URL:

google.com

Full analysis: https://app.any.run/tasks/1208f173-4a56-4f5c-9b52-40b6a17a078f
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 25, 2025, 01:11:52
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
autorun-download
opera
tool
Indicators:
MD5:

1D5920F4B44B27A802BD77C4F0536F5A

SHA1:

BAEA954B95731C68AE6E45BD1E252EB4560CDC45

SHA256:

D4C9D9027326271A89CE51FCAF328ED673F17BE33469FF979E8AB8DD501E664F

SSDEEP:

3:duK:IK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • setup.exe (PID: 7196)
      • setup.exe (PID: 8608)
      • setup.exe (PID: 9176)
      • setup.exe (PID: 9160)
      • assistant_installer.exe (PID: 8808)
      • assistant_installer.exe (PID: 8288)
      • installer.exe (PID: 8600)
      • installer.exe (PID: 8876)
      • assistant_installer.exe (PID: 9332)
      • assistant_installer.exe (PID: 9244)
      • assistant_installer.exe (PID: 9552)
      • assistant_installer.exe (PID: 9516)
      • opera_crashreporter.exe (PID: 9808)
      • opera_crashreporter.exe (PID: 9800)
      • opera.exe (PID: 9660)
      • opera.exe (PID: 9688)
      • opera_crashreporter.exe (PID: 10080)
      • opera.exe (PID: 10172)
      • opera_crashreporter.exe (PID: 1280)
      • opera.exe (PID: 10000)
      • opera.exe (PID: 9320)
      • browser_assistant.exe (PID: 9964)
      • opera_crashreporter.exe (PID: 9788)
      • opera.exe (PID: 9392)
      • opera_crashreporter.exe (PID: 9592)
      • opera_crashreporter.exe (PID: 9248)
      • browser_assistant.exe (PID: 9604)
      • opera.exe (PID: 10172)
      • opera.exe (PID: 9864)
      • opera.exe (PID: 10200)
      • opera_autoupdate.exe (PID: 3300)
      • opera_autoupdate.exe (PID: 10304)
      • opera_autoupdate.exe (PID: 7312)
      • opera_autoupdate.exe (PID: 5812)
      • installer.exe (PID: 1600)
      • installer.exe (PID: 8452)
    • Actions looks like stealing of personal data

