URL:

https://us06web.zoom.us/j/89538447442?pwd=Fj3FttX9W9DyzsbfxT4rW2JbHoBstM.1

Full analysis: https://app.any.run/tasks/b92f38a2-b0b2-4498-a8aa-6147cea894e7
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: December 25, 2025, 02:29:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
fingerprinting
loader
arch-exec
meshagent
Indicators:
MD5:

F68894ED9FBF03999E0F92D116A4701D

SHA1:

83EE990A31331FAF2AE521D6E9AE182FFD104289

SHA256:

D75E44F8A4029A9EF7AF0C3E63BC0DE96E80B313BC23F50718AAB1044D1D3E3E

SSDEEP:

3:N8CAHVILQNzQcX0Ahc+hXi/HSU:2CA19DfiPSU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
      • Installer.exe (PID: 9172)
      • Zoom.exe (PID: 1136)
      • Zoom.exe (PID: 8960)
      • Installer.exe (PID: 3380)
      • Zoom.exe (PID: 5156)
    • Executable content was dropped or overwritten

      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
      • Installer.exe (PID: 9172)
      • Zoom.exe (PID: 1136)
    • The process creates files with name similar to system file names

      • Installer.exe (PID: 9172)
      • Zoom.exe (PID: 1136)
    • Process drops legitimate windows executable

      • Installer.exe (PID: 9172)
    • Reads the date of Windows installation

      • Installer.exe (PID: 9172)
      • Zoom.exe (PID: 1136)
    • Executes application which crashes

      • Installer.exe (PID: 8760)
    • Application launched itself

      • Installer.exe (PID: 9172)
      • Zoom.exe (PID: 1136)
    • Starts itself from another location

      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
    • The process drops C-runtime libraries

      • Installer.exe (PID: 9172)
    • Starts application with an unusual extension

      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
    • Using the short paths format

      • Zoom.exe (PID: 1136)
    • MeshAgent potential remote access (YARA)

      • Zoom.exe (PID: 1136)
  • INFO

    • The sample compiled with english language support

      • msedge.exe (PID: 7916)
      • msedge.exe (PID: 7576)
      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
      • Installer.exe (PID: 9172)
      • Zoom.exe (PID: 1136)
    • Application launched itself

      • msedge.exe (PID: 7576)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 7576)
    • Checks supported languages

      • identity_helper.exe (PID: 8316)
      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
      • Installer.exe (PID: 9172)
      • Installer.exe (PID: 8760)
      • zm978F.tmp (PID: 2680)
      • Zoom.exe (PID: 1136)
      • Zoom.exe (PID: 8960)
      • Installer.exe (PID: 3380)
      • Zoom.exe (PID: 5156)
    • Reads Environment values

      • identity_helper.exe (PID: 8316)
      • Zoom.exe (PID: 1136)
    • Reads the computer name

      • identity_helper.exe (PID: 8316)
      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
      • Installer.exe (PID: 9172)
      • Zoom.exe (PID: 1136)
      • Zoom.exe (PID: 8960)
      • Installer.exe (PID: 3380)
      • Zoom.exe (PID: 5156)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 7576)
    • Create files in a temporary directory

      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
      • Zoom.exe (PID: 1136)
    • Reads the machine GUID from the registry

      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
      • Installer.exe (PID: 9172)
      • Zoom.exe (PID: 1136)
      • Zoom.exe (PID: 8960)
      • Installer.exe (PID: 3380)
      • Zoom.exe (PID: 5156)
    • Creates files or folders in the user directory

      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
      • Installer.exe (PID: 9172)
      • WerFault.exe (PID: 8728)
      • Zoom.exe (PID: 1136)
      • Zoom.exe (PID: 8960)
    • Checks proxy server information

      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
      • WerFault.exe (PID: 8728)
      • Zoom.exe (PID: 1136)
      • Zoom.exe (PID: 8960)
      • Zoom.exe (PID: 5156)
      • slui.exe (PID: 7232)
    • Process checks computer location settings

      • Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe (PID: 9088)
      • Installer.exe (PID: 9172)
      • Zoom.exe (PID: 1136)
      • Zoom.exe (PID: 8960)
      • Zoom.exe (PID: 5156)
    • The sample compiled with chinese language support

      • Installer.exe (PID: 9172)
      • Zoom.exe (PID: 1136)
    • Creates a software uninstall entry

      • Installer.exe (PID: 9172)
    • Reads product name

      • Zoom.exe (PID: 1136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
204
Monitored processes
49
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
948"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=8076,i,18221734995405051613,17134462676132241492,262144 --variations-seed-version --mojo-platform-channel-handle=7100 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1112"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2504,i,18221734995405051613,17134462676132241492,262144 --variations-seed-version --mojo-platform-channel-handle=4804 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1136"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe" "--url=zoommtg://win.launch?h.domain=us06web.zoom.us&h.path=join&confid=dXNzPVIwZVNGMHNLU292VmpGaUhDbzg1QUVHM0JUU2x2ckZjeHlaZlJzX1dPNE9NWjM0QkJGRG84VlpYRnlBaE9kbC1EVVc4eC00Q3FsOGhIRkV1X2ZSUWN4aDlWLVBUSXB1ZHYzWUh2NmxRWERnS3hidUNGMERWako2TEZQb1pjbE5KSmQyVVRDZFd6RktXemVaQnJUUm56anFBbDFFWndFVzhzWmdBX3RhQXFuTW5JR09UYkF0dWszbWguWGpvVWgxaGRkemM4cmtMNyZ0aWQ9MDkxYjBmMWY3Y2I1NGQ2MTgxMjQwMDg4OGYxZWMxZjU%3D&mcv=0.92.11227.0929&stype=0&zc=64&browser=chrome&action=join&confno=89538447442&pwd=Fj3FttX9W9DyzsbfxT4rW2JbHoBstM.1"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe
Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe
User:
admin
Company:
Zoom Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Meetings
Version:
6.7.0.24657
Modules
Images
c:\users\admin\appdata\roaming\zoom\bin\zoom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1232"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=8176,i,18221734995405051613,17134462676132241492,262144 --variations-seed-version --mojo-platform-channel-handle=1672 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1352"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=920,i,18221734995405051613,17134462676132241492,262144 --variations-seed-version --mojo-platform-channel-handle=4472 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1840"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5164,i,18221734995405051613,17134462676132241492,262144 --variations-seed-version --mojo-platform-channel-handle=5260 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2360"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=7640,i,18221734995405051613,17134462676132241492,262144 --variations-seed-version --mojo-platform-channel-handle=7644 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2364"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5208,i,18221734995405051613,17134462676132241492,262144 --variations-seed-version --mojo-platform-channel-handle=3540 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2392"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4456,i,18221734995405051613,17134462676132241492,262144 --variations-seed-version --mojo-platform-channel-handle=1584 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2680"C:\Users\admin\AppData\Local\Temp\zm978F.tmp" -DAF8C715436E44649F1312698287E6A5=C:\Users\admin\Downloads\Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exeC:\Users\admin\AppData\Local\Temp\zm978F.tmpZoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exe
User:
admin
Company:
Zoom Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Opener
Exit code:
0
Version:
6,6,0,85
Modules
Images
c:\users\admin\appdata\local\temp\zm978f.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
Total events
37 114
Read events
36 900
Write events
158
Delete events
56

Modification events

(PID) Process:(9088) Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(9088) Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(9088) Zoom_cm_fo42pnktZ9vvrZo4_mJqeLSe1uH67kE7+B4ZUDzCTcZXqF13InYqUP@ix0Y2vCXbRC2fl6h_k129f7888411573a7_.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(9172) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe
(PID) Process:(9172) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:DisplayName
Value:
Zoom Workplace
(PID) Process:(9172) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:DisplayVersion
Value:
6.7.0 (24657)
(PID) Process:(9172) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:HelpLink
Value:
https://support.zoom.us/home
(PID) Process:(9172) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:URLInfoAbout
Value:
https://zoom.us
(PID) Process:(9172) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:URLUpdateInfo
Value:
https://zoom.us
(PID) Process:(9172) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:Publisher
Value:
Zoom Communications, Inc.
Executable files
272
Suspicious files
200
Text files
355
Unknown types
4

