URL:

https://filecr.com/windows/avast-premier-antivirus/

Full analysis: https://app.any.run/tasks/d02f1b65-edb9-40bd-a45b-d844f48172bb
Verdict: Malicious activity
Threats:

AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.

Analysis date: November 10, 2024, 18:34:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
xor-url
generic
masslogger
atlantida
stealer
m0yv
dcrat
ims-api
wmi-base64
crypto-regex
susp-powershell
api-base64
mimikatz
tools
growtopia
cobaltstrike
discordgrabber
cryptbot
darkvision
rat
lumma
cve-2022-30190
exploit
sodinokibi
revil
xmrig
asyncrat
pecompact
themida
stealerium
meshagent
antivm
pyinstaller
upx
Indicators:
MD5:

035E8111B08025132CBE7863FE80036E

SHA1:

226820016057B93A5AE5C7B8277E9A39A3DAC6F8

SHA256:

D3D124DB163A7A560D0077615A06E0E66F0594241A6ADBEB58608F6EAB02B9AD

SSDEEP:

3:N8JTCmrRbxAX5LqTWQN:2hFlxA0N

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ATLANTIDA has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • MASSLOGGER has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • M0YV has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • XORed URL has been found (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • DCRAT has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • MIMIKATZ has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • GROWTOPIA has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • CRYPTBOT has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Registers / Runs the DLL via REGSVR32.EXE

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 2660)
    • DISCORDGRABBER has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • COBALTSTRIKE has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • [YARA] DarkVision RAT is detected

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • LUMMA has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • CVE-2022-30190 detected

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • SODINOKIBI has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • XMRIG has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • ASYNCRAT has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • STEALERIUM has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 2660)
      • msert.exe (PID: 2432)
      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 7024)
      • msert.exe (PID: 6512)
      • WinZipSmartMonitorSetup.exe (PID: 7508)
      • WinZip System Utilities Suite.exe (PID: 5328)
    • Process drops legitimate windows executable

      • msert.exe (PID: 6512)
      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 2660)
      • msert.exe (PID: 2432)
    • Application launched itself

      • msert.exe (PID: 6892)
      • msert.exe (PID: 1788)
      • WinZip System Utilities Suite.exe (PID: 5328)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 2660)
      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 7024)
      • WinZipSmartMonitorSetup.exe (PID: 7508)
    • The process drops C-runtime libraries

      • f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe (PID: 2660)
    • Found regular expressions for crypto-addresses (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Possible usage of Discord/Telegram API has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Executes as Windows Service

      • WinZip Smart Monitor Service.exe (PID: 6240)
    • Drops 7-zip archiver for unpacking

      • WinZip System Utilities Suite.exe (PID: 5328)
    • MeshAgent potential remote access (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • There is functionality for VM detection antiVM strings (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Executes application which crashes

      • msert.exe (PID: 6512)
      • msert.exe (PID: 2432)
  • INFO

    • Reads the computer name

      • identity_helper.exe (PID: 6960)
    • Checks supported languages

      • identity_helper.exe (PID: 6960)
    • Application launched itself

      • msedge.exe (PID: 6224)
    • Reads Environment values

      • identity_helper.exe (PID: 6960)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 6224)
      • msedge.exe (PID: 5036)
      • msedge.exe (PID: 7060)
    • Found Base64 encoded reflection usage via PowerShell (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Found Base64 encoded reference to WMI classes (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Found Base64 encoded reference to AntiVirus WMI classes (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Found Base64 encoded network access via PowerShell (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Potential remote process memory writing (Base64 Encoded 'WriteProcessMemory')

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Potential modification of remote process state (Base64 Encoded 'SetThreadContext')

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Found Base64 encoded access to environment variables via PowerShell (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Found Base64 encoded access to Windows Defender via PowerShell (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Potential library load (Base64 Encoded 'LoadLibrary')

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Found Base64 encoded text manipulation via PowerShell (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Potential remote process memory interaction (Base64 Encoded 'VirtualAllocEx')

