URL:

https://www.winzip.com/en/

Full analysis: https://app.any.run/tasks/a6aea41a-6b17-420c-b16e-04e2422118ee
Verdict: Malicious activity
Analysis date: May 21, 2025, 12:01:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MD5:

7FFB24B030E209AF626942266BE670F3

SHA1:

BE8269EE76444889392BF0707EC7824D41F89F44

SHA256:

DBC913ED7F2DCAB5FA1EAE8EBE3FD47FD219F633580BF3ED90832164151BD823

SSDEEP:

3:N8DSLAyTSn:2OLhSn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts itself from another location

      • winzip76-home.exe (PID: 2340)
      • MicrosoftEdgeUpdate.exe (PID: 7968)
      • winzip76-home.exe (PID: 7864)
    • Executable content was dropped or overwritten

      • winzip76-home.exe (PID: 2340)
      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
      • MicrosoftEdgeUpdate.exe (PID: 7968)
      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 6876)
      • winzip76-home.exe (PID: 7864)
      • MicrosoftEdgeWebview_X64_136.0.3240.76.exe (PID: 4424)
      • setup.exe (PID: 2980)
    • Process drops legitimate windows executable

      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 6876)
      • MicrosoftEdgeUpdate.exe (PID: 7968)
      • MicrosoftEdgeWebview_X64_136.0.3240.76.exe (PID: 4424)
      • setup.exe (PID: 2980)
      • msiexec.exe (PID: 4300)
    • Reads security settings of Internet Explorer

      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • Reads Microsoft Outlook installation path

      • winzip76-home.exe (PID: 4980)
    • Reads Internet Explorer settings

      • winzip76-home.exe (PID: 4980)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
      • MicrosoftEdgeUpdate.exe (PID: 7968)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • Application launched itself

      • MicrosoftEdgeUpdate.exe (PID: 5796)
      • msiexec.exe (PID: 4300)
      • setup.exe (PID: 2980)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7752)
    • Drops 7-zip archiver for unpacking

      • msiexec.exe (PID: 4300)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 4300)
  • INFO

    • Executable content was dropped or overwritten

      • firefox.exe (PID: 7400)
      • firefox.exe (PID: 4880)
      • msiexec.exe (PID: 4300)
      • msiexec.exe (PID: 5084)
    • Application launched itself

      • firefox.exe (PID: 7380)
      • firefox.exe (PID: 7400)
      • firefox.exe (PID: 3140)
      • firefox.exe (PID: 4880)
    • Create files in a temporary directory

      • winzip76-home.exe (PID: 2340)
      • winzip76-home.exe (PID: 4980)
    • Checks supported languages

      • winzip76-home.exe (PID: 2340)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • Creates files in the program directory

      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
    • Process checks computer location settings

      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • The sample compiled with english language support

      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 6876)
      • MicrosoftEdgeUpdate.exe (PID: 7968)
      • msiexec.exe (PID: 4300)
      • MicrosoftEdgeWebview_X64_136.0.3240.76.exe (PID: 4424)
      • setup.exe (PID: 2980)
    • Reads the computer name

      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • Checks proxy server information

      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
      • wermgr.exe (PID: 5968)
    • Creates files or folders in the user directory

      • winzip76-home.exe (PID: 4980)
      • wermgr.exe (PID: 5968)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 7840)
      • wermgr.exe (PID: 5968)
      • winzip76-home.exe (PID: 4980)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • Manual execution by a user

      • firefox.exe (PID: 3140)
      • winzip76-home.exe (PID: 7864)
      • winzip76-home.exe (PID: 7780)
    • Reads the machine GUID from the registry

