| URL: | tlauncher.com |
| Full analysis: | https://app.any.run/tasks/faefa520-3a27-407b-aca4-08fd8edc3019 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | January 27, 2026, 15:33:24 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | DB61C2F0255F0B5D152E510372730B34 |
| SHA1: | 6FEB4E0B078E7BB28E30CBE9B0C80B0A3160337E |
| SHA256: | D7BEE7CE08281DEF34C7212D73CEFA689B6D84CCBBD12812D712A5AD4347671A |
| SSDEEP: | 3:ceLiT:ce2T |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 32 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=1556,i,5841854050739466352,3304513310907862200,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=8108 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 552 | C:\Users\admin\AppData\Roaming\.tlauncher\starter\jre_default\jre-21.0.91-windows-x64\bin\java.exe -Dsun.java2d.uiScale.enabled=false -Xmx1536m -Dfile.encoding=UTF8 -Djava.net.preferIPv4Stack=true --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.time=ALL-UNNAMED --add-opens=java.desktop/java.awt=ALL-UNNAMED --add-opens=java.desktop/sun.awt.image=ALL-UNNAMED --add-opens=java.desktop/sun.java2d=ALL-UNNAMED --add-opens=java.desktop/java.awt.color=ALL-UNNAMED --add-opens=java.desktop/java.awt.image=ALL-UNNAMED --add-opens=java.desktop/com.apple.eawt=ALL-UNNAMED --add-opens=java.base/java.util.regex=ALL-UNNAMED --add-opens=java.desktop/javax.swing=ALL-UNNAMED --add-opens=java.desktop/java.beans=ALL-UNNAMED --add-opens=javafx.web/com.sun.webkit.network=ALL-UNNAMED --add-opens=javafx.web/javafx.scene.web=ALL-UNNAMED --add-opens=javafx.web/com.sun.webkit=ALL-UNNAMED --add-opens=javafx.web/com.sun.webkit.event=ALL-UNNAMED -cp C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\annotations-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\aopalliance-1.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\arns-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\auth-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\aws-core-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\aws-query-protocol-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\aws-xml-protocol-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\checker-qual-3.12.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\checksums-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\checksums-spi-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\commons-codec-1.9.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\commons-compress-1.23.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\commons-io-2.11.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\commons-lang3-3.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\commons-logging-1.2.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\commons-logging-api-1.1.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\commons-vfs2-2.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\crt-core-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\desktop-common-util-1.266.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\DiscordIPC-0.5.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\dnsjava-2.1.8.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\endpoints-spi-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\error_prone_annotations-2.18.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\eventstream-1.0.1.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\failureaccess-1.0.1.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\fluent-hc-4.5.2.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\gson-2.8.8.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\guava-31.0.1-jre.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\guice-7.0.