File name:

infected.rar

Full analysis: https://app.any.run/tasks/d3e127e9-e5db-450e-9aef-ebbc7f267528
Verdict: Malicious activity
Threats:

Rhadamanthys is a C++ information-stealing malware that extracts sensitive data from infiltrated machines. Its layered operational chain and advanced evasion tactics make it a major risk in cybersecurity landscapes.

Analysis date: May 28, 2025, 08:40:55
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
rust
stealer
rhadamanthys
shellcode
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

5FF5B7F67282F540C70BF31E3CD947A9

SHA1:

D6675703B04F0DB7FABA84468006C7DF76BDE4EC

SHA256:

ED95A5E92E0D83ADF370B5CB57145ADF8E8F6164AAAC461F651C5B6BF3214757

SSDEEP:

98304:drEGmqt6SBOZuKr3ufQPixY2VG5OKNIPlsph1wsndTQLMTWlsHOI1AiLOydsQCo/:VOryYm1aKjFKZyeJl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • OOBE-Maintenance.exe (PID: 1052)
    • RHADAMANTHYS has been detected (YARA)

      • OOBE-Maintenance.exe (PID: 1052)
    • Scans artifacts that could help determine the target

      • msedge.exe (PID: 6148)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 5556)
      • msedge.exe (PID: 6148)
    • There is functionality for taking screenshot (YARA)

      • Documentación en la investigación.exe (PID: 8008)
      • Documentación en la investigación.exe (PID: 8060)
      • Documentación en la investigación.exe (PID: 8104)
      • Documentación en la investigación.exe (PID: 5408)
      • Documentación en la investigación.exe (PID: 4120)
      • Documentación en la investigación.exe (PID: 8184)
    • Application launched itself

      • Documentación en la investigación.exe (PID: 8008)
      • Documentación en la investigación.exe (PID: 8104)
      • Documentación en la investigación.exe (PID: 5408)
    • Executes application which crashes

      • Documentación en la investigación.exe (PID: 8060)
      • Documentación en la investigación.exe (PID: 8184)
      • Documentación en la investigación.exe (PID: 4120)
    • The process checks if it is being run in the virtual environment

      • OpenWith.exe (PID: 6640)
    • Connects to unusual port

      • OpenWith.exe (PID: 6640)
      • OOBE-Maintenance.exe (PID: 1052)
    • Multiple wallet extension IDs have been found

      • OOBE-Maintenance.exe (PID: 1052)
    • Loads DLL from Mozilla Firefox

      • OOBE-Maintenance.exe (PID: 1052)
    • Reads Mozilla Firefox installation path

      • msedge.exe (PID: 6148)
    • Searches for installed software

      • OOBE-Maintenance.exe (PID: 1052)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 5556)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5556)
    • Checks supported languages

      • Documentación en la investigación.exe (PID: 8008)
      • Documentación en la investigación.exe (PID: 8060)
      • Documentación en la investigación.exe (PID: 8104)
      • Documentación en la investigación.exe (PID: 5408)
      • Documentación en la investigación.exe (PID: 8184)
      • chrome.exe (PID: 2904)
      • Documentación en la investigación.exe (PID: 4120)
      • msedge.exe (PID: 6148)
    • Application based on Rust

      • Documentación en la investigación.exe (PID: 8008)
      • Documentación en la investigación.exe (PID: 8104)
      • Documentación en la investigación.exe (PID: 5408)
    • Manual execution by a user

      • Documentación en la investigación.exe (PID: 8104)
      • Documentación en la investigación.exe (PID: 5408)
      • OpenWith.exe (PID: 6640)
      • OOBE-Maintenance.exe (PID: 1052)
    • Reads the software policy settings

      • slui.exe (PID: 7280)
      • slui.exe (PID: 8144)
    • Reads Environment values

      • chrome.exe (PID: 2904)
      • msedge.exe (PID: 6148)
    • Reads the computer name

      • chrome.exe (PID: 2904)
      • msedge.exe (PID: 6148)
    • Reads the machine GUID from the registry

      • chrome.exe (PID: 2904)
      • msedge.exe (PID: 6148)
    • Process checks computer location settings

      • chrome.exe (PID: 2904)
      • msedge.exe (PID: 6148)
    • Create files in a temporary directory

      • chrome.exe (PID: 2904)
      • msedge.exe (PID: 6148)
      • OOBE-Maintenance.exe (PID: 1052)
    • Application launched itself

      • chrome.exe (PID: 2904)
      • msedge.exe (PID: 6148)
    • Checks proxy server information

      • chrome.exe (PID: 2904)
      • msedge.exe (PID: 6148)
      • slui.exe (PID: 8144)
    • Process checks whether UAC notifications are on