      • setup.exe (PID: 7196)
      • setup.exe (PID: 8608)
      • setup.exe (PID: 9160)
      • setup.exe (PID: 9176)
      • assistant_installer.exe (PID: 8808)
      • assistant_installer.exe (PID: 8288)
      • installer.exe (PID: 8600)
      • installer.exe (PID: 8876)
      • assistant_installer.exe (PID: 9244)
      • assistant_installer.exe (PID: 9332)
      • assistant_installer.exe (PID: 9516)
      • assistant_installer.exe (PID: 9552)
      • opera_crashreporter.exe (PID: 9808)
      • opera_crashreporter.exe (PID: 9800)
      • opera.exe (PID: 9688)
      • opera.exe (PID: 9660)
      • opera.exe (PID: 10000)
      • opera.exe (PID: 10064)
      • opera.exe (PID: 10072)
      • opera.exe (PID: 10172)
      • opera_crashreporter.exe (PID: 1280)
      • opera_crashreporter.exe (PID: 10080)
      • opera.exe (PID: 9320)
      • opera_crashreporter.exe (PID: 9592)
      • opera_crashreporter.exe (PID: 9788)
      • browser_assistant.exe (PID: 9964)
      • opera.exe (PID: 9392)
      • opera.exe (PID: 9652)
      • opera_crashreporter.exe (PID: 9248)
      • opera.exe (PID: 10172)
      • browser_assistant.exe (PID: 9604)
      • opera.exe (PID: 9824)
      • opera.exe (PID: 7440)
      • opera.exe (PID: 9204)
      • opera.exe (PID: 9868)
      • opera.exe (PID: 8156)
      • opera.exe (PID: 10092)
      • opera.exe (PID: 9540)
      • opera.exe (PID: 9864)
      • opera.exe (PID: 7724)
      • opera.exe (PID: 10020)
      • opera.exe (PID: 11104)
      • opera.exe (PID: 4428)
      • opera.exe (PID: 11128)
      • opera.exe (PID: 5392)
      • opera.exe (PID: 10200)
      • opera.exe (PID: 11112)
      • opera.exe (PID: 7308)
      • opera.exe (PID: 7284)
      • opera.exe (PID: 4380)
      • opera.exe (PID: 4728)
      • opera.exe (PID: 9080)
      • opera.exe (PID: 3124)
      • opera.exe (PID: 10500)
      • opera.exe (PID: 10492)
      • opera.exe (PID: 10516)
      • opera.exe (PID: 8256)
      • opera.exe (PID: 6940)
      • opera.exe (PID: 3784)
      • opera.exe (PID: 10496)
      • opera.exe (PID: 10476)
      • opera.exe (PID: 8824)
      • opera.exe (PID: 5172)
      • opera.exe (PID: 10524)
      • opera.exe (PID: 10288)
      • opera.exe (PID: 10376)
      • opera.exe (PID: 10192)
      • opera.exe (PID: 8508)
      • opera.exe (PID: 10520)
      • opera_autoupdate.exe (PID: 3300)
      • opera_autoupdate.exe (PID: 7312)
      • opera.exe (PID: 6760)
      • installer.exe (PID: 1600)
      • opera_autoupdate.exe (PID: 10304)
      • installer.exe (PID: 8452)
      • opera_autoupdate.exe (PID: 5812)
      • opera.exe (PID: 8224)
      • opera.exe (PID: 9816)
      • opera.exe (PID: 5344)
      • opera.exe (PID: 5596)
      • opera.exe (PID: 1184)
      • opera.exe (PID: 5044)
      • opera.exe (PID: 11120)
      • opera.exe (PID: 2356)
      • opera.exe (PID: 7928)
      • opera.exe (PID: 10748)
      • opera.exe (PID: 5964)
      • opera.exe (PID: 11584)
      • opera.exe (PID: 9572)
      • opera.exe (PID: 5408)
      • opera.exe (PID: 11924)
    • Executing a file with an untrusted certificate

      • TG_PCOptimizer.exe (PID: 8304)
      • TG_PCOptimizer.exe (PID: 7928)
      • TG_PCOptimizer.exe (PID: 8832)
      • TG_PCOptimizer.exe (PID: 9056)
      • TG_PCOptimizer.exe (PID: 8676)
      • TG_PCOptimizer.exe (PID: 8488)
      • TG_PCOptimizer.exe (PID: 7192)
      • TG_PCOptimizer.exe (PID: 8888)
      • TechGenie.exe (PID: 232)
      • WMOSetup_4.2.2.128.exe (PID: 11740)
      • WMOSetup_4.2.2.128.exe (PID: 11840)
      • WiseMemoryOptimzer.exe (PID: 12244)
      • WiseMemoryOptimzer.exe (PID: 12136)
    • Detects Cygwin installation

      • TG_PCOptimizer.exe (PID: 8488)
    • Changes the autorun value in the registry

      • assistant_installer.exe (PID: 9244)
      • opera.exe (PID: 9688)
      • opera.exe (PID: 10172)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OperaSetup.exe (PID: 2092)
      • setup.exe (PID: 7196)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 8608)
      • setup.exe (PID: 9160)
      • setup.exe (PID: 9176)
      • Assistant_117.0.5408.35_Setup.exe_sfx.exe (PID: 8968)
      • TG_PCOptimizer.exe (PID: 8488)
      • TG_PCOptimizer.exe (PID: 8676)
      • installer.exe (PID: 8876)
      • installer.exe (PID: 8600)
      • Dism.exe (PID: 8400)
      • Dism.exe (PID: 5640)
      • assistant_installer.exe (PID: 9244)
      • installer.exe (PID: 1600)
      • installer.exe (PID: 8452)
      • opera_autoupdate.exe (PID: 7312)
      • installer.exe (PID: 11036)
      • opera.exe (PID: 5408)
      • WMOSetup_4.2.2.128.exe (PID: 11740)
      • WMOSetup_4.2.2.128.exe (PID: 11840)
      • WMOSetup_4.2.2.128.tmp (PID: 11860)
    • Starts itself from another location