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\guice-assistedinject-7.0.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\http-auth-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\http-auth-aws-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\http-auth-aws-eventstream-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\http-auth-spi-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\http-client-spi-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\http-download-1.266.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\httpclient-4.5.2.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\httpcore-4.4.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\identity-spi-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\j2objc-annotations-1.3.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\jackson-annotations-2.13.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\jakarta.inject-api-2.0.1.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-base-21.0.9-win.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-base-21.0.9.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-controls-21.0.9-win.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-controls-21.0.9.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-graphics-21.0.9-win.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-graphics-21.0.9.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-media-21.0.9-win.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-media-21.0.9.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-swing-21.0.9-win.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-swing-21.0.9.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-web-21.0.9-win.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javafx-web-21.0.9.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\javax.annotation-api-1.3.2.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\jaxb-api-2.3.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\jaxb-core-2.3.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\jaxb-impl-2.3.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\jcl-over-slf4j-1.7.25.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\jopt-simple-5.0.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\json-20230227.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\json-utils-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\jsr305-3.0.2.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\junixsocket-common-2.6.2.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\junixsocket-native-common-2.6.2.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\junrar-0.7.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\log4j-1.2.17.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\logback-classic-1.2.10.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\logback-core-1.2.10.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\lombok-1.18.30.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\maven-scm-api-1.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\maven-scm-provider-svn-commons-1.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\maven-scm-provider-svnexe-1.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\metrics-spi-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\MinecraftServerPing-1.0.2.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\mockserver-netty-no-dependencies-5.14.0.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\modpack-dto-2.282.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\picture-bundle-3.72.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\plexus-utils-1.5.6.