| URL: | google.com |
| Full analysis: | https://app.any.run/tasks/e91ad9fa-0457-4461-94d2-00490f6a84bd |
| Verdict: | Malicious activity |
| Analysis date: | November 09, 2024, 11:30:55 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 1D5920F4B44B27A802BD77C4F0536F5A |
| SHA1: | BAEA954B95731C68AE6E45BD1E252EB4560CDC45 |
| SHA256: | D4C9D9027326271A89CE51FCAF328ED673F17BE33469FF979E8AB8DD501E664F |
| SSDEEP: | 3:duK:IK |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 528 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --no-appcompat-clear --mojo-platform-channel-handle=1580 --field-trial-handle=2232,i,7272271144772312238,8864162633095037331,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 1073807364 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 916 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3616 --field-trial-handle=2232,i,7272271144772312238,8864162633095037331,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1068 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "google.com" | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1196 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=5916 --field-trial-handle=2232,i,7272271144772312238,8864162633095037331,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1452 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5092 --field-trial-handle=2232,i,7272271144772312238,8864162633095037331,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1884 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa7284.21829\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa7284.21829\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe | NoEscape.exe | ||||||||||||
User: admin Company: Endermanch Integrity Level: HIGH Description: Windows Customization Tool Exit code: 0 Version: 6.6.6.6 Modules
| |||||||||||||||
| 1952 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6084 --field-trial-handle=2232,i,7272271144772312238,8864162633095037331,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2224 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=4452 --field-trial-handle=2232,i,7272271144772312238,8864162633095037331,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2928 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=3740 --field-trial-handle=2232,i,7272271144772312238,8864162633095037331,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 3108 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4344 --field-trial-handle=2232,i,7272271144772312238,8864162633095037331,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (1068) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (1068) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (1068) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1068) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (1068) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: 0D80397C0F852F00 | |||
| (PID) Process: | (1068) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: D269407C0F852F00 | |||
| (PID) Process: | (1068) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262760 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {E0B3A6AE-D3F5-46FF-95E1-BA56573163CF} | |||
| (PID) Process: | (1068) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262760 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {85FFFB12-E261-438D-8D06-05EBC9F5AAB2} | |||
| (PID) Process: | (1068) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262760 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {185DA199-74A1-4A8D-8155-D829E52597DD} | |||
| (PID) Process: | (1068) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262760 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {CB7E603A-ABEC-4519-9119-91F35A5E6054} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5168 | msedge.exe | C:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping1068_1992491510\data.txt | text | |
MD5:D0DD3C5E500FBC9EB7225B76660632A5 | SHA256:72B3A4617D74868B4F2F7FCEA1EFA6849D5A77F3D29889BD87BDDE7053C5424E | |||
| 1068 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RFa9123.TMP | binary | |
MD5:7CC509B06E9733ACCCE9DFB9E26DA24F | SHA256:C33AE9D5A50EE98B591EA9472080672E3D8F34BACE295E715094DAC0F57C329E | |||
| 5168 | msedge.exe | C:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping1068_1992491510\manifest.json | binary | |
MD5:C35841DD7F0A10120E2B6DF0DD1FFF93 | SHA256:39296A0D56C1BB9DB0A56CC532164266B69802791DFDC2A5161FE614A3CE28DB | |||
| 1068 | msedge.exe | C:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping1068_1046770330\manifest.fingerprint | text | |
MD5:3FB5233616491DF0EC229BA9F42EFDB8 | SHA256:946F3A9E019B0D80F5671DE782F295132341F663F74AEBAD7628F22E528D6D52 | |||
| 1068 | msedge.exe | C:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping1068_1992491510\manifest.fingerprint | text | |
MD5:59BA4C6EADAE3418997670507F0C0D40 | SHA256:D9D46A8A61FBE5A957AE65D02926D3E69B03706767A15C33F1C54B374CA3E03E | |||
| 1068 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\ad6725e0-5c8a-4471-817e-8c10297d7de4.tmp | binary | |
MD5:617809CBD18A8389D5B4BC54F8579416 | SHA256:DDB8CA90E1D63CCAD00395940BE12781BBC14405B275EA866D380E79519D285E | |||
| 2928 | msedge.exe | C:\Users\admin\AppData\Local\D3DSCache\f4d41c5d09ae781\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock | text | |
MD5:F49655F856ACB8884CC0ACE29216F511 | SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA | |||
| 7664 | msedge.exe | C:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping1068_1046770330\manifest.json | binary | |
MD5:AF3A9104CA46F35BB5F6123D89C25966 | SHA256:81BD82AC27612A58BE30A72DD8956B13F883E32FFB54A58076BD6A42B8AFAEEA | |||
| 7304 | msedge.exe | C:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping1068_639332300\manifest.json | binary | |
MD5:D17E65F6F5E60F89D39BE9E78751B310 | SHA256:3126AF874B50391D6172492623E82560E5F24BDA5E82FC8ACDA2DAE7C50D80AB | |||
| 7284 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa7284.21829\NoEscape.exe-Download-main\NoEscape.exe\vc_redist.x86.exe | executable | |
MD5:1A15E6606BAC9647E7AD3CAA543377CF | SHA256:FDD1E1F0DCAE2D0AA0720895EFF33B927D13076E64464BB7C7E5843B7667CD14 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4360 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
4700 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6944 | svchost.exe | GET | 200 | 23.32.97.216:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6944 | svchost.exe | GET | 200 | 23.48.23.177:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7384 | SIHClient.exe | GET | 200 | 23.32.97.216:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7384 | SIHClient.exe | GET | 200 | 23.32.97.216:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
2588 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | HEAD | 200 | 2.19.126.155:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1731462760&P2=404&P3=2&P4=cqq%2bo09VUuTc8tWhQiXiLnjG1qwmrfEJwWeVIjzB0opPbRRS48Xo5EThl45w0mhGRnZCywcv0H8IYNJBY0xcSw%3d%3d | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 206 | 2.19.126.155:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1731462760&P2=404&P3=2&P4=cqq%2bo09VUuTc8tWhQiXiLnjG1qwmrfEJwWeVIjzB0opPbRRS48Xo5EThl45w0mhGRnZCywcv0H8IYNJBY0xcSw%3d%3d | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 206 | 2.19.126.155:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1731462760&P2=404&P3=2&P4=cqq%2bo09VUuTc8tWhQiXiLnjG1qwmrfEJwWeVIjzB0opPbRRS48Xo5EThl45w0mhGRnZCywcv0H8IYNJBY0xcSw%3d%3d | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4360 | SearchApp.exe | 92.123.104.40:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4360 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
6944 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6764 | msedge.exe | 142.250.185.68:443 | www.google.com | — | — | whitelisted |
1068 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
6764 | msedge.exe | 216.58.206.78:443 | google.com | — | — | whitelisted |
6764 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
edge-mobile-static.azureedge.net |
| whitelisted |
business.bing.com |
| whitelisted |
www.google.com |
| whitelisted |
bzib.nelreports.net |
| whitelisted |
fonts.gstatic.com |
| whitelisted |