URL:

https://github.com/Da2dalus/The-MALWARE-Repo/tree/master/Trojan/MrsMajors

Full analysis: https://app.any.run/tasks/bfafeb88-3167-4529-b9e1-11329a7403f8
Verdict: Malicious activity
Analysis date: May 16, 2025, 12:27:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
github
Indicators:
MD5:

65F372D987D68AAAF45C7445A86CB903

SHA1:

5E18E4C8CDB074BE71E9C661B89D29EC08E3E89B

SHA256:

DAA1D204256147B036EA3D32926F112251D96B3659EF6407B7CE9E3565ABD472

SSDEEP:

3:N8tEdJejSOpykO3QAT+bPpoXU:2ubYSOc9VT+bPpKU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Checks whether a specified folder exists (SCRIPT)

      • wscript.exe (PID: 1820)
    • Accesses environment variables (SCRIPT)

      • wscript.exe (PID: 1820)
    • Gets TEMP folder path (SCRIPT)

      • wscript.exe (PID: 1820)
    • Gets path to any of the special folders (SCRIPT)

      • wscript.exe (PID: 1820)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 1820)
    • Copies file to a new location (SCRIPT)

      • wscript.exe (PID: 1820)
    • Disables Windows Defender

      • wscript.exe (PID: 1820)
      • wscript.exe (PID: 2792)
    • Modifies registry startup key (SCRIPT)

      • wscript.exe (PID: 1820)
    • Creates a new registry key or changes the value of an existing one (SCRIPT)

      • wscript.exe (PID: 1820)
    • Changes the login/logoff helper path in the registry

      • wscript.exe (PID: 1820)
      • wscript.exe (PID: 2792)
    • Modify registry editing tools (regedit)

      • wscript.exe (PID: 2792)
    • Uses TASKKILL.EXE to kill security tools

      • cmd.exe (PID: 2856)
      • cmd.exe (PID: 2852)
      • cmd.exe (PID: 3828)
      • cmd.exe (PID: 4012)
      • cmd.exe (PID: 3132)
      • cmd.exe (PID: 2700)
      • cmd.exe (PID: 3008)
      • cmd.exe (PID: 3680)
      • cmd.exe (PID: 1512)
      • cmd.exe (PID: 3616)
      • cmd.exe (PID: 3900)
      • cmd.exe (PID: 2700)
      • cmd.exe (PID: 3636)
      • cmd.exe (PID: 2472)
      • cmd.exe (PID: 2972)
      • cmd.exe (PID: 3572)
      • cmd.exe (PID: 3628)
      • cmd.exe (PID: 1008)
      • cmd.exe (PID: 2532)
      • cmd.exe (PID: 680)
      • cmd.exe (PID: 3344)
      • cmd.exe (PID: 4032)
      • cmd.exe (PID: 616)
      • cmd.exe (PID: 2616)
      • cmd.exe (PID: 3468)
      • cmd.exe (PID: 860)
      • cmd.exe (PID: 936)
      • cmd.exe (PID: 3252)
      • cmd.exe (PID: 2188)
    • Antivirus name has been found in the command line (generic signature)

      • taskkill.exe (PID: 3392)
      • taskkill.exe (PID: 3440)
      • taskkill.exe (PID: 2384)
      • taskkill.exe (PID: 3564)
      • taskkill.exe (PID: 2528)
      • taskkill.exe (PID: 3300)
      • taskkill.exe (PID: 3368)
      • taskkill.exe (PID: 2300)
      • taskkill.exe (PID: 3328)
      • taskkill.exe (PID: 340)
      • taskkill.exe (PID: 2344)
      • taskkill.exe (PID: 3272)
      • taskkill.exe (PID: 1016)
      • taskkill.exe (PID: 3356)
      • taskkill.exe (PID: 2060)
      • taskkill.exe (PID: 3324)
      • taskkill.exe (PID: 2168)
      • taskkill.exe (PID: 3288)
      • taskkill.exe (PID: 3952)
      • taskkill.exe (PID: 2400)
      • taskkill.exe (PID: 728)
      • taskkill.exe (PID: 2568)
      • taskkill.exe (PID: 3072)
      • taskkill.exe (PID: 3368)
      • taskkill.exe (PID: 4068)
      • taskkill.exe (PID: 872)
      • taskkill.exe (PID: 3848)
      • taskkill.exe (PID: 3536)
      • taskkill.exe (PID: 2724)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MrsMajor2.0.exe (PID: 3540)
      • wscript.exe (PID: 1820)
      • cmd.exe (PID: 2584)
    • Reads the Internet Settings

