File name:

Screenshot.jpg

Full analysis: https://app.any.run/tasks/5026c1b7-1a07-4e72-892e-2ebd84f87206
Verdict: Malicious activity
Analysis date: May 20, 2022, 19:35:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: image/jpeg
File info: JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 1366x768, frames 3
MD5:

A5D3C962FCDB7CF3EAAE53245A7FEA18

SHA1:

2A5536AFC47E5E2BB767A2A1C7AEB09A26735686

SHA256:

E9E763F458C47F97873F6B1B9B16D4DDA2C54E8FBBF5195D681CDD4A98AC4762

SSDEEP:

3072:OcHtMr8nAOFFJ0pC3YktS9E823U1d7t/qYbWaf0:OmpPFMd9E8LqYbWas

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • reg.exe (PID: 3096)
  • SUSPICIOUS

    • Checks supported languages

      • Skype.exe (PID: 3848)
      • Skype.exe (PID: 3464)
      • Skype.exe (PID: 3988)
      • Skype.exe (PID: 3048)
      • Skype.exe (PID: 2968)
      • Skype.exe (PID: 2856)
      • Skype.exe (PID: 1328)
      • Skype.exe (PID: 2584)
    • Reads the computer name

      • Skype.exe (PID: 3848)
      • Skype.exe (PID: 3048)
      • Skype.exe (PID: 3464)
      • Skype.exe (PID: 3988)
      • Skype.exe (PID: 2584)
      • Skype.exe (PID: 2968)
      • Skype.exe (PID: 1328)
      • Skype.exe (PID: 2856)
    • Application launched itself

      • Skype.exe (PID: 3848)
      • Skype.exe (PID: 3048)
      • Skype.exe (PID: 2584)
    • Changes default file association

      • Skype.exe (PID: 3848)
    • Reads CPU info

      • Skype.exe (PID: 3848)
    • Uses REG.EXE to modify Windows registry

      • Skype.exe (PID: 3848)
    • Creates files in the user directory

      • Skype.exe (PID: 3848)
      • Skype.exe (PID: 2584)
      • Skype.exe (PID: 3048)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 1592)
  • INFO

    • Manual execution by user

      • Skype.exe (PID: 3848)
      • chrome.exe (PID: 1592)
    • Checks supported languages

      • reg.exe (PID: 3128)
      • rundll32.exe (PID: 2972)
      • reg.exe (PID: 3096)
      • chrome.exe (PID: 1592)
      • chrome.exe (PID: 2528)
      • chrome.exe (PID: 2424)
      • chrome.exe (PID: 2044)
      • chrome.exe (PID: 2576)
      • chrome.exe (PID: 3632)
      • chrome.exe (PID: 3760)
      • chrome.exe (PID: 984)
      • chrome.exe (PID: 3444)
      • chrome.exe (PID: 3640)
      • chrome.exe (PID: 4044)
      • chrome.exe (PID: 3880)
      • chrome.exe (PID: 1024)
      • chrome.exe (PID: 3016)
      • chrome.exe (PID: 3216)
      • chrome.exe (PID: 2184)
      • chrome.exe (PID: 3352)
      • chrome.exe (PID: 984)
      • chrome.exe (PID: 2432)
      • chrome.exe (PID: 976)
      • chrome.exe (PID: 3540)
      • chrome.exe (PID: 292)
      • chrome.exe (PID: 3640)
      • chrome.exe (PID: 1008)
      • chrome.exe (PID: 2816)
      • chrome.exe (PID: 2612)
    • Reads the hosts file

      • Skype.exe (PID: 3848)
      • chrome.exe (PID: 1592)
      • chrome.exe (PID: 2576)
    • Dropped object may contain Bitcoin addresses

      • Skype.exe (PID: 3848)
    • Reads settings of System Certificates

      • Skype.exe (PID: 3848)
      • chrome.exe (PID: 2576)
    • Reads the computer name

      • chrome.exe (PID: 1592)
      • chrome.exe (PID: 3444)
      • chrome.exe (PID: 2528)
      • chrome.exe (PID: 2576)
      • chrome.exe (PID: 3760)
      • chrome.exe (PID: 3640)
    • Application launched itself