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\profiles-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\protocol-core-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\reactive-streams-1.0.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\regexp-1.3.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\regions-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\retries-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\retries-spi-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\s3-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\sdk-core-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\skin-api-1.7.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\slf4j-api-1.7.25.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\statistics-dto-1.73.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\third-party-jackson-core-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\tlauncher-resource-1.6.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\utils-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\utils-lite-2.40.4.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\dependencies\xz-1.9.jar;C:\Users\admin\AppData\Roaming\.tlauncher\starter\original-TLauncher-2.9358.jar; org.tlauncher.tlauncher.rmo.TLauncher -starterConfig=C:\Users\admin\AppData\Roaming\.tlauncher\starter\starter.json -requireUpdate=false -currentAppVersion=2.9358 -starterDomainAvailabilityV1=C:\Users\admin\AppData\Roaming\.tlauncher\starter\domainAvailability.json -country=${country} "-starterJVM=C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe" -starterWorkingDirectory=C:\Users\admin\Downloads -starterJarFile=C:\Users\admin\AppData\Roaming\.minecraft\TLauncher.exe -starterFileEncoding=windows-1252 | C:\Users\admin\AppData\Roaming\.tlauncher\starter\jre_default\jre-21.0.91-windows-x64\bin\java.exe | javaw.exe | ||||||||||||
User: admin Company: Oracle Corporation Integrity Level: HIGH Description: Java(TM) Platform SE binary Version: 21.0.9.0 Modules
| |||||||||||||||
| 936 | chcp 437 | C:\Windows\System32\chcp.com | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Change CodePage Utility Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1352 | "C:\Users\admin\Downloads\TLauncher-Installer-1.9.5.5.exe" | C:\Users\admin\Downloads\TLauncher-Installer-1.9.5.5.exe | — | msedge.exe | |||||||||||
User: admin Company: TL Inc. Integrity Level: MEDIUM Description: TL Setup Exit code: 3221226540 Version: 1.9.5.5 Modules
| |||||||||||||||
| 1692 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=8 --always-read-main-dll --field-trial-handle=5240,i,5841854050739466352,3304513310907862200,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=4692 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1708 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=7360,i,5841854050739466352,3304513310907862200,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=7236 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1868 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --disable-quic --onnx-enabled-for-ee --string-annotations --always-read-main-dll --field-trial-handle=5588,i,5841854050739466352,3304513310907862200,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5656 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1868 | "C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServer | C:\Windows\System32\GameBarPresenceWriter.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Gamebar Presence Writer Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2096 | "C:\Users\admin\Downloads\TLauncher-Installer-1.9.5.5.exe" | C:\Users\admin\Downloads\TLauncher-Installer-1.9.5.5.exe | msedge.exe | ||||||||||||