      • MrsMajor2.0.exe (PID: 3540)
      • wscript.exe (PID: 1820)
      • GetReady.exe (PID: 2444)
      • sipnotify.exe (PID: 240)
      • wscript.exe (PID: 2264)
      • cmd.exe (PID: 2324)
      • runner32s.exe (PID: 2620)
      • RuntimeChecker.exe (PID: 2628)
      • wscript.exe (PID: 2660)
      • wscript.exe (PID: 2792)
      • Major.exe (PID: 2772)
      • wscript.exe (PID: 2884)
      • majorlist.exe (PID: 2936)
    • Reads security settings of Internet Explorer

      • MrsMajor2.0.exe (PID: 3540)
      • GetReady.exe (PID: 2444)
      • RuntimeChecker.exe (PID: 2628)
      • runner32s.exe (PID: 2620)
      • Major.exe (PID: 2772)
      • majorlist.exe (PID: 2936)
    • The process executes VB scripts

      • MrsMajor2.0.exe (PID: 3540)
      • RuntimeChecker.exe (PID: 2628)
      • runner32s.exe (PID: 2620)
      • Major.exe (PID: 2772)
      • cmd.exe (PID: 2832)
      • RuntimeChecker.exe (PID: 2628)
      • runner32s.exe (PID: 2620)
      • Major.exe (PID: 2776)
      • cmd.exe (PID: 2832)
      • runner32s.exe (PID: 2464)
      • RuntimeChecker.exe (PID: 2472)
      • Major.exe (PID: 2604)
      • cmd.exe (PID: 2672)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 1820)
    • Checks whether a specific file exists (SCRIPT)

      • wscript.exe (PID: 1820)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 1820)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 1820)
      • GetReady.exe (PID: 2444)
      • wscript.exe (PID: 2264)
      • wscript.exe (PID: 2660)
      • wscript.exe (PID: 2792)
      • majorlist.exe (PID: 2936)
      • wscript.exe (PID: 2180)
      • wscript.exe (PID: 2676)
      • wscript.exe (PID: 2792)
      • majorlist.exe (PID: 2952)
      • wscript.exe (PID: 2056)
      • wscript.exe (PID: 2636)
      • wscript.exe (PID: 2500)
      • majorlist.exe (PID: 2800)
    • The executable file from the user directory is run by the CMD process

      • eula32.exe (PID: 2220)
      • runner32s.exe (PID: 2352)
      • runner32s.exe (PID: 2416)
      • runner32s.exe (PID: 2620)
      • runner32s.exe (PID: 2260)
      • runner32s.exe (PID: 2352)
      • runner32s.exe (PID: 2620)
      • runner32s.exe (PID: 2168)
      • runner32s.exe (PID: 2228)
      • runner32s.exe (PID: 2464)
    • There is functionality for taking screenshot (YARA)

      • MrsMajor2.0.exe (PID: 3540)
    • Changes the desktop background image

      • wscript.exe (PID: 1820)
      • wscript.exe (PID: 2792)
    • Takes ownership (TAKEOWN.EXE)

      • cmd.exe (PID: 2584)
    • Executing commands from a ".bat" file

      • GetReady.exe (PID: 2444)
      • wscript.exe (PID: 2792)
      • majorlist.exe (PID: 2936)
      • majorlist.exe (PID: 2952)
      • wscript.exe (PID: 2792)
      • wscript.exe (PID: 2636)
      • majorlist.exe (PID: 2800)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 2584)
    • The system shut down or reboot

