File name:

SecuriteInfo.com.W32.PossibleThreat.20282.14864

Full analysis: https://app.any.run/tasks/3cbde78b-d355-4f28-b7d8-9cddd95c078f
Verdict: Malicious activity
Analysis date: September 12, 2024, 18:25:07
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
themida
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

7268329D169F985BE48D34007C4FD957

SHA1:

C44B9BBB1A384B146E758316532164DF963BDB50

SHA256:

F1CE6D3956C9EC05C7FDC5CC58828B62E698D9A9B27733B2DF03166F9242F2A3

SSDEEP:

98304:uB0GWjcvPtB/rXaAUBxfRq+zfVg3zGNLgMDIeZ6h8HbYCpjo7kUPsTJsS+cms3wL:uyycaz48

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
    • The process creates files with name similar to system file names

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
    • Creates a software uninstall entry

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 6444)
    • Reads security settings of Internet Explorer

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
      • BlackBerryBackupExtractor.exe (PID: 1840)
    • Executable content was dropped or overwritten

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
    • Starts CMD.EXE for commands execution

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 6952)
    • Reads the BIOS version

      • BlackBerryBackupExtractor.exe (PID: 1840)
  • INFO

    • Checks supported languages

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
      • BlackBerryBackupExtractor.exe (PID: 1840)
      • identity_helper.exe (PID: 8068)
    • Creates files or folders in the user directory

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
    • Reads the computer name

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
      • BlackBerryBackupExtractor.exe (PID: 1840)
      • identity_helper.exe (PID: 8068)
    • Create files in a temporary directory

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
    • The process uses the downloaded file

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
      • explorer.exe (PID: 6016)
    • Process checks computer location settings

      • SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 7116)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 6016)
    • Sends debugging messages

      • BlackBerryBackupExtractor.exe (PID: 1840)
    • Disables trace logs

      • BlackBerryBackupExtractor.exe (PID: 1840)
    • Reads the software policy settings

      • BlackBerryBackupExtractor.exe (PID: 1840)
    • Reads the machine GUID from the registry

      • BlackBerryBackupExtractor.exe (PID: 1840)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 232)
      • msedge.exe (PID: 3812)
    • Checks proxy server information

      • BlackBerryBackupExtractor.exe (PID: 1840)
    • Themida protector has been detected

      • BlackBerryBackupExtractor.exe (PID: 1840)
    • Reads Environment values

      • identity_helper.exe (PID: 8068)
    • Application launched itself

      • msedge.exe (PID: 3812)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:58:45+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 186880
UninitializedDataSize: 2048
EntryPoint: 0x3665
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.8.5
ProductVersionNumber: 2.0.8.5
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Reincubate Software Ltd
FileDescription: BlackBerry Backup Extractor installer
FileVersion: 2.0.8.5
LegalCopyright: Copyright (c) Reincubate Software Ltd
ProductName: BlackBerry Backup Extractor
ProductVersion: 2.0.8.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
195
Monitored processes
64
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start securiteinfo.com.w32.possiblethreat.20282.14864.exe cmd.exe no specs conhost.exe no specs taskkill.exe no specs explorer.exe no specs explorer.exe no specs THREAT blackberrybackupextractor.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs securiteinfo.com.w32.possiblethreat.20282.14864.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
232"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=3020 --field-trial-handle=2492,i,5366557303529563511,2122809557553974140,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
888"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6664 --field-trial-handle=2492,i,5366557303529563511,2122809557553974140,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=45 --mojo-platform-channel-handle=7308 --field-trial-handle=2492,i,5366557303529563511,2122809557553974140,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1148"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=7784 --field-trial-handle=2492,i,5366557303529563511,2122809557553974140,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1840"C:\Users\admin\AppData\Roaming\Reincubate\BlackBerry Backup Extractor\BlackBerryBackupExtractor.exe" C:\Users\admin\AppData\Roaming\Reincubate\BlackBerry Backup Extractor\BlackBerryBackupExtractor.exe
explorer.exe
User:
admin
Company:
Reincubate Software Ltd
Integrity Level:
MEDIUM
Description:
BlackBerry Backup Extractor
Version:
2.0.8.5
Modules
Images
c:\users\admin\appdata\roaming\reincubate\blackberry backup extractor\blackberrybackupextractor.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.3636_none_c0df324c38bbc0ce\comctl32.dll
2396"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2488 --field-trial-handle=2492,i,5366557303529563511,2122809557553974140,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2520"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=7724 --field-trial-handle=2492,i,5366557303529563511,2122809557553974140,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2584taskkill /f /im "BlackBerryBackupExtractor.exe"C:\Windows\SysWOW64\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3584"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3032 --field-trial-handle=2492,i,5366557303529563511,2122809557553974140,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3812"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.blackberryconverter.com/help-howto-and-support/?utm_source=app&utm_campaign=2.0.8.5C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
BlackBerryBackupExtractor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
9 041
Read events
8 981
Write events
60
Delete events
0