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Found Base64 encoded file access via PowerShell (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • PECompact has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • Themida protector has been detected

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • PyInstaller has been detected (YARA)

      • msert.exe (PID: 2432)
      • msert.exe (PID: 6512)
    • UPX packer has been detected

      • msert.exe (PID: 2432)
    • Potential remote process memory reading (Base64 Encoded 'ReadProcessMemory')

      • msert.exe (PID: 6512)
      • msert.exe (PID: 2432)
    • Manual execution by a user

      • Taskmgr.exe (PID: 2632)
      • Taskmgr.exe (PID: 2184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

xor-url

(PID) Process(2432) msert.exe
Decrypted-URLs (2)http://creatonprojects.com/drv32.data
http://powermpeg.com/
Decrypted-URLs (1)http://www.pdefender2009.com/buy.php
Decrypted-URLs (1)http://kurs.ru/index)551
Decrypted-URLs (1)http://khamenei.cogia.net/y.phpD
Decrypted-URLs (1)http://www.jjanfile.co.kr/mqqu?**rrr+oodkcli
Decrypted-URLs (1)http://888.843call.cn/adpack.txtF644F
Decrypted-URLs (2)http://34393.cn/xiao.exe%ALLUSERSPROFILE%
http://clicksmile.org/x92s/uc12vx04/xdtldil.php?id=350'1a
Decrypted-URLs (1)http://www.spamcatchero.biz/dl/bot.dll
Decrypted-URLs (1)http://mymetavids.com/drv32.data
Decrypted-URLs (2)http://humbertocosta.quotaless.com/y.txthttp://silvanasz42.googlepages.com/y.txtw
http://silvanasz42.googlepages.com/y.txtw
Decrypted-URLs (1)http://fund.cmc.orli
Decrypted-URLs (1)http://dawateislami.net/html/fonts/taskkill
Decrypted-URLs (1)http://qd.netkill.com.cn/pw.txtfzfo
Decrypted-URLs (1)http://www.sjservicoAtualiza
Decrypted-URLs (1)http://mm.21380.com/t/sleepdown/updatew
(PID) Process(6512) msert.exe
Decrypted-URLs (2)http://creatonprojects.com/drv32.data
http://powermpeg.com/
Decrypted-URLs (1)http://www.pdefender2009.com/buy.php
Decrypted-URLs (1)http://kurs.ru/index)551
Decrypted-URLs (2)http://34393.cn/xiao.exe%ALLUSERSPROFILE%
http://clicksmile.org/x92s/uc12vx04/xdtldil.php?id=350'1a
Decrypted-URLs (1)http://www.jjanfile.co.kr/mqqu?**rrr+oodkcli
Decrypted-URLs (1)http://khamenei.cogia.net/y.phpD
Decrypted-URLs (1)http://888.843call.cn/adpack.txtF644F
Decrypted-URLs (1)http://www.spamcatchero.biz/dl/bot.dll
Decrypted-URLs (1)http://mymetavids.com/drv32.data
Decrypted-URLs (2)http://humbertocosta.quotaless.com/y.txthttp://silvanasz42.googlepages.com/y.txtw
http://silvanasz42.googlepages.com/y.txtw
Decrypted-URLs (1)http://dawateislami.net/html/fonts/taskkill
Decrypted-URLs (1)http://fund.cmc.orli
Decrypted-URLs (1)http://qd.netkill.com.cn/pw.txtfzfo
Decrypted-URLs (1)http://www.sjservicoAtualiza
Decrypted-URLs (1)http://mm.21380.com/t/sleepdown/updatew