      • setup.exe (PID: 7196)
    • Application launched itself

      • setup.exe (PID: 7196)
      • setup.exe (PID: 9160)
      • assistant_installer.exe (PID: 8288)
      • installer.exe (PID: 8600)
      • assistant_installer.exe (PID: 9244)
      • assistant_installer.exe (PID: 9516)
      • browser_assistant.exe (PID: 9604)
      • opera.exe (PID: 9688)
      • opera.exe (PID: 10172)
      • opera_autoupdate.exe (PID: 7312)
      • opera_autoupdate.exe (PID: 5812)
      • installer.exe (PID: 8452)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 7196)
      • installer.exe (PID: 8600)
      • TG_PCOptimizer.exe (PID: 8888)
      • browser_assistant.exe (PID: 9604)
      • WMOSetup_4.2.2.128.tmp (PID: 11760)
    • There is functionality for taking screenshot (YARA)

      • setup.exe (PID: 8608)
      • setup.exe (PID: 9176)
      • setup.exe (PID: 9160)
      • setup.exe (PID: 7196)
      • TG_PCOptimizer.exe (PID: 8304)
      • TG_PCOptimizer.exe (PID: 8676)
      • TG_PCOptimizer.exe (PID: 8488)
    • Process drops legitimate windows executable

      • Assistant_117.0.5408.35_Setup.exe_sfx.exe (PID: 8968)
      • TG_PCOptimizer.exe (PID: 8488)
      • assistant_installer.exe (PID: 9244)
    • Searches for installed software

      • installer.exe (PID: 8600)
      • TiWorker.exe (PID: 9724)
      • browser_assistant.exe (PID: 9604)
    • Creates a software uninstall entry

      • installer.exe (PID: 8600)
    • Reads the date of Windows installation

      • installer.exe (PID: 8600)
      • opera.exe (PID: 10172)
    • Starts CMD.EXE for commands execution

      • TechGenie.exe (PID: 232)
    • The process creates files with name similar to system file names

      • Dism.exe (PID: 5640)
      • Dism.exe (PID: 8400)
    • Starts a Microsoft application from unusual location

      • DismHost.exe (PID: 9428)
      • DismHost.exe (PID: 9436)
    • Executes as Windows Service

      • VSSVC.exe (PID: 9664)
    • Reads Mozilla Firefox installation path

      • opera.exe (PID: 10172)
    • The process checks if it is being run in the virtual environment

      • opera.exe (PID: 10172)
    • The process executes via Task Scheduler

      • opera_autoupdate.exe (PID: 7312)
    • Reads the Windows owner or organization settings

      • WMOSetup_4.2.2.128.tmp (PID: 11860)
  • INFO

    • Reads the computer name

      • identity_helper.exe (PID: 1188)
      • setup.exe (PID: 7196)
      • setup.exe (PID: 9160)
      • assistant_installer.exe (PID: 8288)
      • TG_PCOptimizer.exe (PID: 8304)
      • TG_PCOptimizer.exe (PID: 8676)
      • TG_PCOptimizer.exe (PID: 8488)
      • installer.exe (PID: 8600)
      • TG_PCOptimizer.exe (PID: 8888)
      • TechGenie.exe (PID: 232)
      • DismHost.exe (PID: 9436)
      • DismHost.exe (PID: 9428)
      • assistant_installer.exe (PID: 9244)
      • assistant_installer.exe (PID: 9516)
      • opera.exe (PID: 9688)
      • opera.exe (PID: 9660)
      • browser_assistant.exe (PID: 9604)
      • opera.exe (PID: 10000)
      • opera.exe (PID: 10172)
      • opera.exe (PID: 10064)
      • opera.exe (PID: 10072)
      • opera.exe (PID: 9320)
      • opera.exe (PID: 9392)
      • opera.exe (PID: 10172)
      • opera.exe (PID: 10200)
      • opera_gx_splash.exe (PID: 9200)
      • opera.exe (PID: 10092)
      • opera.exe (PID: 7284)
      • opera.exe (PID: 4380)
      • opera_autoupdate.exe (PID: 5812)
      • opera_autoupdate.exe (PID: 7312)
      • installer.exe (PID: 8452)
      • WMOSetup_4.2.2.128.tmp (PID: 11860)
      • WMOSetup_4.2.2.128.tmp (PID: 11760)
      • WiseMemoryOptimzer.exe (PID: 12244)
    • Reads Environment values