Modification events

(PID) Process:(7116) SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlackBerry Backup Extractor
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Roaming\Reincubate\BlackBerry Backup Extractor\BlackBerryBackupExtractor-uninstaller.exe"
(PID) Process:(7116) SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlackBerry Backup Extractor
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\Reincubate\BlackBerry Backup Extractor\BlackBerryBackupExtractor.exe
(PID) Process:(7116) SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlackBerry Backup Extractor
Operation:writeName:DisplayName
Value:
BlackBerry Backup Extractor
(PID) Process:(7116) SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlackBerry Backup Extractor
Operation:writeName:DisplayVersion
Value:
2.0.8.5
(PID) Process:(7116) SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlackBerry Backup Extractor
Operation:writeName:Version
Value:
2.0.8.5
(PID) Process:(7116) SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlackBerry Backup Extractor
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\Reincubate\BlackBerry Backup Extractor
(PID) Process:(7116) SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlackBerry Backup Extractor
Operation:writeName:Publisher
Value:
Reincubate Software Ltd
(PID) Process:(7116) SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlackBerry Backup Extractor
Operation:writeName:InstallDate
Value:
20240912
(PID) Process:(7116) SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlackBerry Backup Extractor
Operation:writeName:EstimatedSize
Value:
2773
(PID) Process:(7116) SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
Operation:writeName:Droid Sans (TrueType)
Value:
DroidSans.ttf
Executable files
43
Suspicious files
284
Text files
76
Unknown types
1

