URL:

https://disk.yandex.ru/d/0vyJHV8BFOjs4w

Full analysis: https://app.any.run/tasks/8d82393b-c0ed-4bca-9b04-63b3db2419b1
Verdict: Malicious activity
Analysis date: January 16, 2026, 09:47:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MD5:

BF06A264E34D30F0264BD80E627D863A

SHA1:

83B24B8092A7F565907C6BFD7909BA3D3F130216

SHA256:

EBD7B0FBB77E2FCF2E48D9A64021B5CAE912CC7437B8CA2B1872FCDDED880095

SSDEEP:

3:N8U26eBdWN:2U26eB0N

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • firefox.exe (PID: 4080)
  • SUSPICIOUS

    • The process executes via Task Scheduler

      • ctfmon.exe (PID: 1596)
      • sipnotify.exe (PID: 1676)
      • sipnotify.exe (PID: 1452)
      • ctfmon.exe (PID: 1468)
    • There is functionality for taking screenshot (YARA)

      • ToxidPP.exe (PID: 2712)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 1676)
      • runonce.exe (PID: 2060)
      • sipnotify.exe (PID: 1452)
      • runonce.exe (PID: 120)
    • Application launched itself

      • WerFault.exe (PID: 2100)
      • WerFault.exe (PID: 2056)
    • Likely accesses (executes) a file from the Public directory

      • msedge.exe (PID: 2820)
  • INFO

    • Drops script file

      • msedge.exe (PID: 1544)
      • sipnotify.exe (PID: 1676)
      • sipnotify.exe (PID: 1452)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1244)
      • msedge.exe (PID: 2820)
    • Manual execution by a user

      • ToxidPP.exe (PID: 2712)
      • runonce.exe (PID: 2060)
      • IMEKLMG.EXE (PID: 2184)
      • IMEKLMG.EXE (PID: 2200)
      • ToxidPP.exe (PID: 2388)
      • ToxidPP.exe (PID: 2512)
      • ToxidPP.exe (PID: 3088)
      • runonce.exe (PID: 120)
      • IMEKLMG.EXE (PID: 2172)
      • IMEKLMG.EXE (PID: 2180)
      • ToxidPP.exe (PID: 2668)
      • chrome.exe (PID: 2760)
      • rundll32.exe (PID: 2740)
      • msedge.exe (PID: 2820)
    • Application launched itself

      • msedge.exe (PID: 1544)
      • chrome.exe (PID: 2760)
      • msedge.exe (PID: 2820)
    • Reads the machine GUID from the registry

      • ToxidPP.exe (PID: 2712)
      • ToxidPP.exe (PID: 2512)
      • ToxidPP.exe (PID: 2668)
      • ToxidPP.exe (PID: 3088)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 1544)
      • msedge.exe (PID: 2820)
    • Reads the time zone

      • runonce.exe (PID: 2060)
      • runonce.exe (PID: 120)
    • Create files in a temporary directory

      • WerFault.exe (PID: 2108)
      • WerFault.exe (PID: 2064)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 2060)
      • runonce.exe (PID: 120)
    • Reads the computer name

      • ToxidPP.exe (PID: 2712)
      • IMEKLMG.EXE (PID: 2200)
      • IMEKLMG.EXE (PID: 2184)
      • ToxidPP.exe (PID: 3088)
      • ToxidPP.exe (PID: 2512)
      • IMEKLMG.EXE (PID: 2180)
      • IMEKLMG.EXE (PID: 2172)
      • ToxidPP.exe (PID: 2668)
    • Checks supported languages

      • IMEKLMG.EXE (PID: 2184)
      • IMEKLMG.EXE (PID: 2200)
      • ToxidPP.exe (PID: 2512)
      • ToxidPP.exe (PID: 3088)
      • ToxidPP.exe (PID: 2712)
      • IMEKLMG.EXE (PID: 2180)
      • IMEKLMG.EXE (PID: 2172)
      • ToxidPP.exe (PID: 2668)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 2184)
      • IMEKLMG.EXE (PID: 2200)
      • IMEKLMG.EXE (PID: 2180)
      • IMEKLMG.EXE (PID: 2172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
198
Monitored processes
64
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe toxidpp.exe ctfmon.exe no specs sipnotify.exe runonce.exe werfault.exe no specs werfault.exe no specs imeklmg.exe no specs imeklmg.exe no specs toxidpp.exe no specs toxidpp.exe toxidpp.exe sipnotify.exe ctfmon.exe no specs runonce.exe werfault.exe no specs werfault.exe no specs imeklmg.exe no specs imeklmg.exe no specs toxidpp.exe rundll32.exe no specs chrome.exe chrome.exe no specs msedge.exe msedge.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs chrome.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120runonce.exe /ExplorerC:\Windows\System32\runonce.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Run Once Wrapper
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\runonce.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1060"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1420 --field-trial-handle=1324,i,6843703658406747363,17758698046489756471,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1244"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\ToxidPP.zip"C:\Program Files\WinRAR\WinRAR.exe
msedge.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1452C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1468C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1544"C:\Program Files\Microsoft\Edge\Application\msedge.exe" "https://disk.yandex.ru/d/0vyJHV8BFOjs4w"C:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1556"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1628 --field-trial-handle=1324,i,6843703658406747363,17758698046489756471,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1564"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2300 --field-trial-handle=1324,i,6843703658406747363,17758698046489756471,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1596C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1676C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
7 881
Read events
7 789
Write events
79
Delete events
13

