File name:

TheExecutor.zip

Full analysis: https://app.any.run/tasks/862942cd-b64b-4bcb-a3ab-4076507cbe59
Verdict: Malicious activity
Analysis date: August 09, 2025, 11:12:08
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-doc
github
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

17E42692E05300F6A46688E37D9F2F51

SHA1:

E39CF97441F97B3ABC5268241D5B71C01673F029

SHA256:

D809475B12759D692531A93AEED630A076CCAB6EF5A003E81689EB6678661A43

SSDEEP:

98304:7e89tUKcxmX3g5VhxNWYgsBFqSmS0w2Wruvx4HLyQsEVVldsk8+AbBwy13j8fpuw:UBFOK45BCHF1KxJJMh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 1508)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1508)
      • TheExecutor.exe (PID: 1192)
      • TheExecutor.exe (PID: 1232)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 1508)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7420)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7580)
    • Drops 7-zip archiver for unpacking

      • msiexec.exe (PID: 7580)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 7580)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 1508)
      • msiexec.exe (PID: 7580)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1508)
      • msedge.exe (PID: 7056)
      • msedge.exe (PID: 6656)
      • msiexec.exe (PID: 7580)
    • Creates files in the program directory

      • TheExecutor.exe (PID: 1192)
    • Application launched itself

      • msedge.exe (PID: 4528)
      • msedge.exe (PID: 5248)
      • msedge.exe (PID: 6656)
    • Checks supported languages

      • identity_helper.exe (PID: 7896)
      • TheExecutor.exe (PID: 1192)
      • msiexec.exe (PID: 7580)
      • TheExecutor.exe (PID: 1232)
    • Reads Environment values

      • identity_helper.exe (PID: 7896)
    • Reads the computer name

      • TheExecutor.exe (PID: 1192)
      • identity_helper.exe (PID: 7896)
      • msiexec.exe (PID: 7580)
      • TheExecutor.exe (PID: 1232)
    • Manual execution by a user

      • msedge.exe (PID: 6656)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 6656)
    • Manages system restore points

      • SrTasks.exe (PID: 2296)
    • The sample compiled with russian language support

      • msiexec.exe (PID: 7580)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 7580)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:11:13 12:15:28
ZipCRC: 0x7798f956
ZipCompressedSize: 769737
ZipUncompressedSize: 1437056
ZipFileName: clrjit.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
191
Monitored processes
48
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe theexecutor.exe no specs theexecutor.exe conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe no specs msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs theexecutor.exe no specs theexecutor.exe conhost.exe no specs slui.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1192"C:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\TheExecutor.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\TheExecutor.exe
WinRAR.exe
User:
admin
Company:
Marcin Szeniak
Integrity Level:
HIGH
Description:
WinUpdateHelper
Version:
5.8.2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1508.24940\theexecutor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1232"C:\Users\admin\AppData\Local\Temp\Rar$EXa1508.29371\TheExecutor.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1508.29371\TheExecutor.exe
WinRAR.exe
User:
admin
Company:
Marcin Szeniak
Integrity Level:
HIGH
Description:
WinUpdateHelper
Version:
5.8.2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1508.29371\theexecutor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1392"C:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\TheExecutor.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\TheExecutor.exeWinRAR.exe
User:
admin
Company:
Marcin Szeniak
Integrity Level:
MEDIUM
Description:
WinUpdateHelper
Exit code:
3221226540
Version:
5.8.2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1508.24940\theexecutor.exe
c:\windows\system32\ntdll.dll
1468"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3568,i,11732563032577702147,10670532200799405511,262144 --variations-seed-version --mojo-platform-channel-handle=3580 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1508"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\TheExecutor.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1808"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2408,i,11732563032577702147,10670532200799405511,262144 --variations-seed-version --mojo-platform-channel-handle=2400 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1880"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2348,i,12186397747545992538,16604146151614898783,262144 --variations-seed-version --mojo-platform-channel-handle=2344 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1932"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x29c,0x2a0,0x2a4,0x298,0x214,0x7ffc4528f208,0x7ffc4528f214,0x7ffc4528f220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2296C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2348"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=26 --always-read-main-dll --field-trial-handle=3116,i,11732563032577702147,10670532200799405511,262144 --variations-seed-version --mojo-platform-channel-handle=6096 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
15 049
Read events
14 708
Write events
324
Delete events
17