Dropped files

PID
Process
Filename
Type
7116SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeC:\Windows\Fonts\DroidSans.ttfbinary
MD5:205EF3CF1E8C6B008BC74EC0D287199E
SHA256:12F0210759B1716B822043A6179047EF5F751A793ABBFDA150B566AE57D83F68
7116SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeC:\Users\admin\AppData\Local\Temp\nscB754.tmp\LangDLL.dllexecutable
MD5:68B287F4067BA013E34A1339AFDB1EA8
SHA256:18E8B40BA22C7A1687BD16E8D585380BC2773FFF5002D7D67E9485FCC0C51026
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.datbinary
MD5:04E3F29A62D8BFE314652697DE334A9C
SHA256:62F1F368DA991B1B7964570CBE0C0D6F6ADAB80A628C139B8DB54D1FB71D5A16
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Last Versiontext
MD5:C7E2197BAE099B13BBB3ADEB1433487D
SHA256:3460EEAF45D581DD43A6E4E17AF8102DDAFF5AEAA88B10099527CF85211629E9
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\40281d8c-a30e-4adf-b3dc-e52f51f7a614.tmpbinary
MD5:5982BE4755C421C19162DA9009EACD5C
SHA256:B5987DFC678B363B51C39514711725844FC1E02831367F6AEA50366B8860FC35
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Variationsbinary
MD5:16B7586B9EBA5296EA04B791FC3D675E
SHA256:474D668707F1CB929FEF1E3798B71B632E50675BD1A9DCEAAB90C9587F72F680
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF12f97b.TMP
MD5:
SHA256:
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7116SecuriteInfo.com.W32.PossibleThreat.20282.14864.exeC:\Users\admin\AppData\Local\Temp\nswB60B.tmpbinary
MD5:C83A97178B92EBFBA03616B612469672
SHA256:2A60B230818467D8C538D4DEFE222402CB6520404FEE8B212C405E5095BED50E
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF12f94c.TMPbinary
MD5:091D54DC6EA0818B4A7C9764FD859B6A
SHA256:3255E791AA8DA5FAE81EB54281E095B0FE80DC642C55CD14BF634A2D6A5CF4A2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
107
DNS requests
117
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3424
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1076
svchost.exe
HEAD
200
2.19.126.157:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ea79963f-51af-4930-ab74-50e807a8950b?P1=1726546772&P2=404&P3=2&P4=FYSJC9P9u8a3OaSH639A1Cmss7LgIX%2bi2dnVfCX%2bOcfFye3BL%2bQjCHMW%2bt1%2bGuXveP%2bj6RiPzGSCcuXGxxa9hw%3d%3d
unknown
whitelisted
7448
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7448
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1076
svchost.exe
GET
206
2.19.126.157:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ea79963f-51af-4930-ab74-50e807a8950b?P1=1726546772&P2=404&P3=2&P4=FYSJC9P9u8a3OaSH639A1Cmss7LgIX%2bi2dnVfCX%2bOcfFye3BL%2bQjCHMW%2bt1%2bGuXveP%2bj6RiPzGSCcuXGxxa9hw%3d%3d
unknown
whitelisted
1076
svchost.exe
GET
206
2.19.126.157:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ea79963f-51af-4930-ab74-50e807a8950b?P1=1726546772&P2=404&P3=2&P4=FYSJC9P9u8a3OaSH639A1Cmss7LgIX%2bi2dnVfCX%2bOcfFye3BL%2bQjCHMW%2bt1%2bGuXveP%2bj6RiPzGSCcuXGxxa9hw%3d%3d
unknown
whitelisted
1076
svchost.exe
GET
206
2.19.126.157:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ea79963f-51af-4930-ab74-50e807a8950b?P1=1726546772&P2=404&P3=2&P4=FYSJC9P9u8a3OaSH639A1Cmss7LgIX%2bi2dnVfCX%2bOcfFye3BL%2bQjCHMW%2bt1%2bGuXveP%2bj6RiPzGSCcuXGxxa9hw%3d%3d
unknown
whitelisted
1076
svchost.exe
GET
206
2.19.126.157:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ea79963f-51af-4930-ab74-50e807a8950b?P1=1726546772&P2=404&P3=2&P4=FYSJC9P9u8a3OaSH639A1Cmss7LgIX%2bi2dnVfCX%2bOcfFye3BL%2bQjCHMW%2bt1%2bGuXveP%2bj6RiPzGSCcuXGxxa9hw%3d%3d
unknown
whitelisted
1076
svchost.exe
GET
206
2.19.126.157:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ea79963f-51af-4930-ab74-50e807a8950b?P1=1726546772&P2=404&P3=2&P4=FYSJC9P9u8a3OaSH639A1Cmss7LgIX%2bi2dnVfCX%2bOcfFye3BL%2bQjCHMW%2bt1%2bGuXveP%2bj6RiPzGSCcuXGxxa9hw%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1356
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6160
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3424
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3424
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 40.127.240.158
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 23.35.229.160
whitelisted
google.com
  • 216.58.206.46
whitelisted
login.live.com
  • 20.190.159.73
  • 20.190.159.4
  • 20.190.159.0
  • 20.190.159.2
  • 20.190.159.75
  • 40.126.31.73
  • 40.126.31.69
  • 20.190.159.71
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
uds.reincubate.com
  • 104.26.7.161
  • 104.26.6.161
  • 172.67.75.19
unknown
config.edge.skype.com
  • 52.123.243.206
  • 52.123.243.201
  • 52.123.243.89
whitelisted
www.blackberryconverter.com
  • 172.67.205.48
  • 104.21.66.145
unknown
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted

Threats

PID
Process
Class
Message
232
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
232
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
232
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
232
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
Process
Message
BlackBerryBackupExtractor.exe
%s------------------------------------------------ --- Themida Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------