URL:

https://www.winzip.com/en/

Full analysis: https://app.any.run/tasks/a6aea41a-6b17-420c-b16e-04e2422118ee
Verdict: Malicious activity
Analysis date: May 21, 2025, 12:01:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MD5:

7FFB24B030E209AF626942266BE670F3

SHA1:

BE8269EE76444889392BF0707EC7824D41F89F44

SHA256:

DBC913ED7F2DCAB5FA1EAE8EBE3FD47FD219F633580BF3ED90832164151BD823

SSDEEP:

3:N8DSLAyTSn:2OLhSn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts itself from another location

      • winzip76-home.exe (PID: 2340)
      • MicrosoftEdgeUpdate.exe (PID: 7968)
      • winzip76-home.exe (PID: 7864)
    • Executable content was dropped or overwritten

      • winzip76-home.exe (PID: 2340)
      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 6876)
      • MicrosoftEdgeUpdate.exe (PID: 7968)
      • setup.exe (PID: 2980)
      • winzip76-home.exe (PID: 7864)
      • MicrosoftEdgeWebview_X64_136.0.3240.76.exe (PID: 4424)
    • Reads security settings of Internet Explorer

      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • Reads Microsoft Outlook installation path

      • winzip76-home.exe (PID: 4980)
    • Reads Internet Explorer settings

      • winzip76-home.exe (PID: 4980)
    • Process drops legitimate windows executable

      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
      • MicrosoftEdgeUpdate.exe (PID: 7968)
      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 6876)
      • setup.exe (PID: 2980)
      • msiexec.exe (PID: 4300)
      • MicrosoftEdgeWebview_X64_136.0.3240.76.exe (PID: 4424)
      • winzip76-home.exe (PID: 4980)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 7840)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
      • MicrosoftEdgeUpdate.exe (PID: 7968)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • Application launched itself

      • setup.exe (PID: 2980)
      • MicrosoftEdgeUpdate.exe (PID: 5796)
      • msiexec.exe (PID: 4300)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7752)
    • Drops 7-zip archiver for unpacking

      • msiexec.exe (PID: 4300)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 4300)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 7400)
      • firefox.exe (PID: 7380)
      • firefox.exe (PID: 4880)
      • firefox.exe (PID: 3140)
    • Create files in a temporary directory

      • winzip76-home.exe (PID: 2340)
      • winzip76-home.exe (PID: 4980)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 7400)
      • firefox.exe (PID: 4880)
      • msiexec.exe (PID: 4300)
      • msiexec.exe (PID: 5084)
    • Creates files in the program directory

      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
    • Process checks computer location settings

      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • Checks supported languages

      • winzip76-home.exe (PID: 4980)
      • winzip76-home.exe (PID: 2340)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • Reads the computer name

      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • Checks proxy server information

      • winzip76-home.exe (PID: 4980)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
      • wermgr.exe (PID: 5968)
    • Creates files or folders in the user directory

      • winzip76-home.exe (PID: 4980)
      • wermgr.exe (PID: 5968)
    • The sample compiled with english language support

      • MicrosoftEdgeWebview2Setup.exe (PID: 7188)
      • MicrosoftEdgeUpdate.exe (PID: 7840)
      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 6876)
      • MicrosoftEdgeUpdate.exe (PID: 7968)
      • MicrosoftEdgeWebview_X64_136.0.3240.76.exe (PID: 4424)
      • setup.exe (PID: 2980)
      • msiexec.exe (PID: 4300)
      • winzip76-home.exe (PID: 4980)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 7840)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 7840)
      • wermgr.exe (PID: 5968)
      • winzip76-home.exe (PID: 4980)
    • Manual execution by a user

      • firefox.exe (PID: 3140)
      • winzip76-home.exe (PID: 7864)
      • winzip76-home.exe (PID: 7780)
    • Reads the machine GUID from the registry