Modification events

(PID) Process:(1244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1244) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\ToxidPP.zip
(PID) Process:(1244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
15
Suspicious files
125
Text files
212
Unknown types
3

Dropped files

PID
Process
Filename
Type
1544msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF10f06d.TMP
MD5:
SHA256:
1544msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
1544msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF10f0bb.TMP
MD5:
SHA256:
1544msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
1544msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF10f176.TMP
MD5:
SHA256:
1544msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
1544msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.datbinary
MD5:C71FF4D3A6085C165C6A9C908C072A09
SHA256:3CA7B7E98B5CA1C1DC458415463D00ACD9DF8302F481B103C93177FD2642B37B
2832msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\CrashpadMetrics.pma~RF10ecc3.TMPbinary
MD5:C612E96CBFAC63232FC2062E15600FB1
SHA256:DB3C05D5EC0B6719A73E7F0BE84BCE9342772DA70567E7CE08CF6573480B38FF
1544msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\LOG.old~RF10f09b.TMPtext
MD5:DA58A5ED5A650FE47BBFB2CA6C156D15
SHA256:A4C01ECF5D00CEE3AC9724408BD58DE8C54A620EF3BFEE44979E965F206598A4
1544msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\aeda8906-de86-4e72-aabd-2fc06b005da2.tmpbinary
MD5:5058F1AF8388633F609CADB75A75DC9D
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
76
TCP/UDP connections
47
DNS requests
45
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1060
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/109.0.1518.115?clientId=-626569875466424637&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig%2CEdgeDomainActions&osname=win&client=edge&channel=stable&scpfull=0&scpguard=1&scpfre=0&scpver=18&osarch=x86&osver=6.1.7601&wu=0&devicefamily=desktop&uma=1&sessionid=16&mngd=0&installdate=1604373552&edu=0&bphint=0
US
text
37.0 Kb
unknown
1060
msedge.exe
GET
200
150.171.28.11:443
https://edge.microsoft.com/serviceexperimentation/v2/
US
text
132 b
whitelisted
1060
msedge.exe
GET
200
37.9.64.225:443
https://yastatic.net/s3/disk/_/react-dom.16.14.0.min.js
RS
text
114 Kb
unknown
1060
msedge.exe
GET
200
87.250.250.50:443
https://disk.yandex.ru/d/0vyJHV8BFOjs4w
RS
html
46.6 Kb
unknown
1060
msedge.exe
GET
200
37.9.64.225:443
https://yastatic.net/s3/psf/disk-public/_/public.ru.e5ed268b3f363e0a26dc.js
RS
text
128 Kb
unknown
1060
msedge.exe
GET
200
37.9.64.225:443
https://yastatic.net/s3/disk/_/react.16.14.0.min.js
RS
text
11.9 Kb
unknown
1060
msedge.exe
GET
200
37.9.64.225:443
https://yastatic.net/s3/psf/disk-public/_/public.e5ed268b3f363e0a26dc.css
RS
text
128 Kb
unknown
1060
msedge.exe
GET
200
77.88.21.119:443
https://mc.yandex.ru/metrika/watch.js
RS
text
128 Kb
unknown
1060
msedge.exe
GET
200
37.9.64.225:443
https://yastatic.net/s3/psf/disk-public/_/6b4d8053b90691296ecd.svg
RS
image
4.27 Kb
unknown
1060
msedge.exe
GET
200
37.9.64.225:443
https://yastatic.net/s3/psf/remote-global-bar/1_0_3/client/styles.css
RS
text
84.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
224.0.0.252:5355
whitelisted
1092
svchost.exe
224.0.0.252:5355
whitelisted
1544
msedge.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
1060
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1060
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1060
msedge.exe
87.250.250.50:443
disk.yandex.ru
TELETECH
RS
whitelisted
1060
msedge.exe
37.9.64.225:443
yastatic.net
TELETECH
RS
whitelisted
1060
msedge.exe
77.88.21.119:443
mc.yandex.ru
TELETECH
RS
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.78
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
disk.yandex.ru
  • 87.250.250.50
whitelisted
yastatic.net
  • 37.9.64.225
whitelisted
mc.yandex.ru
  • 77.88.21.119
  • 87.250.251.119
  • 87.250.250.119
whitelisted
docviewer.yandex.ru
  • 77.88.21.148
whitelisted
csp.yandex.net
  • 87.250.250.104
whitelisted
yandex.ru
  • 77.88.44.55
  • 5.255.255.77
  • 77.88.55.88
whitelisted
www.bing.com
  • 2.16.204.153
  • 2.16.204.161
  • 2.16.204.155
  • 2.16.204.160
  • 2.16.204.159
  • 2.16.204.156
  • 2.16.204.157
  • 2.16.204.134
  • 2.16.204.158
  • 2.16.204.132
  • 2.16.204.135
  • 2.16.204.136
whitelisted

Threats

No threats detected
No debug info