      • identity_helper.exe (PID: 1188)
      • DismHost.exe (PID: 9428)
      • DismHost.exe (PID: 9436)
      • WiseMemoryOptimzer.exe (PID: 12244)
    • Checks supported languages

      • identity_helper.exe (PID: 1188)
      • OperaSetup.exe (PID: 2092)
      • setup.exe (PID: 7196)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 8608)
      • setup.exe (PID: 9160)
      • setup.exe (PID: 9176)
      • assistant_installer.exe (PID: 8288)
      • Assistant_117.0.5408.35_Setup.exe_sfx.exe (PID: 8968)
      • assistant_installer.exe (PID: 8808)
      • TG_PCOptimizer.exe (PID: 8304)
      • TG_PCOptimizer.exe (PID: 8488)
      • TG_PCOptimizer.exe (PID: 8676)
      • installer.exe (PID: 8876)
      • TG_PCOptimizer.exe (PID: 8888)
      • installer.exe (PID: 8600)
      • TechGenie.exe (PID: 232)
      • assistant_installer.exe (PID: 9244)
      • DismHost.exe (PID: 9428)
      • DismHost.exe (PID: 9436)
      • assistant_installer.exe (PID: 9332)
      • assistant_installer.exe (PID: 9552)
      • opera.exe (PID: 9660)
      • opera_crashreporter.exe (PID: 9808)
      • opera_crashreporter.exe (PID: 9800)
      • assistant_installer.exe (PID: 9516)
      • browser_assistant.exe (PID: 9964)
      • opera.exe (PID: 10000)
      • opera_crashreporter.exe (PID: 10080)
      • opera.exe (PID: 10072)
      • opera.exe (PID: 10064)
      • opera.exe (PID: 10172)
      • opera_crashreporter.exe (PID: 1280)
      • opera.exe (PID: 9320)
      • opera_crashreporter.exe (PID: 9592)
      • opera.exe (PID: 9392)
      • opera.exe (PID: 9652)
      • opera.exe (PID: 9688)
      • opera_crashreporter.exe (PID: 9788)
      • opera_crashreporter.exe (PID: 9248)
      • opera.exe (PID: 10200)
      • opera.exe (PID: 10092)
      • browser_assistant.exe (PID: 9604)
      • opera.exe (PID: 9540)
      • opera.exe (PID: 9204)
      • opera.exe (PID: 9868)
      • opera.exe (PID: 9824)
      • opera.exe (PID: 7440)
      • opera.exe (PID: 8156)
      • opera.exe (PID: 10172)
      • opera.exe (PID: 9864)
      • opera.exe (PID: 4428)
      • opera.exe (PID: 7724)
      • opera.exe (PID: 10020)
      • opera_gx_splash.exe (PID: 9200)
      • opera.exe (PID: 11128)
      • opera.exe (PID: 9080)
      • opera.exe (PID: 11112)
      • opera.exe (PID: 11104)
      • opera.exe (PID: 5392)
      • opera.exe (PID: 7284)
      • opera.exe (PID: 4380)
      • opera.exe (PID: 4728)
      • opera.exe (PID: 7308)
      • opera.exe (PID: 6940)
      • opera.exe (PID: 10496)
      • opera.exe (PID: 10520)
      • opera.exe (PID: 3124)
      • opera.exe (PID: 3784)
      • opera.exe (PID: 5172)
      • opera.exe (PID: 10516)
      • opera.exe (PID: 10500)
      • opera.exe (PID: 10492)
      • opera.exe (PID: 10524)
      • opera.exe (PID: 8824)
      • opera.exe (PID: 10288)
      • opera.exe (PID: 10476)
      • opera.exe (PID: 10376)
      • opera.exe (PID: 10192)
      • opera.exe (PID: 8508)
      • opera.exe (PID: 8256)
      • opera_autoupdate.exe (PID: 7312)
      • opera_autoupdate.exe (PID: 3300)
      • installer.exe (PID: 8452)
      • opera.exe (PID: 6760)
      • installer.exe (PID: 1600)
      • opera_autoupdate.exe (PID: 10304)
      • opera.exe (PID: 5344)
      • opera.exe (PID: 8224)
      • opera.exe (PID: 5596)
      • opera.exe (PID: 5044)
      • opera_autoupdate.exe (PID: 5812)
      • opera.exe (PID: 9816)
      • opera.exe (PID: 9992)
      • opera.exe (PID: 10344)
      • opera.exe (PID: 11120)
      • opera.exe (PID: 1184)
      • installer.exe (PID: 11036)
      • opera.exe (PID: 2356)
      • opera.exe (PID: 7928)
      • opera.exe (PID: 10748)
      • opera.exe (PID: 9392)
      • opera.exe (PID: 5964)
      • WMOSetup_4.2.2.128.tmp (PID: 11760)
      • opera.exe (PID: 9572)
      • opera.exe (PID: 5408)
      • opera.exe (PID: 11584)
      • WMOSetup_4.2.2.128.exe (PID: 11740)
      • WMOSetup_4.2.2.128.tmp (PID: 11860)
      • WMOSetup_4.2.2.128.exe (PID: 11840)
      • opera.exe (PID: 11924)
      • WiseMemoryOptimzer.exe (PID: 12244)
    • Autorun file from Downloads