      • chrome.exe (PID: 1592)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jpg | JFIF-EXIF JPEG Bitmap (38.4)
.jpg | JFIF JPEG bitmap (30.7)
.jpg | JPEG bitmap (23)
.mp3 | MP3 audio (7.6)

EXIF

Composite

Megapixels: 1
ImageSize: 1366x768

JFIF

YResolution: 96
XResolution: 96
ResolutionUnit: inches
JFIFVersion: 1.01
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
73
Monitored processes
37
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rundll32.exe no specs skype.exe skype.exe reg.exe skype.exe no specs reg.exe no specs skype.exe skype.exe no specs skype.exe skype.exe no specs skype.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1120,5345561059230425667,11587029880971019320,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3268 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
976"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1120,5345561059230425667,11587029880971019320,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=3496 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\version.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
984"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1120,5345561059230425667,11587029880971019320,131072 --enable-features=PasswordImport --lang=en-US --instant-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1888 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
984"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1120,5345561059230425667,11587029880971019320,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=22 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3408 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1008"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1120,5345561059230425667,11587029880971019320,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=24 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3504 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1024"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1120,5345561059230425667,11587029880971019320,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=3676 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shlwapi.dll
1328"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --ms-disable-indexeddb-transaction-timeout --no-sandbox --disable-databases --service-pipe-token=AE4B6B263FA94965DC6F002C52CA99B3 --lang=en-US --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar\WebViewPreload.js" --guest-instance-id=1 --enable-blink-features --disable-blink-features --context-id=2 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=AE4B6B263FA94965DC6F002C52CA99B3 --renderer-client-id=6 --mojo-platform-channel-handle=2764 /prefetch:1C:\Program Files\Microsoft\Skype for Desktop\Skype.exeSkype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Exit code:
0
Version:
8.29.0.50
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft\skype for desktop\skype.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
1592"C:\Program Files\Google\Chrome\Application\chrome.exe" C:\Program Files\Google\Chrome\Application\chrome.exe
Explorer.EXE
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2044"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1120,5345561059230425667,11587029880971019320,131072 --enable-features=PasswordImport --lang=en-US --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2304 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2184"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1120,5345561059230425667,11587029880971019320,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2408 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
Total events
17 608
Read events
17 507
Write events
99
Delete events
2

Modification events

(PID) Process:(2972) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
rundll32.exe
(PID) Process:(3096) reg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Skype for Desktop
Value:
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
(PID) Process:(3848) Skype.exeKey:HKEY_CLASSES_ROOT\skype
Operation:writeName:URL Protocol
Value:
(PID) Process:(3848) Skype.exeKey:HKEY_CLASSES_ROOT\skype
Operation:writeName:(default)
Value:
URL:skype
(PID) Process:(3848) Skype.exeKey:HKEY_CLASSES_ROOT\skype\shell\open\command
Operation:writeName:(default)
Value:
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" -- "%1"
(PID) Process:(3848) Skype.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1592) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1592) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(1592) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(1592) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
Executable files
0
Suspicious files
214
Text files
126
Unknown types
15