      • wscript.exe (PID: 1820)
    • The process executes via Task Scheduler

      • ctfmon.exe (PID: 1916)
      • sipnotify.exe (PID: 240)
      • ctfmon.exe (PID: 1456)
      • sipnotify.exe (PID: 1460)
      • sipnotify.exe (PID: 1776)
      • ctfmon.exe (PID: 148)
    • Uses TASKKILL.EXE to kill Browsers

      • cmd.exe (PID: 2856)
      • cmd.exe (PID: 2852)
      • cmd.exe (PID: 3132)
      • cmd.exe (PID: 3828)
      • cmd.exe (PID: 4028)
      • cmd.exe (PID: 4012)
      • cmd.exe (PID: 2700)
      • cmd.exe (PID: 3900)
      • cmd.exe (PID: 3008)
      • cmd.exe (PID: 3680)
      • cmd.exe (PID: 1512)
      • cmd.exe (PID: 3616)
      • cmd.exe (PID: 2700)
      • cmd.exe (PID: 3636)
      • cmd.exe (PID: 2472)
      • cmd.exe (PID: 2972)
      • cmd.exe (PID: 3572)
      • cmd.exe (PID: 3628)
      • cmd.exe (PID: 1008)
      • cmd.exe (PID: 680)
      • cmd.exe (PID: 2532)
      • cmd.exe (PID: 3344)
      • cmd.exe (PID: 2616)
      • cmd.exe (PID: 3468)
      • cmd.exe (PID: 4032)
      • cmd.exe (PID: 860)
      • cmd.exe (PID: 616)
      • cmd.exe (PID: 936)
      • cmd.exe (PID: 3252)
      • cmd.exe (PID: 2188)
    • Octal escape sequence obfuscation

      • majorlist.exe (PID: 2936)
      • majorlist.exe (PID: 2952)
      • majorlist.exe (PID: 2800)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2856)
      • cmd.exe (PID: 2852)
      • cmd.exe (PID: 3132)
      • cmd.exe (PID: 3828)
      • cmd.exe (PID: 4028)
      • cmd.exe (PID: 4012)
      • cmd.exe (PID: 2700)
      • cmd.exe (PID: 3900)
      • cmd.exe (PID: 3008)
      • cmd.exe (PID: 3680)
      • cmd.exe (PID: 1512)
      • cmd.exe (PID: 3616)
      • cmd.exe (PID: 2700)
      • cmd.exe (PID: 3636)
      • cmd.exe (PID: 3572)
      • cmd.exe (PID: 2972)
      • cmd.exe (PID: 3628)
      • cmd.exe (PID: 2472)
      • cmd.exe (PID: 1008)
      • cmd.exe (PID: 680)
      • cmd.exe (PID: 2532)
      • cmd.exe (PID: 3344)
      • cmd.exe (PID: 860)
      • cmd.exe (PID: 2616)
      • cmd.exe (PID: 616)
      • cmd.exe (PID: 3468)
      • cmd.exe (PID: 4032)
      • cmd.exe (PID: 936)
      • cmd.exe (PID: 3252)
      • cmd.exe (PID: 2188)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4068)
    • Application launched itself

      • msedge.exe (PID: 2812)
    • Manual execution by a user

      • MrsMajor2.0.exe (PID: 2064)
      • MrsMajor2.0.exe (PID: 3540)
      • IMEKLMG.EXE (PID: 2240)
      • wscript.exe (PID: 2264)
      • IMEKLMG.EXE (PID: 2256)
      • IMEKLMG.EXE (PID: 2148)
      • IMEKLMG.EXE (PID: 2168)
      • wscript.exe (PID: 2180)
      • wscript.exe (PID: 2056)
      • IMEKLMG.EXE (PID: 1136)
      • IMEKLMG.EXE (PID: 1412)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 4068)
    • Checks supported languages