User: admin Company: TL Inc. Integrity Level: HIGH Description: TL Setup Exit code: 5 Version: 1.9.5.5 Modules
| |||||||||||||||
| 2264 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6812,i,5841854050739466352,3304513310907862200,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6760 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5180 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1b41d8.TMP | — | |
MD5:— | SHA256:— | |||
| 5180 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5180 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1b41e7.TMP | — | |
MD5:— | SHA256:— | |||
| 5180 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1b41e7.TMP | — | |
MD5:— | SHA256:— | |||
| 5180 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5180 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5180 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1b41e7.TMP | — | |
MD5:— | SHA256:— | |||
| 5180 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1b41f7.TMP | — | |
MD5:— | SHA256:— | |||
| 5180 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5180 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1b41f7.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
8920 | msedge.exe | GET | 200 | 150.171.22.17:443 | https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=66&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0 | US | text | 4.70 Kb | whitelisted |
8920 | msedge.exe | GET | 200 | 150.171.27.11:443 | https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0 | US | text | 295 b | whitelisted |
8920 | msedge.exe | GET | 200 | 150.171.27.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:4E03QE9d4zbVk96BxUtxi9rMZdmEK9L5EV62tyParOQ&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | US | text | 98 b | whitelisted |
8920 | msedge.exe | GET | 200 | 104.18.23.222:443 | https://copilot.microsoft.com/c/api/user/eligibility | US | text | 25 b | whitelisted |
8920 | msedge.exe | GET | 200 | 199.191.50.184:80 | http://tlauncher.com/ | VG | html | 3.58 Kb | unknown |
8920 | msedge.exe | GET | 200 | 13.107.246.44:443 | https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appId=edge-extensions&country=US | US | binary | 82 b | whitelisted |
8920 | msedge.exe | GET | 200 | 188.114.97.3:443 | https://l.cdn-fileserver.com/bping.php?vgd_cage=7&prid=8PR11258V&ssld=%7B%22QQNN%22%3A%22V_%22%2C%22QQN75%22%3A%22z1EjJQ%22%2C%22QQ8E%22%3A%22%22%2C%22QQQN%22%3A%22IK%22%7D&vgd_asn=137409&vgd_cdv=O2681&vgd_oreqf=one&vgd_setup=c21&vgd_wlstp=0&hvsid=00001769528012991023663175687649&lper=100&vgd_bid=374927&gdpr=1&mspa=0&wshp=0&vgd_l2type=dmola&vgd_oresf=one&ugd=4&lf=6&cc=IT&sc=NA&requrl=https%3A%2F%2Ftlauncher.com&vgd_rpth=%2Fola&r=1769528012993&vgd_tsce=L1122&cid=8CUF42P6U&crid=683910882&vi=1769528012977859406&wsip=170764226&vgd_len=548&vgd_end=1 | US | image | 43 b | unknown |
8920 | msedge.exe | GET | 200 | 2.16.204.160:443 | https://www.bing.com/bloomfilterfiles/ExpandedDomainsFilterGlobal.json | NL | text | 128 Kb | whitelisted |
8920 | msedge.exe | GET | 200 | 199.191.50.144:443 | https://find-searcher.com/sr/754870121/SAFEFRAME.html?ule=764&%21Q911=I&%21n0=&%29nnrp=I&0G=I68yq~XgI~y66Xqywg8&19.W1T=%29nnrp%3A%2F%2FnTNW%21m%2991embQ&4Mr1=I&4Mr1m%21pn=&9m1GM=&FM=&FP15=&GpGM=g&HMpr1=&Hj%21KmmK97r=&HrTr=&M9mQQQ=&MQ15=I&NM0=&NMbQNG%21=&NMnI=&NMn~=&Nmn=%28d3D5Bf7571wW%2Fww77%2F%21f4L.L5B74BfdLd7&NrlW=&PTpnr=g&Pp%29r=g&QprN=g&T~nHr9=MQbTN&W4M=w&Wpr9%215=g&_jGM=&bGM=NNNqy6jqSjwy~SwNIwSy~yqSj8qyqm~y~q9N&bTN5=b%219&htmlsrc=1&j9=g&jGM=D6wy~6&jM13M=&jN9=&kkdd=uW%7C3%7CA9nH%2A&m%29%21QD=y%28cwgDARZ&m%29%21Q~=bp0wKG%21nm&m1GM=8XDyIgXX~&mGM=Xls%2Aw~%288s&mM0=c~8XI&mm=3x&mnrGM=&npm9=uII~~&pGL9=IIqw78Xy&pjM13M=&pm=Bf&ppTM=%7B%22ppmm%22%3A%223x%22%2C%22ppmnH%22%3A%22%21NrT9p%22%2C%22ppGr%22%3A%22%22%2C%22pppm%22%3A%22Bf%22%7D&rGM=&tpid=&eobd=&eoac=RvYbkNvbY&ure=1 | VG | html | 72.7 Kb | unknown |