ims-api

(PID) Process(2432) msert.exe
Telegram-Tokens (1)5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy
Telegram-Info-Links
5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy
Get info about bothttps://api.telegram.org/bot5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy/getMe
Get incoming updateshttps://api.telegram.org/bot5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy/getUpdates
Get webhookhttps://api.telegram.org/bot5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy
End-Pointa
Args
Discord-Webhook-Tokens (1)899278272179863642/crprqqbwb4570liu_vjmmrd629imskwperk9b88tdmewcdhf8z_iwh1l3amqv5mhppkx
Discord-Info-Links
899278272179863642/crprqqbwb4570liu_vjmmrd629imskwperk9b88tdmewcdhf8z_iwh1l3amqv5mhppkx
Get Webhook Infohttps://discord.com/api/webhooks/899278272179863642/crprqqbwb4570liu_vjmmrd629imskwperk9b88tdmewcdhf8z_iwh1l3amqv5mhppkx
Telegram-Tokens (1)5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo
Telegram-Info-Links
5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo
Get info about bothttps://api.telegram.org/bot5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo/getMe
Get incoming updateshttps://api.telegram.org/bot5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo/getUpdates
Get webhookhttps://api.telegram.org/bot5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo/deleteWebhook?drop_pending_updates=true
Telegram-Tokens (1)2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw
Telegram-Info-Links
2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw
Get info about bothttps://api.telegram.org/bot2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw/getMe
Get incoming updateshttps://api.telegram.org/bot2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw/getUpdates
Get webhookhttps://api.telegram.org/bot2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw
End-PointsendMessage
Args
chat_id (1)-1001777723555
Token2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw
End-PointsendMessage
Args
chat_id (1)-1001777723555
text (1)h
Telegram-Tokens (2)6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo
6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI
Telegram-Info-Links
6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo
Get info about bothttps://api.telegram.org/bot6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo/getMe
Get incoming updateshttps://api.telegram.org/bot6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo/getUpdates
Get webhookhttps://api.telegram.org/bot6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo/deleteWebhook?drop_pending_updates=true
6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI
Get info about bothttps://api.telegram.org/bot6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI/getMe
Get incoming updateshttps://api.telegram.org/bot6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI/getUpdates
Get webhookhttps://api.telegram.org/bot6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo
End-Pointsendmessage
Args
Token6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI
End-PointsendMessage
Args
Discord-Webhook-Tokens (1)1109437421331943467/r3lngrry37ry5cone7dwkukqiz2nnr9ecz8et5wqcowerj32bqhbz9w3otdsefgqcwep
Discord-Info-Links
1109437421331943467/r3lngrry37ry5cone7dwkukqiz2nnr9ecz8et5wqcowerj32bqhbz9w3otdsefgqcwep
Get Webhook Infohttps://discord.com/api/webhooks/1109437421331943467/r3lngrry37ry5cone7dwkukqiz2nnr9ecz8et5wqcowerj32bqhbz9w3otdsefgqcwep
Telegram-Tokens (1)6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu
Telegram-Info-Links
6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu
Get info about bothttps://api.telegram.org/bot6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu/getMe
Get incoming updateshttps://api.telegram.org/bot6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu/getUpdates
Get webhookhttps://api.telegram.org/bot6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu
End-Pointsendmessage
Args
chat_id (1)6481270908
text (1)","get","open","send"]
Telegram-Tokens (1)7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c
Telegram-Info-Links
7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c
Get info about bothttps://api.telegram.org/bot7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c/getMe
Get incoming updateshttps://api.telegram.org/bot7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c/getUpdates