      • winzip76-home.exe (PID: 4980)
    • Manages system restore points

      • SrTasks.exe (PID: 6032)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
203
Monitored processes
64
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs sppextcomobj.exe no specs slui.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs winzip76-home.exe no specs winzip76-home.exe winzip76-home.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe wermgr.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe microsoftedgewebview2runtimeinstallerx64.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs rundll32.exe no specs microsoftedgewebview_x64_136.0.3240.76.exe setup.exe setup.exe no specs winzip76-home.exe no specs winzip76-home.exe winzip76-home.exe microsoftedgeupdate.exe msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe wzpreviewer64.exe no specs wzpreloader.exe no specs winzip64.exe wzcabcachesynchelper64.exe winzip64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
232C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\EDGEMITMP_D5061.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=136.0.7103.113 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\EDGEMITMP_D5061.tmp\setup.exe --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=136.0.3240.76 --initial-client-data=0x260,0x264,0x268,0x23c,0x26c,0x7ff7ca9bf3e8,0x7ff7ca9bf3f4,0x7ff7ca9bf400C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\EDGEMITMP_D5061.tmp\setup.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
136.0.3240.76
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{3c6f33b9-18c6-45a7-9545-9dc2bc8081aa}\edgemitmp_d5061.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
736"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5900 -childID 8 -isForBrowser -prefsHandle 5892 -prefMapHandle 5832 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1392 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d33999d6-e769-4040-8b9e-27e021de17bd} 7400 "\\.\pipe\gecko-crash-server-pipe.7400" 1c42489ca10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
920C:\Windows\syswow64\MsiExec.exe -Embedding 156D946CBFE11BA993C0590105EEFC18C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1096"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5128 -childID 7 -isForBrowser -prefsHandle 5752 -prefMapHandle 5088 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1416 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f56ce552-6ae8-40ed-831b-4c04fd429fc0} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 218ff183a10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
1452"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2132 -parentBuildID 20240213221259 -prefsHandle 2124 -prefMapHandle 2120 -prefsLen 32226 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {36e934c6-7fc2-40ef-a05a-06c61fcacded} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 218eb481d10 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2340"C:\Users\admin\Downloads\winzip76-home.exe" C:\Users\admin\Downloads\winzip76-home.exe
firefox.exe
User:
admin
Company:
WinZip Computing
Integrity Level:
HIGH
Description:
WinZipStub Installer
Exit code:
0
Version:
76.9.16251.0
Modules
Images
c:\users\admin\downloads\winzip76-home.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2772"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2704 -childID 1 -isForBrowser -prefsHandle 2696 -prefMapHandle 2680 -prefsLen 32642 -prefMapSize 244583 -jsInitHandle 1416 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b62090df-4317-4de3-bb97-a1c1b80486c4} 4880 "\\.\pipe\gecko-crash-server-pipe.4880" 218fcc4ff50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
2896C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
2980"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\EDGEMITMP_D5061.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\MicrosoftEdgeWebview_X64_136.0.3240.76.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3C6F33B9-18C6-45A7-9545-9DC2BC8081AA}\EDGEMITMP_D5061.tmp\setup.exe
MicrosoftEdgeWebview_X64_136.0.3240.76.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
136.0.3240.76
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{3c6f33b9-18c6-45a7-9545-9dc2bc8081aa}\edgemitmp_d5061.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
3140"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
Total events
64 259
Read events
61 306
Write events
2 866
Delete events
87

Modification events

(PID) Process:(7400) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(7400) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Corel\stubframework\WNZP\76
Operation:writeName:install_language
Value:
English
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Corel\PCU
Operation:writeName:7
Value:
C21120524153
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Corel\PCU
Operation:writeName:HFNCv2
Value:
C21120524153
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4980) winzip76-home.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7840) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(7840) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{E6014B19-7BB9-4C8A-A954-225A6330BFCF}
Operation:writeName:PersistedPingString
Value:
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.195.61" shell_version="1.3.147.37" ismachine="1" sessionid="{E2AD6815-90F4-4087-9E71-FB356F85C137}" userid="{FD984739-A122-4DB0-BE5B-46E3E09D84E4}" installsource="otherinstallcmd" requestid="{E6014B19-7BB9-4C8A-A954-225A6330BFCF}" dedup="cr" domainjoined="0"><hw logical_cpus="4" physmemory="4" disk_type="2" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="10.0.19045.4046" sp="" arch="x64" product_type="48" is_wip="0" is_in_lockdown_mode="0"/><oem product_manufacturer="DELL" product_name="DELL"/><exp etag="&quot;r452t1+k2Tgq/HXzjvFNBRhopBWR9sbjXxqeUDH9uX0=&quot;"/><app appid="{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}" version="1.3.185.17" nextversion="1.3.195.61" lang="" brand="" client=""><event eventtype="2" eventresult="1" errorcode="0" extracode1="0" system_uptime_ticks="9868174910" install_time_ms="688"/></app></request>
Executable files
752
Suspicious files
335
Text files
192
Unknown types
0

Dropped files

PID
Process
Filename
Type
7400firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
7400firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
7400firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.binbinary
MD5:C95DDC2B1A525D1A243E4C294DA2F326
SHA256:3A5919E086BFB31E36110CF636D2D5109EB51F2C410B107F126126AB25D67363
7400firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:297E88D7CEB26E549254EC875649F4EB
SHA256:8B75D4FB1845BAA06122888D11F6B65E6A36B140C54A72CC13DF390FD7C95702
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
78
TCP/UDP connections
274
DNS requests
335
Threats
14

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2104
svchost.exe
GET
304
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7400
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
7400
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
7400
firefox.exe
POST
200
184.24.77.71:80
http://r11.o.lencr.org/
unknown
whitelisted
7400
firefox.exe
POST
200
184.24.77.71:80
http://r11.o.lencr.org/
unknown
whitelisted
7400
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.66:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 23.52.120.96
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.66
  • 40.126.32.68
  • 20.190.160.5
  • 20.190.160.64
  • 40.126.32.76
  • 40.126.32.72
  • 20.190.160.17
  • 20.190.160.2
  • 40.126.31.3
  • 40.126.31.128
  • 20.190.159.71
  • 40.126.31.129
  • 40.126.31.73
  • 20.190.159.75
  • 20.190.159.128
  • 40.126.31.131
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
www.winzip.com
  • 23.41.181.185
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
e834.d.akamaiedge.net
  • 23.41.181.185
malicious

Threats

PID
Process
Class
Message
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
7400
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
7400
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
4880
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
4880
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
4880
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
4880
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
4880
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
No debug info