      • msedge.exe (PID: 7412)
      • msedge.exe (PID: 9140)
      • msedge.exe (PID: 8660)
      • msedge.exe (PID: 11436)
    • Reads the software policy settings

      • slui.exe (PID: 5364)
      • setup.exe (PID: 7196)
      • installer.exe (PID: 8600)
      • slui.exe (PID: 7264)
      • browser_assistant.exe (PID: 9604)
      • TiWorker.exe (PID: 9724)
      • WiseMemoryOptimzer.exe (PID: 12244)
    • Create files in a temporary directory

      • OperaSetup.exe (PID: 2092)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 8608)
      • setup.exe (PID: 9160)
      • setup.exe (PID: 9176)
      • setup.exe (PID: 7196)
      • Assistant_117.0.5408.35_Setup.exe_sfx.exe (PID: 8968)
      • TG_PCOptimizer.exe (PID: 8676)
      • TG_PCOptimizer.exe (PID: 8488)
      • TG_PCOptimizer.exe (PID: 8304)
      • installer.exe (PID: 8600)
      • installer.exe (PID: 8876)
      • TG_PCOptimizer.exe (PID: 8888)
      • Dism.exe (PID: 5640)
      • Dism.exe (PID: 8400)
      • opera.exe (PID: 9688)
      • opera.exe (PID: 10172)
      • installer.exe (PID: 8452)
      • installer.exe (PID: 1600)
      • installer.exe (PID: 11036)
      • opera_autoupdate.exe (PID: 7312)
      • WMOSetup_4.2.2.128.exe (PID: 11740)
      • WMOSetup_4.2.2.128.tmp (PID: 11860)
      • WMOSetup_4.2.2.128.exe (PID: 11840)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 7412)
      • msedge.exe (PID: 8284)
      • msedge.exe (PID: 7692)
    • The sample compiled with english language support