Modification events

(PID) Process:(1508) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1508) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1508) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1508) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1508) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1508) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\TheExecutor.zip
(PID) Process:(1508) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1508) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1508) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1508) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
62
Suspicious files
230
Text files
143
Unknown types
0

Dropped files

PID
Process
Filename
Type
1508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\clrjit.dllexecutable
MD5:92795535F2855D02685A78985D2F3D28
SHA256:7399B0EFE5B3D0A9656F35A7317C9210DFDA4374FBBA7B2FD07671A5855A9345
1508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\coreclr.dllexecutable
MD5:CBB2F646B9B2A67DAD68C35BBC7CB7C8
SHA256:C6E05A6D8433F111916F2B107B765A9159F41FA1C7A5D8E267645DBD6734D737
1508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\hostfxr.dllexecutable
MD5:A4431266F13F98D48A2F2B10FD2D8A71
SHA256:88945E1FD1B63C3D941F67E6CF161680F1288C97FB7AC6028D2645477708F124
1508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\System.Console.dllexecutable
MD5:3FE0D98FDA1FEDBC8AA7DCB05DE92805
SHA256:DD2C6992C14120D0D758F778D5D390FE340D745A00CB0C93452B5FF23DB13306
1508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\hostpolicy.dllexecutable
MD5:04AEBB8B06CBFA10DE7225F2AE76F98F
SHA256:BFC1C6DD5EED11E15882A3D9E85C63A942A10F81C82D21BB0E7A190BA2D49A91
1508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\README.txttext
MD5:3A06935DDF57B2FACEC08DEA3D29740C
SHA256:77CFCB6BA324785DE19110F03E7DF78ED523A61F747824B296B924D584F9D154
1508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\System.Collections.dllexecutable
MD5:7F99540073810866C551A48BA22DBCDD
SHA256:12E621A0CFE6A28B22246BA06A65B832C9F11ACA62CA0222265906480F01B90C
1508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\System.ComponentModel.Primitives.dllexecutable
MD5:FBD7AB0A2B86514EE3FE03D3A1B89ADB
SHA256:9D68BE843B0493B015CBC54EBB861631202D23CF5871B527523083DE29102B48
1508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\Microsoft.Win32.Primitives.dllexecutable
MD5:CC3035B444919AAF960F226B256C612A
SHA256:C5892083EF60BEAF9551F8DF3DCF4FED0FC2CE96A289AB1B1835979A1DB88FD2
1508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1508.24940\System.Diagnostics.Process.dllexecutable
MD5:A688B390880E4BA55B2A4E52A6EFB5C4
SHA256:B47FA6C38902EB8AF6745A6F968BBF79BA9E35C7B41D9D48975D87B1F8BFAA59
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
77
DNS requests
68
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3872
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2216
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.216.77.27:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2216
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7056
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:GJqK29zQCTE5LAiKHz1TY87oCiTOWQGoWEfGd2zU4nw&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1300
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3872
svchost.exe
40.126.32.138:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3872
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.216.77.27:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.184.206
whitelisted
login.live.com
  • 40.126.32.138
  • 20.190.160.130
  • 20.190.160.128
  • 20.190.160.66
  • 40.126.32.140
  • 20.190.160.67
  • 40.126.32.72
  • 20.190.160.131
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 23.216.77.27
  • 23.216.77.28
  • 23.216.77.30
  • 23.216.77.34
  • 23.216.77.37
  • 23.216.77.26
  • 23.216.77.36
  • 23.216.77.35
  • 23.216.77.29
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
igk.filexspace.com
  • 104.21.112.1
  • 104.21.32.1
  • 104.21.64.1
  • 104.21.96.1
  • 104.21.80.1
  • 104.21.16.1
  • 104.21.48.1
whitelisted
copilot.microsoft.com
  • 2.16.241.220
  • 2.16.241.224
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
7056
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
7056
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
7056
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
7056
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
7056
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
7056
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
7056
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access release user assets on GitHub
Potentially Bad Traffic
ET INFO Possible Chrome Plugin install
Process
Message
TheExecutor.exe
Profiler was prevented from loading notification profiler due to app settings. Process ID (decimal): 1192. Message ID: [0x2509].
TheExecutor.exe
Profiler was prevented from loading notification profiler due to app settings. Process ID (decimal): 1232. Message ID: [0x2509].