Get webhookhttps://api.telegram.org/bot7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c
End-Pointsendmessage
Args
Telegram-Tokens (1)7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade
Telegram-Info-Links
7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade
Get info about bothttps://api.telegram.org/bot7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade/getMe
Get incoming updateshttps://api.telegram.org/bot7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade/getUpdates
Get webhookhttps://api.telegram.org/bot7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade
End-Pointsendmessage
Args
chat_id (1)6481270908
text (1)","get","open","send"];
Telegram-Tokens (1)6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a
Telegram-Info-Links
6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a
Get info about bothttps://api.telegram.org/bot6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a/getMe
Get incoming updateshttps://api.telegram.org/bot6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a/getUpdates
Get webhookhttps://api.telegram.org/bot6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a
End-Pointsendmessage
Args
chat_id (1)6643273432
text (1)new-result=>new:bynbf:=${message}`,{method:"get"}).then(success=>{},error=>{alert('messagenotsent')console.log(error)})document.getelementbyid("password").value="";console.log("yesssss")
Discord-Webhook-Tokens (1)1204220382094168145/anpobLsMQf9X7wjCwVR3wiFeqzMNRHXz07QubMDY6LjhZSG7apvQUUOf5T3_Z0iCvhxF
Discord-Info-Links
1204220382094168145/anpobLsMQf9X7wjCwVR3wiFeqzMNRHXz07QubMDY6LjhZSG7apvQUUOf5T3_Z0iCvhxF
Get Webhook Infohttps://discord.com/api/webhooks/1204220382094168145/anpobLsMQf9X7wjCwVR3wiFeqzMNRHXz07QubMDY6LjhZSG7apvQUUOf5T3_Z0iCvhxF
Telegram-Tokens (2)6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0
6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk
Telegram-Info-Links
6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0
Get info about bothttps://api.telegram.org/bot6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0/getMe
Get incoming updateshttps://api.telegram.org/bot6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0/getUpdates
Get webhookhttps://api.telegram.org/bot6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0/deleteWebhook?drop_pending_updates=true
6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk
Get info about bothttps://api.telegram.org/bot6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk/getMe
Get incoming updateshttps://api.telegram.org/bot6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk/getUpdates
Get webhookhttps://api.telegram.org/bot6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk
End-Pointsendmessage
Args
chat_id (1)-1002016417277
text (1)new login mail :
Token6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0
End-Pointsendmessage
Args
chat_id (1)-1002016417277
text (1)new login mail :
Telegram-Tokens (1)7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84
Telegram-Info-Links
7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84
Get info about bothttps://api.telegram.org/bot7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84/getMe
Get incoming updateshttps://api.telegram.org/bot7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84/getUpdates
Get webhookhttps://api.telegram.org/bot7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84
End-Pointsendmessage
Args
Discord-Webhook-Tokens (1)850115118066040833/lcFHGcD2eUjv1zEJO_Ped6EAVU7W44L8X3chfyx9YoIb7YBSdo1mqFBIdTWM-GMztfzq
Discord-Info-Links
850115118066040833/lcFHGcD2eUjv1zEJO_Ped6EAVU7W44L8X3chfyx9YoIb7YBSdo1mqFBIdTWM-GMztfzq
Get Webhook Infohttps://discord.com/api/webhooks/850115118066040833/lcFHGcD2eUjv1zEJO_Ped6EAVU7W44L8X3chfyx9YoIb7YBSdo1mqFBIdTWM-GMztfzq
Discord-Webhook-Tokens (1)770716126988599316/o7gxyebupqzx7rqfud4ctopmq2ggicypomynpfvqsib9qyvw2bgz4mmt6c7jvgedo5y6
Discord-Info-Links
770716126988599316/o7gxyebupqzx7rqfud4ctopmq2ggicypomynpfvqsib9qyvw2bgz4mmt6c7jvgedo5y6
Get Webhook Infohttps://discord.com/api/webhooks/770716126988599316/o7gxyebupqzx7rqfud4ctopmq2ggicypomynpfvqsib9qyvw2bgz4mmt6c7jvgedo5y6
Discord-Webhook-Tokens (1)757994001767989269/f3KGimlvr5nZDHyIVt3GF4iEkqvy-je8zsM6MPhPc54x0caWiSJudDLY4XhpV64IEvFz
Discord-Info-Links
757994001767989269/f3KGimlvr5nZDHyIVt3GF4iEkqvy-je8zsM6MPhPc54x0caWiSJudDLY4XhpV64IEvFz