      • OperaSetup.exe (PID: 2092)
      • setup.exe (PID: 7196)
      • setup.exe (PID: 8608)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 9160)
      • setup.exe (PID: 9176)
      • Assistant_117.0.5408.35_Setup.exe_sfx.exe (PID: 8968)
      • msedge.exe (PID: 8284)
      • installer.exe (PID: 8876)
      • installer.exe (PID: 8600)
      • Dism.exe (PID: 8400)
      • Dism.exe (PID: 5640)
      • assistant_installer.exe (PID: 9244)
      • installer.exe (PID: 8452)
      • installer.exe (PID: 1600)
      • opera_autoupdate.exe (PID: 7312)
      • installer.exe (PID: 11036)
      • opera.exe (PID: 5408)
      • WMOSetup_4.2.2.128.tmp (PID: 11860)
    • Creates files or folders in the user directory

      • setup.exe (PID: 8608)
      • setup.exe (PID: 7196)
      • setup.exe (PID: 9160)
      • installer.exe (PID: 8600)
      • assistant_installer.exe (PID: 9244)
      • opera.exe (PID: 9688)
      • opera.exe (PID: 10172)
      • browser_assistant.exe (PID: 9604)
      • opera.exe (PID: 10200)
      • opera_autoupdate.exe (PID: 3300)
      • opera_autoupdate.exe (PID: 5812)
      • opera_autoupdate.exe (PID: 7312)
      • opera.exe (PID: 11584)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 7196)
      • installer.exe (PID: 8600)
      • opera.exe (PID: 9688)
      • opera.exe (PID: 10172)
      • browser_assistant.exe (PID: 9604)
      • opera_autoupdate.exe (PID: 5812)
      • opera_autoupdate.exe (PID: 7312)
      • opera_autoupdate.exe (PID: 3300)
      • opera_autoupdate.exe (PID: 10304)
      • opera.exe (PID: 11584)
    • Checks proxy server information

      • setup.exe (PID: 7196)
      • slui.exe (PID: 7264)
      • opera.exe (PID: 9688)
      • browser_assistant.exe (PID: 9604)
      • opera.exe (PID: 10172)
      • opera_autoupdate.exe (PID: 5812)
      • opera_autoupdate.exe (PID: 7312)
      • WMOSetup_4.2.2.128.tmp (PID: 11760)
      • WiseMemoryOptimzer.exe (PID: 12244)
    • Application launched itself

      • msedge.exe (PID: 7412)
    • Process checks computer location settings

      • TG_PCOptimizer.exe (PID: 8888)
      • opera.exe (PID: 9688)
      • opera.exe (PID: 10172)
      • opera.exe (PID: 10020)
      • opera.exe (PID: 11112)
      • opera.exe (PID: 11128)
      • opera.exe (PID: 5392)
      • opera.exe (PID: 11104)
      • opera.exe (PID: 7308)
      • opera.exe (PID: 4728)
      • opera.exe (PID: 9080)
      • opera.exe (PID: 6940)
      • opera.exe (PID: 10288)
      • opera.exe (PID: 6760)
      • opera.exe (PID: 9992)
      • opera.exe (PID: 10748)
      • WMOSetup_4.2.2.128.tmp (PID: 11760)
    • Reads mouse settings

      • TechGenie.exe (PID: 232)
    • Manual execution by a user

      • assistant_installer.exe (PID: 9516)
    • OPERA mutex has been found

      • opera.exe (PID: 9688)
      • opera.exe (PID: 10172)
      • browser_assistant.exe (PID: 9604)
      • opera_autoupdate.exe (PID: 5812)
      • opera_autoupdate.exe (PID: 7312)
    • Manages system restore points

      • SrTasks.exe (PID: 10356)
      • SrTasks.exe (PID: 5596)
    • Reads CPU info

      • opera.exe (PID: 10172)
    • Connects to unusual port

      • msedge.exe (PID: 7692)
    • Creates files in the program directory

      • WMOSetup_4.2.2.128.tmp (PID: 11860)
    • Creates a software uninstall entry

      • WMOSetup_4.2.2.128.tmp (PID: 11860)
    • Local mutex for internet shortcut management