8920 | msedge.exe | GET | 200 | 188.114.96.3:443 | https://l.cdn-fileserver.com/bql.php?vgd_len=5298&&vgd_l2type=dmola&fp=ylt0GbowY3mfvUzzCzuORwqLB7xiA6VUi3rJk-mqhxJdxg92EBKqtmxKd5jnILWAb-uhuVrWjvVZzkEGg3cn3FZXyZfmUEkEd1cLeMVwmGoOFxN55yj9NYmvztlEgMuW47yXSdO8bh1jF2W0m81vNw%3D%3D&cme=f_VgoC8RvrOgYc5FXT9T66mfeEriIAL5bsh2cS6BrNJzMZheJ16b8T9UIR9ngBKJPw6ZcjnE57WrMruPFee3nc7ADARHRGKTxCt5BZiCkjHXCbqfjnKHxejQF9Q0pIhST6qwKEjQly4rwBNzVC7rSdgeRgdllgKPpONhJW-F3kbTQq-OuImP4E8EzxUw_5rvgWW-zlbEWPSW4ve6zsi4y9_2r8jmCztGetDeTmjSY5bXbJTtLkjGFQigJgJ_6YizqAFZhipBGw1GlJMff7eTAg%3D%3D%7C%7Cb8KlCmE6kTENKxSBIehsQLbXBNKeHPZV%7ClMFef-zTcacfVarD4OaeexiEsA2U9ClznX-6yEYnkap7QVrS1hMxMk9l_7OKU6R0IH4Xq96vZajNm71FNz76ccJdLKtofaZ6H-GGrsB9k1B2mQSMmqSTs49IL3xRsikIJCj_1q3R5FFjE-6szXsQ2jLIee698MBTH6lYl7zDReIR2WYlRAb0poqbtm0xajILROQpjGxmIVx-muVee-GKq7xK5gOqLv_cKscxwAo-pZoE92eXSVhyLSIXTTxRFReJXnLMZ2GNxo-gebUaO_h8jXO5dqU388kuv_t15tlemQ6rTPakXWz7oASh4akEaxxnCf6Nni-6TOj21CTv3JHggagYfcsqVcI5qkDl-U22O3ztJabPc1-7pXPu1EZ6uOosMCwzvKbxamqIVaDt1IeSfgNzv48QvuN8AaKJUsJ1YGqoMTe9SsxP9DiImMQrIyQLvrsc9gr8DNs8B3u3Ma9pMpSp0w06CWTR7oReZOuXXNGEL3u09gu-7loHxBzP6A-6OfpGzSKQ20SJAD6rOpkIAtelQU1CpORnl-x2UfQuJpz3Q0aXefH3Dc0hLFNh8IbGevTGW4MyVlmeWjOIY9hmXDMaqMFWUIc6FQnMxHotgYT4JnW7SGNA_-1IjW2oIhQ_3NPdQgT7llAiRzleFbcDGOGgA9GqLZdtexeGI2ASJ5kwyHIB5NNH0sJasU_NIoP6s540Jaf4Md6m64NVY10EHG_wnd9bwREO2YouIroKeuxEvltZDmuFZVkltCFlYpsvuOi9Dia87ekyh4JU98EyiuMj1xCSlOLfZexn1DMZ8ayjOnO7ZESAS7-jDDr10CMWk0YYaeXQxhkyylsIUBAKBx0PeFmaAaEHgiNG4FOe8pze4Q41vtziNg%3D%3D%7CWOR44ZnjshyX0FEZj6c52uG8KGTsvju_%7CWtJPvijWHRscLS_XxuiqJpxfkrKTykIJ%7Ca0AmFUYXmD7fQ2LB-7FdWZ53uSdsF_TzlAZT_rbGIak%3D%7C&ksu=306&fdkt=658&vgde_kbbh=fuoyxQBuGUBO&kwd[]=I+5+Migliori+VPN+Per+Emule&kwt[]=658&kbc[]=1fc64b37dab8ca9124cb54a8b042d921.d2s&kwp[]=1&kid[]=1565633997&kbc2[]=clid_fz%3D-2%7Cclid_serp%3D-1%7Cakp%3D13%7C5%3D-1%7C6%3D-1%7C16%3D-1%7C19%3D0.00%7Ckus%3D0.4304%7Ckucs%3D5.0000%7Ckcucs%3D5.0000%7Ckcucs2%3D5.0000%7Ckssks%3D5.0000%7Crcid%3D80919%7Cclpr%3D0.789500%7Ccllvl%3D5%7Cokt%3D658%7Cbdkt%3D658%7Cbfk%3D1&ktd[]=79228162514264337593561125120&klg[]=it&unt[]=The+5+Best+VPNs+For+Emule&kwd[]=Scarica+La+Libreria+Z&kwt[]=658&kbc[]=1fc64b37dab8ca9124cb54a8b042d921.d2s&kwp[]=2&kid[]=1358064937&kbc2[]=clid_fz%3D-2%7Cclid_serp%3D-2%7Cakp%3D6%7C5%3D-1%7C6%3D-1%7C16%3D-1%7C19%3D0.00%7Ckus%3D0.4200%7Ckucs%3D5.0000%7Ckcucs%3D5.0000%7Ckcucs2%3D5.0000%7Ckssks%3D5.0000%7Crcid%3D9373%7Cclpr%3D0.717400%7Ccllvl%3D5%7Cokt%3D658%7Cbdkt%3D658%7Cbfk%3D1&ktd[]=79228162514264337593561125120&klg[]=it&unt[]=Download+the+Z+Library&kwd[]=Scarica+VPN+Gratis&kwt[]=658&kbc[]=1fc64b37dab8ca9124cb54a8b042d921.d2s&kwp[]=3&kid[]=1389250205&kbc2[]=clid_fz%3D-2%7Cclid_serp%3D-2%7Cakp%3D12%7C5%3D-1%7C6%3D-1%7C16%3D-1%7C19%3D0.00%7Ckus%3D0.4212%7Ckucs%3D5.0000%7Ckcucs%3D5.0000%7Ckcucs2%3D5.0000%7Ckssks%3D5.0000%7Crcid%3D191956%7Cclpr%3D0.879600%7Ccllvl%3D5%7Cokt%3D658%7Cbdkt%3D658%7Cbfk%3D1&ktd[]=79228162514264337593561125120&klg[]=it&unt[]=Download+Free+VPN&kwd[]=Localizza+Il+Mio+Pacchetto+Gratuitamente&kwt[]=658&kbc[]=1fc64b37dab8ca9124cb54a8b042d921.d2s&kwp[]=4&kid[]=1442342457&kbc2[]=clid_fz%3D-2%7Cclid_serp%3D-1%7Cakp%3D5%7C5%3D-1%7C6%3D-1%7C16%3D-1%7C19%3D0.00%7Ckus%3D0.4099%7Ckucs%3D5.0000%7Ckcucs%3D5.0000%7Ckcucs2%3D5.0000%7Ckssks%3D5.0000%7Crcid%3D188159%7Cclpr%3D0.749700%7Ccllvl%3D5%7Cokt%3D658%7Cbdkt%3D658%7Cbfk%3D1&ktd[]=79228162514264337593561125120&klg[]=it