Get Webhook Infohttps://discord.com/api/webhooks/757994001767989269/f3KGimlvr5nZDHyIVt3GF4iEkqvy-je8zsM6MPhPc54x0caWiSJudDLY4XhpV64IEvFz
(PID) Process(6512) msert.exe
Telegram-Tokens (1)5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy
Telegram-Info-Links
5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy
Get info about bothttps://api.telegram.org/bot5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy/getMe
Get incoming updateshttps://api.telegram.org/bot5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy/getUpdates
Get webhookhttps://api.telegram.org/bot5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token5083760279:aahdfrhveb72fisr6bmz4jqzjmspqigzyxy
End-Pointa
Args
Telegram-Tokens (1)5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo
Telegram-Info-Links
5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo
Get info about bothttps://api.telegram.org/bot5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo/getMe
Get incoming updateshttps://api.telegram.org/bot5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo/getUpdates
Get webhookhttps://api.telegram.org/bot5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot5080947553:aafy7o6u7eynp2csvzgi5zrrbthtlc1deqo/deleteWebhook?drop_pending_updates=true
Discord-Webhook-Tokens (1)899278272179863642/crprqqbwb4570liu_vjmmrd629imskwperk9b88tdmewcdhf8z_iwh1l3amqv5mhppkx
Discord-Info-Links
899278272179863642/crprqqbwb4570liu_vjmmrd629imskwperk9b88tdmewcdhf8z_iwh1l3amqv5mhppkx
Get Webhook Infohttps://discord.com/api/webhooks/899278272179863642/crprqqbwb4570liu_vjmmrd629imskwperk9b88tdmewcdhf8z_iwh1l3amqv5mhppkx
Telegram-Tokens (1)2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw
Telegram-Info-Links
2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw
Get info about bothttps://api.telegram.org/bot2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw/getMe
Get incoming updateshttps://api.telegram.org/bot2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw/getUpdates
Get webhookhttps://api.telegram.org/bot2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw
End-PointsendMessage
Args
chat_id (1)-1001777723555
Token2112414722:AAGuX-HNbrmTUBCQ_UXlO4o-fJHerni8xUw
End-PointsendMessage
Args
chat_id (1)-1001777723555
text (1)h
Telegram-Tokens (2)6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo
6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI
Telegram-Info-Links
6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo
Get info about bothttps://api.telegram.org/bot6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo/getMe
Get incoming updateshttps://api.telegram.org/bot6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo/getUpdates
Get webhookhttps://api.telegram.org/bot6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo/deleteWebhook?drop_pending_updates=true
6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI
Get info about bothttps://api.telegram.org/bot6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI/getMe
Get incoming updateshttps://api.telegram.org/bot6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI/getUpdates
Get webhookhttps://api.telegram.org/bot6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token6766432184:aah7svaewk_j9o2o2mibghbgw_g77gx8meo
End-Pointsendmessage
Args
Token6115740549:AAGbdtUe6dYkRqVTUBXwsUf8JMRY8cAMiNI
End-PointsendMessage
Args
Telegram-Tokens (1)7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade
Telegram-Info-Links
7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade
Get info about bothttps://api.telegram.org/bot7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade/getMe
Get incoming updateshttps://api.telegram.org/bot7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade/getUpdates
Get webhookhttps://api.telegram.org/bot7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token7265715971:aaemubcxbzbsrfahqpw65ub-4tgxiaaeade
End-Pointsendmessage
Args
chat_id (1)6481270908
text (1)","get","open","send"];
Telegram-Tokens (1)6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu
Telegram-Info-Links
6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu
Get info about bothttps://api.telegram.org/bot6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu/getMe
Get incoming updateshttps://api.telegram.org/bot6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu/getUpdates
