 92.123.104.33
  • 92.123.104.38
  • 92.123.104.34
  • 2.19.122.33
  • 2.19.122.12
  • 2.19.122.30
  • 92.123.104.60
  • 92.123.104.52
  • 92.123.104.19
whitelisted
ocsp.digicert.com
  • 162.159.142.9
  • 172.66.2.5
whitelisted
google.com
  • 172.217.16.206
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
samfw.com
  • 104.26.7.93
  • 104.26.6.93
  • 172.67.70.252
unknown

Threats

PID
Process
Class
Message
1612
msedge.exe
Misc activity
INFO [ANY.RUN] Possible short link service (bit .ly)
2292
svchost.exe
Misc activity
INFO [ANY.RUN] External IP Check (ip-api .com)
1612
msedge.exe
Misc activity
INFO [ANY.RUN] Possible short link service (bit .ly)
2292
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
1612
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
1612
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
1612
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
1612
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
1612
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
1612
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
Process
Message
ss_conn_service2.exe
[CSSVC ][ServiceMain:229 ] ServiceMain Start