&unt[]=Locate+My+Package+Free&kwd[]=Scarica+Gratis+Dell%27antivirus&kwt[]=658&kbc[]=1fc64b37dab8ca9124cb54a8b042d921.d2s&kwp[]=5&kid[]=1387347129&kbc2[]=clid_fz%3D-2%7Cclid_serp%3D-2%7Cakp%3D8%7C5%3D-1%7C6%3D-1%7C16%3D-1%7C19%3D0.00%7Ckus%3D0.3748%7Ckucs%3D5.0000%7Ckcucs%3D5.0000%7Ckcucs2%3D5.0000%7Ckssks%3D5.0000%7Crcid%3D178472%7Cclpr%3D0.780300%7Ccllvl%3D5%7Cokt%3D658%7Cbdkt%3D658%7Cbfk%3D1&ktd[]=79228162514264337593561125120&klg[]=it&unt[]=Download+Free+Antivirus&v=1&gdpr=1&geo=40.86%7C14.26&lper=100&lpid=&tsid=1005&hint=&cc=IT&wsip=170764258&bca=0&ugd=4&vgde_setid=Nfu&vgde_chost=k8zOoQJ1LNwJL.NmY&cid=8CUF42P6U&vi=1769528012977859406&vsid=DefVid&tdAdd[]=asnum%3D137409&vgde_test_data_struct=%7B%22EO7E8O%22%3Au%7D&vgd_adprefflag=00&vgd_adpref_diff=1010&vgd_fm_lang=EN&vgd_implt=3&vgd_cage=5&vgd_tsce=L1122-S1122&vgd_l3_sc=NA&vgd_pdtid=1&vgd_oscar=1&vgd_ctrlid=O_SERP&vgd_nrrv=4417&vgd_nrrmf=8301000480a&vgd_nrrsf=scrr&vgd_cty=naples&vgd_csovr=0&vgd_ifrmode=03&sbdrId=&verid=&mprpslog=VWWiOaa1jlI-pGNyeTCJSw0QCOHZLwz3Q8kFOGZJV4Y7U9MQ-_AHMYpqHSD-dFKqWwzITKkSZbBdnPYgD5sJd5NEwjCeWsqxVDo0vfkX-zdtAjdcAScewMd917x-8dJK38CK8Xw5nSrJ76FdeURJvm7TlWPhf5K65M4H8XsxTUwp8oMSa3DYif_U8inMj2B--eMDvIuxuzNxrWTlKBFgCg&kbbq=%26asn%3D137409&vgd_ppvi=2151707361249369975&vgd_wlstp=0&vgd_vstrid=DefVid&vgd_scsver=2711&vgd_himglg=K0P0-O0K0-S0&vgd_cache_metadata=%7B%22kbb%22%3Afalse%7D&vgd_cfud=250421&vgd_optout=0&vgd_l2shld=1&vgd_akcip=141.11.36.0&vgd_oreqf=one&vgd_oresf=one&vgd_och=0&vgd_rensize=1352_650&vgd_scr_h=768&vgd_scr_w=1360&vgd_col_sch=l&vgd_ect=4g&vgd_be=0&vgd_nmerr=1&tdAdd[]=uiparams%3D%3Brend_w%3A1352%3Brend_h%3A650&vgd_sc=NA&hvsid=00001769528012991023663175687649&rc=0&rand=1769528014159&acid=undefined&matm=1769528014159&vgde_ltimesrc=u&vgde_ltime=uufu&vgde_rtime=uu9h&vgde_etm=X&vgde_timeObj=%7B%22juJ-JN%22%3Azxjj%2C%22jfjm1O%22%3Au9uh%2C%22QNLLQ71L7%22%3AWH%2C%22QNLLLJzOJL%22%3AF%2C%22QNLLJ-JN%22%3Af9%7D&vgd_lhl=2218&vgd_sbSup=1&vgd_nrrs=4417&vgde_cdeplbl=1E8Mzm7M1e18j1GjJ&vgd_end=1 | US | text | 15 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
8240 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8376 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5568 | SearchApp.exe | 2.16.204.134:443 | www.bing.com | AKAMAI-ASN1 | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
8920 | msedge.exe | 150.171.22.17:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8920 | msedge.exe | 150.171.27.11:80 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8920 | msedge.exe | 150.171.27.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8920 | msedge.exe | 13.107.246.44:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
tlauncher.com |
| unknown |
api.edgeoffer.microsoft.com |
| whitelisted |
copilot.microsoft.com |
| whitelisted |
l.cdn-fileserver.com |
| whitelisted |
find-searcher.com |
| unknown |
r13.i.lencr.org |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
8920 | msedge.exe | Potentially Bad Traffic | SUSPICIOUS [ANY.RUN] Possible Malicious CrossDomain (cdn-fileserver .com) |
8920 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge |
8920 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge |
8920 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
8920 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
8920 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
8920 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge |
8920 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
— | — | Potentially Bad Traffic | PAYLOAD [ANY.RUN] XORed Windows executable has been loaded |
9868 | javaw.exe | Potentially Bad Traffic | ET INFO Vulnerable Java Version 1.8.x Detected |