Get webhookhttps://api.telegram.org/bot6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token6989057172:aaflrv_iwsmb1-cc64puz7ki_jyka8br2fu
End-Pointsendmessage
Args
chat_id (1)6481270908
text (1)","get","open","send"]
Telegram-Tokens (1)6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a
Telegram-Info-Links
6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a
Get info about bothttps://api.telegram.org/bot6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a/getMe
Get incoming updateshttps://api.telegram.org/bot6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a/getUpdates
Get webhookhttps://api.telegram.org/bot6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token6616481542:aafhufvwi5drycosjpc1fsfif_lbtu2pu7a
End-Pointsendmessage
Args
chat_id (1)6643273432
text (1)new-result=>new:bynbf:=${message}`,{method:"get"}).then(success=>{},error=>{alert('messagenotsent')console.log(error)})document.getelementbyid("password").value="";console.log("yesssss")
Discord-Webhook-Tokens (1)1109437421331943467/r3lngrry37ry5cone7dwkukqiz2nnr9ecz8et5wqcowerj32bqhbz9w3otdsefgqcwep
Discord-Info-Links
1109437421331943467/r3lngrry37ry5cone7dwkukqiz2nnr9ecz8et5wqcowerj32bqhbz9w3otdsefgqcwep
Get Webhook Infohttps://discord.com/api/webhooks/1109437421331943467/r3lngrry37ry5cone7dwkukqiz2nnr9ecz8et5wqcowerj32bqhbz9w3otdsefgqcwep
Telegram-Tokens (1)7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c
Telegram-Info-Links
7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c
Get info about bothttps://api.telegram.org/bot7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c/getMe
Get incoming updateshttps://api.telegram.org/bot7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c/getUpdates
Get webhookhttps://api.telegram.org/bot7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token7556593612:aafzgxqyc6jokyixx7z8pjv41kml1f3sa_c
End-Pointsendmessage
Args
Telegram-Tokens (2)6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0
6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk
Telegram-Info-Links
6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0
Get info about bothttps://api.telegram.org/bot6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0/getMe
Get incoming updateshttps://api.telegram.org/bot6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0/getUpdates
Get webhookhttps://api.telegram.org/bot6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0/deleteWebhook?drop_pending_updates=true
6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk
Get info about bothttps://api.telegram.org/bot6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk/getMe
Get incoming updateshttps://api.telegram.org/bot6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk/getUpdates
Get webhookhttps://api.telegram.org/bot6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token6546628146:aafglumvq7bsshweuibsmvn6vtfpb2ig8vk
End-Pointsendmessage
Args
chat_id (1)-1002016417277
text (1)new login mail :
Token6546628146:aahecfmffgbbhfhukxj3p-4d9ip_zqm2ed0
End-Pointsendmessage
Args
chat_id (1)-1002016417277
text (1)new login mail :
Discord-Webhook-Tokens (1)1204220382094168145/anpobLsMQf9X7wjCwVR3wiFeqzMNRHXz07QubMDY6LjhZSG7apvQUUOf5T3_Z0iCvhxF
Discord-Info-Links
1204220382094168145/anpobLsMQf9X7wjCwVR3wiFeqzMNRHXz07QubMDY6LjhZSG7apvQUUOf5T3_Z0iCvhxF
Get Webhook Infohttps://discord.com/api/webhooks/1204220382094168145/anpobLsMQf9X7wjCwVR3wiFeqzMNRHXz07QubMDY6LjhZSG7apvQUUOf5T3_Z0iCvhxF
Telegram-Tokens (1)7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84
Telegram-Info-Links
7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84
Get info about bothttps://api.telegram.org/bot7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84/getMe
Get incoming updateshttps://api.telegram.org/bot7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84/getUpdates
Get webhookhttps://api.telegram.org/bot7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token7210144457:aagj5wkql0ko43ahs6h8no0s50gpvqghp84
End-Pointsendmessage
Args
Discord-Webhook-Tokens (1)850115118066040833/lcFHGcD2eUjv1zEJO_Ped6EAVU7W44L8X3chfyx9YoIb7YBSdo1mqFBIdTWM-GMztfzq
Discord-Info-Links
850115118066040833/lcFHGcD2eUjv1zEJO_Ped6EAVU7W44L8X3chfyx9YoIb7YBSdo1mqFBIdTWM-GMztfzq
Get Webhook Infohttps://discord.com/api/webhooks/850115118066040833/lcFHGcD2eUjv1zEJO_Ped6EAVU7W44L8X3chfyx9YoIb7YBSdo1mqFBIdTWM-GMztfzq