      • WMOSetup_4.2.2.128.tmp (PID: 11760)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
444
Monitored processes
294
Malicious processes
47
Suspicious processes
64

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs sppextcomobj.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe operasetup.exe setup.exe setup.exe setup.exe setup.exe setup.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs assistant_117.0.5408.35_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs tg_pcoptimizer.exe no specs tg_pcoptimizer.exe msedge.exe tg_pcoptimizer.exe no specs tg_pcoptimizer.exe no specs tg_pcoptimizer.exe tg_pcoptimizer.exe installer.exe tg_pcoptimizer.exe no specs installer.exe tg_pcoptimizer.exe msedge.exe no specs techgenie.exe no specs cmd.exe no specs cmd.exe no specs UIAutomationCrossBitnessHook32 Class no specs conhost.exe no specs conhost.exe no specs dism.exe dism.exe assistant_installer.exe assistant_installer.exe dismhost.exe no specs dismhost.exe no specs assistant_installer.exe assistant_installer.exe browser_assistant.exe opera.exe opera.exe tiworker.exe no specs opera_crashreporter.exe opera_crashreporter.exe browser_assistant.exe opera.exe opera.exe opera.exe opera_crashreporter.exe opera.exe opera_crashreporter.exe opera.exe opera_crashreporter.exe opera.exe opera.exe opera_crashreporter.exe unsecapp.exe no specs opera.exe opera_crashreporter.exe vssvc.exe no specs opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera_gx_splash.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe installer.exe opera_autoupdate.exe opera_autoupdate.exe opera_autoupdate.exe opera_autoupdate.exe opera.exe installer.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs opera.exe opera.exe opera.exe msedge.exe no specs opera.exe opera.exe opera.exe no specs opera.exe installer.exe opera.exe opera.exe no specs opera.exe no specs opera.exe opera.exe opera.exe opera.exe srtasks.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs srtasks.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs opera.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs opera.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs opera.exe msedge.exe no specs wmosetup_4.2.2.128.exe wmosetup_4.2.2.128.tmp no specs wmosetup_4.2.2.128.exe wmosetup_4.2.2.128.tmp opera.exe openwith.exe no specs wisememoryoptimzer.exe no specs wisememoryoptimzer.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
232"C:\Users\admin\AppData\Local\Temp\TechGenieSetupTMP\TechGenie.exe" C:\Users\admin\AppData\Local\Temp\TechGenieSetupTMP\TechGenie.exeTG_PCOptimizer.exe
User:
admin
Integrity Level:
HIGH
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\appdata\local\temp\techgeniesetuptmp\techgenie.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
300"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=144 --mojo-platform-channel-handle=11784 --field-trial-handle=2300,i,10218873344663301850,9548050924425196595,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
540"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=77 --mojo-platform-channel-handle=7660 --field-trial-handle=2300,i,10218873344663301850,9548050924425196595,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
728"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=79 --mojo-platform-channel-handle=7596 --field-trial-handle=2300,i,10218873344663301850,9548050924425196595,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
872"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=41 --mojo-platform-channel-handle=6960 --field-trial-handle=2300,i,10218873344663301850,9548050924425196595,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
968"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=37 --mojo-platform-channel-handle=5600 --field-trial-handle=2300,i,10218873344663301850,9548050924425196595,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1020"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=10980 --field-trial-handle=2300,i,10218873344663301850,9548050924425196595,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1088"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6344 --field-trial-handle=2300,i,10218873344663301850,9548050924425196595,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1132"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=129 --mojo-platform-channel-handle=7428 --field-trial-handle=2300,i,10218873344663301850,9548050924425196595,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1184"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:bluesky-in-sidebar=on --with-feature:cashback-assistant=off --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-amazon-us-associates=off --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:disable-adblockers-on-search-ads=on --with-feature:discord-in-sidebar=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:new-personal-news-backend=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:sitecheck-age=on --with-feature:slack-in-sidebar=on --with-feature:specific-keywords=on --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --field-trial-handle=3396,i,10030967988897034393,10931040180054229158,262144 --disable-features=CertificateTransparencyAskBeforeEnabling,PlatformSoftwareH264EncoderInGpu --variations-seed-version --mojo-platform-channel-handle=7356 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
117.0.5408.142
Modules
Images
c:\users\admin\appdata\local\programs\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera\117.0.5408.142\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
Total events
92 869
Read events
90 933
Write events
1 806
Delete events
130