      • msedge.exe (PID: 6148)
    • Creates files or folders in the user directory

      • msedge.exe (PID: 6148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 2315834
UncompressedSize: 6365288
OperatingSystem: Win32
ArchivedFileName: Documentación en la investigación.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
185
Monitored processes
48
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe documentación en la investigación.exe no specs documentación en la investigación.exe documentación en la investigación.exe no specs slui.exe documentación en la investigación.exe documentación en la investigación.exe no specs openwith.exe werfault.exe no specs documentación en la investigación.exe #RHADAMANTHYS oobe-maintenance.exe conhost.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs werfault.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs werfault.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --no-appcompat-clear --mojo-platform-channel-handle=5160 --field-trial-handle=2068,i,9048300384969281125,2086661360083877867,262144 --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1052"C:\WINDOWS\system32\OOBE-Maintenance.exe"C:\Windows\System32\OOBE-Maintenance.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
OOBE-Maintenance
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\oobe-maintenance.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shcore.dll
1128C:\WINDOWS\SysWOW64\WerFault.exe -u -p 8184 -s 536C:\Windows\SysWOW64\WerFault.exeDocumentación en la investigación.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1812"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=2060 --field-trial-handle=2068,i,9048300384969281125,2086661360083877867,262144 --variations-seed-version /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3376 --field-trial-handle=2300,i,1823057486824723118,2914839988432447393,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2152C:\WINDOWS\SysWOW64\WerFault.exe -u -p 8060 -s 524C:\Windows\SysWOW64\WerFault.exeDocumentación en la investigación.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2904 --user-data-dir="C:\Users\admin\AppData\Local\Temp\chr261E.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/6d86cd34/03a0677f"C:\Program Files\Google\Chrome\Application\chrome.exe
OOBE-Maintenance.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2984"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6244 --field-trial-handle=2300,i,1823057486824723118,2914839988432447393,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3156"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=3732 --field-trial-handle=2300,i,1823057486824723118,2914839988432447393,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3796"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=5000 --field-trial-handle=2300,i,1823057486824723118,2914839988432447393,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
11 227
Read events
11 187
Write events
26
Delete events
14

Modification events

(PID) Process:(5556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(5556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(5556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(5556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\infected.rar
(PID) Process:(5556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(5556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(5556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
9
Suspicious files
210
Text files
65
Unknown types
0

Dropped files

PID
Process
Filename
Type
5556WinRAR.exeC:\Users\admin\AppData\Local\Temp\infected\oledlg.dll
MD5:
SHA256:
5556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa5556.723\oledlg.dll
MD5:
SHA256:
5556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5556.1106\oledlg.dll
MD5:
SHA256:
2904chrome.exeC:\Users\admin\AppData\Local\Temp\chr261E.tmp\Default\Code Cache\js\indexbinary
MD5:54CB446F628B2EA4A5BCE5769910512E
SHA256:FBCFE23A2ECB82B7100C50811691DDE0A33AA3DA8D176BE9882A9DB485DC0F2D
2904chrome.exeC:\Users\admin\AppData\Local\Temp\chr261E.tmp\Default\656e2160-d7bb-4906-8978-976e7fa160be.tmpbinary
MD5:5058F1AF8388633F609CADB75A75DC9D
SHA256:
5556WinRAR.exeC:\Users\admin\AppData\Local\Temp\infected\Documentación en la investigación.exeexecutable
MD5:8AF756DCF6D5093463AA53B88C773B09
SHA256:E4628593185329DAAAA0E48789E7656A25D523AA050A1645B3F7DF41615E2F61
2904chrome.exeC:\Users\admin\AppData\Local\Temp\chr261E.tmp\Local Statebinary
MD5:55DE8452DFE8CBA18A015D9278901C96
SHA256:47697F95F082C312FB573035F84AD6D2CB2C8C0C0827986C387875EF73D3F662
2904chrome.exeC:\Users\admin\AppData\Local\Temp\chr261E.tmp\Crashpad\settings.datbinary
MD5:0D600A5216739AAA26F37CE4E3F8D5D4
SHA256:9827C7D570AE868FE6D169A68F0ABCADE9CB52AED3E040D705AEEC84AF730893
2904chrome.exeC:\Users\admin\AppData\Local\Temp\chr261E.tmp\Last Versiontext
MD5:FCE53E052E5CF7C20819320F374DEA88
SHA256:CD95DE277E746E92CC2C53D9FC92A8F6F0C3EDFB7F1AD9A4E9259F927065BC89
2904chrome.exeC:\Users\admin\AppData\Local\Temp\chr261E.tmp\Default\READMEtext
MD5:883D62ACD72005F3AD7A14500D482033
SHA256:C43668EEC4A8D88A5B3A06A84F8846853FE33E54293C2DB56899A5A5DFB4D944
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
53
DNS requests
55
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7808
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7808
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7232
chrome.exe
GET
200
173.194.188.234:80
http://r5---sn-4g5ednsk.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx?cms_redirect=yes&met=1748421763,&mh=e_&mip=45.88.97.183&mm=28&mn=sn-4g5ednsk&ms=nvh&mt=1748421380&mv=m&mvi=5&pl=25&rmhost=r1---sn-4g5ednsk.gvt1.com&rms=nvh,nvh&shardbypass=sd&smhost=r4---sn-4g5edndd.gvt1.com
unknown
whitelisted
7232
chrome.exe
GET
302
216.58.206.78:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.219.150.101
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.65
  • 40.126.32.76
  • 40.126.32.138
  • 40.126.32.72
  • 20.190.160.14
  • 40.126.32.134
  • 20.190.160.4
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

PID
Process
Class
Message
6640
OpenWith.exe
Misc activity
ET INFO Cloudflare DNS Over HTTPS Certificate Inbound
No debug info