Discord-Webhook-Tokens (1)757994001767989269/f3KGimlvr5nZDHyIVt3GF4iEkqvy-je8zsM6MPhPc54x0caWiSJudDLY4XhpV64IEvFz
Discord-Info-Links
757994001767989269/f3KGimlvr5nZDHyIVt3GF4iEkqvy-je8zsM6MPhPc54x0caWiSJudDLY4XhpV64IEvFz
Get Webhook Infohttps://discord.com/api/webhooks/757994001767989269/f3KGimlvr5nZDHyIVt3GF4iEkqvy-je8zsM6MPhPc54x0caWiSJudDLY4XhpV64IEvFz
Discord-Webhook-Tokens (1)770716126988599316/o7gxyebupqzx7rqfud4ctopmq2ggicypomynpfvqsib9qyvw2bgz4mmt6c7jvgedo5y6
Discord-Info-Links
770716126988599316/o7gxyebupqzx7rqfud4ctopmq2ggicypomynpfvqsib9qyvw2bgz4mmt6c7jvgedo5y6
Get Webhook Infohttps://discord.com/api/webhooks/770716126988599316/o7gxyebupqzx7rqfud4ctopmq2ggicypomynpfvqsib9qyvw2bgz4mmt6c7jvgedo5y6
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
258
Monitored processes
113
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msert.exe no specs msedge.exe no specs #XOR-URL msert.exe wzsus53.exe no specs wzsus53.exe f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe wzsus53.exe no specs wzsus53.exe f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe msert.exe no specs #XOR-URL msert.exe msedge.exe no specs winzip system utilities suite.exe winzip system utilities suite.exe winzip system utilities suite.exe no specs winzip system utilities suite.exe no specs winzip system utilities suite.exe no specs regsvr32.exe no specs regsvr32.exe no specs winzipsmartmonitorsetup.exe settings.exe msedge.exe no specs winzip smart monitor service.exe no specs winzipsmartmonitor.exe no specs sc.exe no specs conhost.exe no specs winzip smart monitor service.exe winzip system utilities suite.exe no specs settings.exe no specs winzip system utilities suite.exe winzip system utilities suite.exe no specs settings.exe no specs unsecapp.exe no specs winzip system utilities suite.exe no specs settings.exe no specs msedge.exe no specs msedge.exe no specs winzip system utilities suite.exe no specs settings.exe no specs msedge.exe no specs msedge.exe no specs settings.exe no specs msedge.exe no specs werfault.exe no specs msedge.exe no specs winzipsmartmonitor.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs werfault.exe no specs msedge.exe no specs taskmgr.exe no specs taskmgr.exe msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
612"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=68 --mojo-platform-channel-handle=8884 --field-trial-handle=2356,i,8474953240568503347,7893092566372519418,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
848"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6672 --field-trial-handle=2356,i,8474953240568503347,7893092566372519418,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
1180"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=6640 --field-trial-handle=2356,i,8474953240568503347,7893092566372519418,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1372"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7212 --field-trial-handle=2356,i,8474953240568503347,7893092566372519418,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1376"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --no-appcompat-clear --mojo-platform-channel-handle=7072 --field-trial-handle=2356,i,8474953240568503347,7893092566372519418,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1440"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\WinZip System Utilities Suite\windowscontextmenuhandler-vc141-mt.dll"C:\Windows\SysWOW64\regsvr32.exef4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1452C:\WINDOWS\system32\WerFault.exe -u -p 6512 -s 1928C:\Windows\System32\WerFault.exemsert.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
1500"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=8172 --field-trial-handle=2356,i,8474953240568503347,7893092566372519418,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1568"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=45 --mojo-platform-channel-handle=7312 --field-trial-handle=2356,i,8474953240568503347,7893092566372519418,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1572"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6580 --field-trial-handle=2356,i,8474953240568503347,7893092566372519418,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
88 877
Read events
88 762
Write events
114
Delete events
1