Modification events

(PID) Process:(7412) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(7412) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(7412) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(7412) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(7412) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
8451CAB0B68F2F00
(PID) Process:(7412) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
67A9D2B0B68F2F00
(PID) Process:(7412) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\197232
Operation:writeName:WindowTabManagerFileMappingId
Value:
{A939E66F-711B-4A85-B235-DB00C06B2834}
(PID) Process:(7412) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
FD590BB1B68F2F00
(PID) Process:(7412) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:MicrosoftEdgeAutoLaunch_29EBC4579851B72EE312C449CF839B1A
Value:
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start
(PID) Process:(7412) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\Commands\on-logon-autolaunch
Operation:writeName:Enabled
Value:
0
Executable files
234
Suspicious files
2 991
Text files
1 874
Unknown types
2

Dropped files

PID
Process
Filename
Type
7412msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF10b9eb.TMP
MD5:
SHA256:
7412msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7412msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF10b9eb.TMP
MD5:
SHA256:
7412msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7412msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF10ba0b.TMP
MD5:
SHA256:
7412msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF10ba0b.TMP
MD5:
SHA256:
7412msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7412msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
7412msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF10ba1a.TMP
MD5:
SHA256:
7412msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
104
TCP/UDP connections
1 251
DNS requests
1 082
Threats
15

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
304
2.19.105.127:80
http://x1.i.lencr.org/
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
95.101.54.128:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7692
msedge.exe
GET
304
2.19.105.127:80
http://r3.i.lencr.org/
unknown
whitelisted
5720
SIHClient.exe
GET
200
23.222.10.99:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7984
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5720
SIHClient.exe
GET
200
23.222.10.99:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8892
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1743005384&P2=404&P3=2&P4=BGt%2fs13C25lEhcLJDjoCN8WJaYl6ekOEq01JWw3a2AaQNYvi0tfgfFjZHJy6fdkozVDXJrHA5V0jg2JdmHHLNQ%3d%3d
unknown
whitelisted
7412
msedge.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
7412
msedge.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
95.101.54.128:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
7692
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7412
msedge.exe
239.255.255.250:1900
whitelisted
7692
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7692
msedge.exe
13.107.6.158:443
business.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7692
msedge.exe
142.250.185.206:443
google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 95.101.54.128
  • 95.101.54.122
whitelisted
google.com
  • 142.250.185.206
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
  • 150.171.28.11
  • 150.171.27.11
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.60
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
bzib.nelreports.net
  • 2.16.168.201
  • 2.16.168.219
whitelisted
www.google.com
  • 142.250.185.164
  • 142.250.186.100
  • 216.58.212.164
  • 142.250.186.132
whitelisted
www.bing.com
  • 2.19.122.30
  • 2.19.122.26
  • 2.23.227.208
  • 2.23.227.215
  • 2.19.122.50
  • 2.19.122.33
  • 2.19.122.12
  • 2.19.122.17
  • 2.19.122.31
  • 2.19.122.65
  • 2.19.122.4
whitelisted
www.gstatic.com
  • 216.58.206.67
  • 142.250.186.131
whitelisted

Threats

PID
Process
Class
Message
7692
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
7692
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
7692
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
7692
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
7692
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
7692
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
7692
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
10200
opera.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
10200
opera.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
10200
opera.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info