Dropped files

PID
Process
Filename
Type
3848Skype.exeC:\Users\admin\AppData\Local\Temp\90eb000d-bd92-454b-8af8-6d911e38fcdf.tmp.ico
MD5:
SHA256:
3848Skype.exeC:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
MD5:
SHA256:
3848Skype.exeC:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
MD5:
SHA256:
3848Skype.exeC:\Users\admin\AppData\Local\Temp\4bdd2e2f-5539-4d32-8aed-e24a9d354b4d.tmp.ico
MD5:
SHA256:
1592chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-6287EDAE-638.pma
MD5:
SHA256:
3848Skype.exeC:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.jsonbinary
MD5:
SHA256:
3848Skype.exeC:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000005compressed
MD5:
SHA256:
3848Skype.exeC:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOGtext
MD5:
SHA256:
3988Skype.exeC:\Users\admin\AppData\Local\Temp\skype-preview Crashes\operation_log.txttext
MD5:
SHA256:
3848Skype.exeC:\Users\admin\AppData\Local\Temp\4bdd2e2f-5539-4d32-8aed-e24a9d354b4d.tmpimage
MD5:E946D0929470B5E6006FE9BCE06171D2
SHA256:5D9C38BD132DFAE94C31B1ACFFE170C6B8C8988C53557B89CAAF8870DF34C8C9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
84
DNS requests
64
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2576
chrome.exe
GET
200
2.16.107.82:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e4158fa950820914
unknown
compressed
60.0 Kb
whitelisted
2576
chrome.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx
US
crx
242 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3848
Skype.exe
13.107.43.16:443
a.config.skype.com
Microsoft Corporation
US
whitelisted
3848
Skype.exe
13.89.178.26:443
pipe.skype.com
Microsoft Corporation
US
whitelisted
192.229.221.185:443
logincdn.msauth.net
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3848
Skype.exe
40.126.32.136:443
login.live.com
Microsoft Corporation
US
suspicious
2576
chrome.exe
142.250.185.77:443
accounts.google.com
Google Inc.
US
suspicious
3848
Skype.exe
192.229.221.185:443
logincdn.msauth.net
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2576
chrome.exe
142.250.185.67:443
www.gstatic.com
Google Inc.
US
whitelisted
2576
chrome.exe
142.250.186.65:443
clients2.googleusercontent.com
Google Inc.
US
whitelisted
2576
chrome.exe
142.250.185.228:443
www.google.com
Google Inc.
US
whitelisted
2576
chrome.exe
142.251.36.106:443
fonts.googleapis.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
get.skype.com
  • 52.174.193.75
whitelisted
a.config.skype.com
  • 13.107.43.16
whitelisted
pipe.skype.com
  • 13.89.178.26
whitelisted
download.skype.com
  • 104.102.28.183
whitelisted
bot-framework.azureedge.net
  • 152.199.19.160
whitelisted
config.edge.skype.com
  • 13.107.42.16
malicious
login.live.com
  • 40.126.32.136
  • 40.126.32.72
  • 40.126.32.134
  • 20.190.160.22
  • 20.190.160.20
  • 40.126.32.138
  • 20.190.160.17
  • 20.190.160.14
whitelisted
logincdn.msauth.net
  • 192.229.221.185
malicious
accounts.google.com
  • 142.250.185.77
shared
www.google.com
  • 142.250.185.228
malicious

Threats

No threats detected
Process
Message
Skype.exe
[3464:3476:0520/203557.767:VERBOSE1:crash_service_main.cc(78)] Session start. cmdline is [--reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1]
Skype.exe
[3464:3476:0520/203557.767:VERBOSE1:crash_service.cc(145)] window handle is 0003012A
Skype.exe
[3464:3476:0520/203557.767:VERBOSE1:crash_service.cc(300)] pipe name is \\.\pipe\skype-preview Crash Service dumps at C:\Users\admin\AppData\Local\Temp\skype-preview Crashes
Skype.exe
[3464:3476:0520/203557.767:VERBOSE1:crash_service.cc(304)] checkpoint is C:\Users\admin\AppData\Local\Temp\skype-preview Crashes\crash_checkpoint.txt server is https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload maximum 128 reports/day reporter is electron-crash-service
Skype.exe
[3464:3476:0520/203557.767:VERBOSE1:crash_service_main.cc(94)] Ready to process crash requests
Skype.exe
[3464:2756:0520/203557.767:VERBOSE1:crash_service.cc(333)] client start. pid = 3848
Skype.exe
[3464:2756:0520/203559.844:VERBOSE1:crash_service.cc(333)] client start. pid = 3048
Skype.exe
[3988:4000:0520/203559.912:VERBOSE1:crash_service_main.cc(78)] Session start. cmdline is [--reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1]
Skype.exe
[3988:4000:0520/203559.917:VERBOSE1:crash_service.cc(145)] window handle is 0001014C
Skype.exe
[3988:4000:0520/203559.917:VERBOSE1:crash_service.cc(300)] pipe name is \\.\pipe\skype-preview Crash Service dumps at C:\Users\admin\AppData\Local\Temp\skype-preview Crashes