      • MrsMajor2.0.exe (PID: 3540)
      • eula32.exe (PID: 2220)
      • GetReady.exe (PID: 2444)
      • IMEKLMG.EXE (PID: 2240)
      • NotMuch.exe (PID: 3628)
      • RuntimeChecker.exe (PID: 2628)
      • runner32s.exe (PID: 2620)
      • IMEKLMG.EXE (PID: 2256)
      • Major.exe (PID: 2772)
      • majorlist.exe (PID: 2936)
      • majordared.exe (PID: 3016)
    • Reads the computer name

      • MrsMajor2.0.exe (PID: 3540)
      • eula32.exe (PID: 2220)
      • IMEKLMG.EXE (PID: 2240)
      • GetReady.exe (PID: 2444)
      • NotMuch.exe (PID: 3628)
      • IMEKLMG.EXE (PID: 2256)
      • RuntimeChecker.exe (PID: 2628)
      • runner32s.exe (PID: 2620)
      • Major.exe (PID: 2772)
      • majorlist.exe (PID: 2936)
      • majordared.exe (PID: 3016)
    • Create files in a temporary directory

      • MrsMajor2.0.exe (PID: 3540)
      • eula32.exe (PID: 2220)
      • GetReady.exe (PID: 2444)
      • runner32s.exe (PID: 2620)
      • RuntimeChecker.exe (PID: 2628)
      • Major.exe (PID: 2772)
      • majorlist.exe (PID: 2936)
    • Creates files in the program directory

      • wscript.exe (PID: 1820)
      • wscript.exe (PID: 2660)
    • Reads the machine GUID from the registry

      • eula32.exe (PID: 2220)
      • NotMuch.exe (PID: 3628)
      • majordared.exe (PID: 3016)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 2240)
      • IMEKLMG.EXE (PID: 2256)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
997
Monitored processes
773
Malicious processes
38
Suspicious processes
11

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe msedge.exe no specs msedge.exe no specs mrsmajor2.0.exe no specs mrsmajor2.0.exe wscript.exe cmd.exe no specs eula32.exe no specs getready.exe no specs cmd.exe takeown.exe no specs icacls.exe no specs takeown.exe no specs icacls.exe no specs notmuch.exe no specs shutdown.exe no specs ctfmon.exe no specs sipnotify.exe runtimechecker.exe no specs runtimechecker.exe no specs imeklmg.exe no specs imeklmg.exe no specs wscript.exe no specs cmd.exe no specs runner32s.exe no specs runner32s.exe no specs runner32s.exe runtimechecker.exe no specs wscript.exe no specs wscript.exe no specs cmd.exe no specs major.exe no specs wscript.exe cmd.exe no specs cmd.exe no specs wscript.exe no specs taskkill.exe no specs majorlist.exe no specs cmd.exe no specs majordared.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs ctfmon.exe no specs sipnotify.exe runtimechecker.exe no specs runtimechecker.exe no specs imeklmg.exe no specs imeklmg.exe no specs wscript.exe no specs cmd.exe no specs runner32s.exe no specs runner32s.exe no specs runner32s.exe runtimechecker.exe no specs wscript.exe no specs wscript.exe no specs cmd.exe no specs major.exe no specs wscript.exe no specs cmd.exe no specs cmd.exe no specs wscript.exe no specs taskkill.exe no specs majorlist.exe no specs cmd.exe no specs majordared.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs ctfmon.exe no specs sipnotify.exe runtimechecker.exe no specs runtimechecker.exe no specs imeklmg.exe no specs imeklmg.exe no specs wscript.exe no specs cmd.exe no specs runner32s.exe no specs runner32s.exe no specs runner32s.exe runtimechecker.exe no specs wscript.exe no specs wscript.exe no specs cmd.exe no specs major.exe no specs wscript.exe no specs cmd.exe no specs cmd.exe no specs taskkill.exe no specs wscript.exe no specs majorlist.exe no specs cmd.exe no specs majordared.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116taskkill /f /im calc.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
116taskkill /f /im rundll32.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
120taskkill /f /im mspaint.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
120taskkill /f /im superaltf4.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
120taskkill /f /im msedge.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
120taskkill /f /im iexplore.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
148C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
240C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
288"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=3152 --field-trial-handle=1404,i,18790724519214089,14382237168363553117,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
312taskkill /f /im yandex.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
Total events
57 844
Read events
57 135
Write events
692
Delete events
17

Modification events

(PID) Process:(2812) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(2812) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2812) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2812) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2812) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2812) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2812) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(2812) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
2794A230D6932F00
(PID) Process:(2812) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\FirstNotDefault
Operation:delete valueName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
(PID) Process:(2812) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge
Operation:writeName:UsageStatsInSample
Value:
1
Executable files
31
Suspicious files
189
Text files
109
Unknown types
1

Dropped files

PID
Process
Filename
Type
2812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1820c2.TMP
MD5:
SHA256:
2812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
2812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF1820f0.TMP
MD5:
SHA256:
2812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
2812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1821bc.TMP
MD5:
SHA256:
2812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
2812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database\LOG.old~RF1820e1.TMPtext
MD5:CE86C8F851C5C62FD3B245514A656CC3
SHA256:E59B71835032C5D6C65BA4BB15A1676C7287241388CBE117F3C16F601B84E3D0
2812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\LOG.old~RF1820e1.TMPtext
MD5:D6E3A4A682F60FDD61EA5512284171EC
SHA256:8B8EB180A896C63D5112F8DE6EA7CB016296FAB862F8EEEAC5EB2A1462A53332
2812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\LOG.old~RF1821bc.TMPtext
MD5:5EF0F31B6E7675AE779CC7D73CBB1AA3
SHA256:4CA9894E5D3F96E2A7BC1654E87A6D2D88CAE9CA910A126E4350E5BAE17907DF
2812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\e2e6abd3-2752-46f5-874d-77a6478340c5.tmpbinary
MD5:5058F1AF8388633F609CADB75A75DC9D
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
45
DNS requests
32
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1460
sipnotify.exe
HEAD
503
104.102.43.250:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133918757666090000
unknown
whitelisted
1460
sipnotify.exe
HEAD
503
104.102.43.250:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133918758095310000
unknown
whitelisted
240
sipnotify.exe
HEAD
503
23.67.143.243:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133918757406090000
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
672
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2812
msedge.exe
239.255.255.250:1900
whitelisted
672
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
672
msedge.exe
140.82.121.3:443
github.com
GITHUB
US
whitelisted
672
msedge.exe
185.199.111.154:443
github.githubassets.com
FASTLY
US
whitelisted
672
msedge.exe
185.199.111.133:443
avatars.githubusercontent.com
FASTLY
US
whitelisted
672
msedge.exe
92.123.104.58:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
github.com
  • 140.82.121.3
whitelisted
github.githubassets.com
  • 185.199.111.154
  • 185.199.109.154
  • 185.199.108.154
  • 185.199.110.154
whitelisted
avatars.githubusercontent.com
  • 185.199.111.133
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
whitelisted
github-cloud.s3.amazonaws.com
  • 54.231.171.209
  • 52.217.1.28
  • 3.5.29.138
  • 16.15.200.236
  • 54.231.203.33
  • 3.5.19.110
  • 3.5.12.71
  • 52.217.1.156
whitelisted
user-images.githubusercontent.com
  • 185.199.109.133
  • 185.199.111.133
  • 185.199.110.133
  • 185.199.108.133
whitelisted
www.bing.com
  • 92.123.104.58
  • 92.123.104.61
  • 92.123.104.65
  • 92.123.104.66
  • 92.123.104.62
  • 92.123.104.53
  • 92.123.104.49
  • 92.123.104.50
  • 92.123.104.67
whitelisted
collector.github.com
  • 140.82.113.21
whitelisted

Threats

PID
Process
Class
Message
672
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
672
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
No debug info