      • winzip76-home.exe (PID: 4980)
    • Manages system restore points

      • SrTasks.exe (PID: 6032)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
203
Monitored processes
64
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs sppextcomobj.exe no specs slui.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs winzip76-home.exe no specs winzip76-home.exe winzip76-home.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe wermgr.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe microsoftedgewebview2runtimeinstallerx64.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs rundll32.exe no specs microsoftedgewebview_x64_136.0.3240.76.exe setup.exe setup.exe no specs winzip76-home.exe no specs winzip76-home.exe winzip76-home.exe microsoftedgeupdate.exe msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe wzpreviewer64.exe no specs wzpreloader.exe no specs winzip64.exe wzcabcachesynchelper64.exe winzip64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
232C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\EDGEMITMP_D5061.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=136.0.7103.113 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\EDGEMITMP_D5061.tmp\setup.exe --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=136.0.3240.76 --initial-client-data=0x260,0x264,0x268,0x23c,0x26c,0x7ff7ca9bf3e8,0x7ff7ca9bf3f4,0x7ff7ca9bf400C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\EDGEMITMP_D5061.tmp\setup.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
136.0.3240.76
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{3c6f33b9-18c6-45a7-9545-9dc2bc8081aa}\edgemitmp_d5061.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
736"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5900 -childID 8 -isForBrowser -prefsHandle 5892 -prefMapHandle 5832 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1392 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d33999d6-e769-4040-8b9e-27e021de17bd} 7400 "\\.\pipe\gecko-crash-server-pipe.7400" 1c42489ca10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
920C:\Windows\syswow64\MsiExec.exe -Embedding 156D946CBFE11BA993C0590105EEFC18C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1096"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5128 -childID 7 -isForBrowser -prefsHandle 5752 -prefMapHandle 5088 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1416 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f56ce552-6ae8-40ed-831b-4c04fd429fc0} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 218ff183a10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
1452"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2132 -parentBuildID 20240213221259 -prefsHandle 2124 -prefMapHandle 2120 -prefsLen 32226 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {36e934c6-7fc2-40ef-a05a-06c61fcacded} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 218eb481d10 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2340"C:\Users\admin\Downloads\winzip76-home.exe" C:\Users\admin\Downloads\winzip76-home.exe
firefox.exe
User:
admin
Company:
WinZip Computing
Integrity Level:
HIGH
Description:
WinZipStub Installer
Exit code:
0
Version:
76.9.16251.0
Modules
Images
c:\users\admin\downloads\winzip76-home.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2772"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2704 -childID 1 -isForBrowser -prefsHandle 2696 -prefMapHandle 2680 -prefsLen 32642 -prefMapSize 244583 -jsInitHandle 1416 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b62090df-4317-4de3-bb97-a1c1b80486c4} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 218fcc4ff50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
2896C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
2980"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\EDGEMITMP_D5061.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\MicrosoftEdgeWebview_X64_136.0.3240.76.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\EDGEMITMP_D5061.tmp\setup.exe
MicrosoftEdgeWebview_X64_136.0.3240.76.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
136.0.3240.76
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{3c6f33b9-18c6-45a7-9545-9dc2bc8081aa}\edgemitmp_d5061.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
3140"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
Total events
64 259
Read events
61 306
Write events
2 866
Delete events
87

Modification events

(PID) Process:(7400) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(7400) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Corel\stubframework\WNZP\76
Operation:writeName:install_language
Value:
English
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Corel\PCU
Operation:writeName:7
Value:
C21120524153
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Corel\PCU
Operation:writeName:HFNCv2
Value:
C21120524153
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7840) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(7840) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{E6014B19-7BB9-4C8A-A954-225A6330BFCF}
Operation:writeName:PersistedPingString
Value:
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.195.61" shell_version="1.3.147.37" ismachine="1" sessionid="{E2AD6815-90F4-4087-9E71-FB356F85C137}" userid="{FD984739-A122-4DB0-BE5B-46E3E09D84E4}" installsource="otherinstallcmd" requestid="{E6014B19-7BB9-4C8A-A954-225A6330BFCF}" dedup="cr" domainjoined="0"><hw logical_cpus="4" physmemory="4" disk_type="2" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="10.0.19045.4046" sp="" arch="x64" product_type="48" is_wip="0" is_in_lockdown_mode="0"/><oem product_manufacturer="DELL" product_name="DELL"/><exp etag="&quot;r452t1+k2Tgq/HXzjvFNBRhopBWR9sbjXxqeUDH9uX0=&quot;"/><app appid="{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}" version="1.3.185.17" nextversion="1.3.195.61" lang="" brand="" client=""><event eventtype="2" eventresult="1" errorcode="0" extracode1="0" system_uptime_ticks="9868174910" install_time_ms="688"/></app></request>
Executable files
752
Suspicious files
335
Text files
192
Unknown types
0

Dropped files

PID
Process
Filename
Type
7400firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\protections.sqlite-journalbinary
MD5:79AE2748DF65F03A4ED9412BCFB15DDD
SHA256:6F2775B8406F1496A1386477880A820E100C511609BA7D31DC52E5B3DA8B5EDE
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.tmpbinary
MD5:C78F36BF78A74A5C37232FA18305FA6E
SHA256:319C730AC6614FDCE611894E281CBE1B5E1A304DCD812D6B642D3BE978E82EEC
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:2C99A16AED3906D92FFE3EF1808E2753
SHA256:08412578CC3BB4922388F8FF8C23962F616B69A1588DA720ADE429129C73C452
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
78
TCP/UDP connections
274
DNS requests
335
Threats
14

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2104
svchost.exe
GET
304
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7400
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
7400
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
7400
firefox.exe
POST
200
184.24.77.71:80
http://r11.o.lencr.org/
unknown
whitelisted
7400
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
7400
firefox.exe
POST
200
184.24.77.71:80
http://r11.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.66:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 23.52.120.96
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.66
  • 40.126.32.68
  • 20.190.160.5
  • 20.190.160.64
  • 40.126.32.76
  • 40.126.32.72
  • 20.190.160.17
  • 20.190.160.2
  • 40.126.31.3
  • 40.126.31.128
  • 20.190.159.71
  • 40.126.31.129
  • 40.126.31.73
  • 20.190.159.75
  • 20.190.159.128
  • 40.126.31.131
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
www.winzip.com
  • 23.41.181.185
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
e834.d.akamaiedge.net
  • 23.41.181.185
malicious

Threats

PID
Process
Class
Message
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
7400
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
7400
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
4880
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
4880
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
4880
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
4880
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
4880
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
No debug info