Modification events

(PID) Process:(6224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6224) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
E83DC28429852F00
(PID) Process:(6224) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
3FFDDB8429852F00
(PID) Process:(6224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262744
Operation:writeName:WindowTabManagerFileMappingId
Value:
{E4BC60B3-E5A2-4CD6-9647-87BA97B926DA}
(PID) Process:(6224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262744
Operation:writeName:WindowTabManagerFileMappingId
Value:
{B06937FD-B825-4B33-B4D8-D1EF1700C198}
(PID) Process:(6224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262744
Operation:writeName:WindowTabManagerFileMappingId
Value:
{2223805A-014D-451A-AD40-06554B77CE45}
(PID) Process:(6224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262744
Operation:writeName:WindowTabManagerFileMappingId
Value:
{D2111D30-9D35-4195-993A-9F8BC90B936D}
Executable files
156
Suspicious files
740
Text files
586
Unknown types
1

Dropped files

PID
Process
Filename
Type
6224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF8afff.TMP
MD5:
SHA256:
6224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF8afff.TMP
MD5:
SHA256:
6224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF8afff.TMP
MD5:
SHA256:
6224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF8b00f.TMP
MD5:
SHA256:
6224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
6224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF8b00f.TMP
MD5:
SHA256:
6224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
78
TCP/UDP connections
293
DNS requests
272
Threats
18

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7036
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6944
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7036
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
624
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6944
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7872
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
528
svchost.exe
HEAD
200
23.50.131.24:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/fb6dd03b-99d7-4cc8-a878-91c8e655c2d3?P1=1731862803&P2=404&P3=2&P4=Wq4RzQlnHYPgDAW9N3LxMhFtDBrd6zD2seLuLhk3yfJ8ybYQb6bJZ6C7kleX5L2RqrtYwTveMZYxN5yiF1%2b%2fJQ%3d%3d
unknown
whitelisted
528
svchost.exe
GET
206
23.50.131.24:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/fb6dd03b-99d7-4cc8-a878-91c8e655c2d3?P1=1731862803&P2=404&P3=2&P4=Wq4RzQlnHYPgDAW9N3LxMhFtDBrd6zD2seLuLhk3yfJ8ybYQb6bJZ6C7kleX5L2RqrtYwTveMZYxN5yiF1%2b%2fJQ%3d%3d
unknown
whitelisted
528
svchost.exe
GET
206
23.50.131.24:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/fb6dd03b-99d7-4cc8-a878-91c8e655c2d3?P1=1731862803&P2=404&P3=2&P4=Wq4RzQlnHYPgDAW9N3LxMhFtDBrd6zD2seLuLhk3yfJ8ybYQb6bJZ6C7kleX5L2RqrtYwTveMZYxN5yiF1%2b%2fJQ%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5640
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4360
SearchApp.exe
2.23.209.179:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6224
msedge.exe
239.255.255.250:1900
whitelisted
5036
msedge.exe
188.114.96.3:443
filecr.com
unknown
5036
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
  • 4.231.128.59
  • 51.124.78.146
whitelisted
www.bing.com
  • 2.23.209.179
  • 2.23.209.189
  • 2.23.209.133
  • 2.23.209.149
  • 2.23.209.130
  • 2.23.209.187
  • 2.23.209.182
  • 92.123.104.27
  • 92.123.104.26
  • 92.123.104.43
  • 92.123.104.38
  • 92.123.104.36
  • 92.123.104.32
  • 92.123.104.33
  • 92.123.104.30
  • 92.123.104.44
  • 2.23.209.185
  • 2.23.209.140
  • 92.123.104.28
  • 92.123.104.17
  • 92.123.104.11
  • 92.123.104.10
  • 92.123.104.19
  • 92.123.104.31
  • 92.123.104.14
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.186.110
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.45
whitelisted
filecr.com
  • 188.114.96.3
  • 188.114.97.3
unknown
business.bing.com
  • 13.107.6.158
whitelisted
bzib.nelreports.net
  • 2.19.126.152
  • 2.19.126.145
  • 23.50.131.30
  • 23.50.131.21
whitelisted

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
No debug info