Dropped files

PID
Process
Filename
Type
7576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RFfdf3b.TMP
MD5:
SHA256:
7576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFfdf4b.TMP
MD5:
SHA256:
7576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFfdf4b.TMP
MD5:
SHA256:
7576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFfdf4b.TMP
MD5:
SHA256:
7576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFfdf4b.TMP
MD5:
SHA256:
7576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7576msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
127
TCP/UDP connections
103
DNS requests
87
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7916
msedge.exe
GET
200
104.18.86.42:443
https://cdn.cookielaw.org/scripttemplates/6.21.0/assets/otCenterRounded.json
US
text
9.28 Kb
unknown
7916
msedge.exe
GET
200
104.18.86.42:443
https://cdn.cookielaw.org/scripttemplates/6.21.0/assets/otCommonStyles.css
US
text
20.3 Kb
unknown
7916
msedge.exe
GET
200
104.18.86.42:443
https://cdn.cookielaw.org/scripttemplates/6.21.0/assets/v2/otPcCenter.json
US
text
47.0 Kb
unknown
7916
msedge.exe
GET
200
150.171.28.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
US
text
462 b
whitelisted
7916
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:GeBWDzHI6tQyalRWMMJt7JMTh1Oo51snNtFzDoZz3B8&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
102 b
whitelisted
7916
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=EdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=65&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1741678270&lafgdate=0
US
text
768 b
whitelisted
7916
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=65&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766629763&lafgdate=0
US
text
4.71 Kb
whitelisted
7916
msedge.exe
GET
200
170.114.52.6:443
https://us06web.zoom.us/j/89538447442?pwd=Fj3FttX9W9DyzsbfxT4rW2JbHoBstM.1
US
html
8.48 Kb
unknown
7916
msedge.exe
GET
200
2.16.241.201:443
https://www.bing.com/bloomfilterfiles/ExpandedDomainsFilterGlobal.json
NL
text
128 Kb
whitelisted
7916
msedge.exe
GET
200
170.114.46.1:443
https://us01ccistatic.zoom.us/us01cci/web-sdk/chat-client.js
US
text
93.8 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
6300
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2228
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7916
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7916
msedge.exe
150.171.28.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7916
msedge.exe
170.114.52.6:443
us06web.zoom.us
CLOUDFLARESPECTRUM Cloudflare, Inc.
US
whitelisted
7916
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7916
msedge.exe
104.18.23.222:443
copilot.microsoft.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.251.140.174
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
us06web.zoom.us
  • 170.114.52.6
whitelisted
copilot.microsoft.com
  • 104.18.23.222
  • 104.18.22.222
whitelisted
st1.zoom.us
  • 170.114.45.1
  • 170.114.46.1
whitelisted
www.bing.com
  • 2.16.241.201
  • 2.16.241.218
  • 23.3.88.99
  • 23.3.88.66
  • 23.3.88.10
  • 23.3.88.8
  • 23.3.88.58
  • 23.3.88.35
  • 23.3.88.11
  • 23.3.88.19
  • 23.3.88.27
  • 104.126.37.131
  • 104.126.37.145
whitelisted
us01ccistatic.zoom.us
  • 170.114.46.1
  • 170.114.45.1
whitelisted
us04st1.zoom.us
  • 170.114.45.1
  • 170.114.46.1
whitelisted

Threats

PID
Process
Class
Message
Attempted Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Usage Observed in HTTP response
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
Misc activity
ET INFO EXE - Served Attached HTTP
Misc activity
ET INFO EXE - Served Inline HTTP
Misc activity
ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging)
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Process
Message
Installer.exe
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\zoom_install_src
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\tmp_uninstall
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\tmp_bin
Installer.exe
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is: