File name:

BonziBuddy432.exe

Full analysis: https://app.any.run/tasks/484fb0d3-e502-4ab4-a9d1-44e297579190
Verdict: Malicious activity
Analysis date: July 31, 2024, 22:21:23
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

06D87D4C89C76CB1BCB2F5A5FC4097D1

SHA1:

657248F78ABFA9015B77C431F2FD8797481478FD

SHA256:

F1E859D99072E35F20E172D8458E3EA1BAF8BA86C8C9E311A0DEBCD2ACD5D0FC

SSDEEP:

393216:57nfCfPI3z6/pu9rk+G1k7Nx6OcOXni2wEv9tjap0g9E0g9g/fhYSuK:5yPwu/Erk+eSNYOcGP/8N9m9gXhnuK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BonziBuddy432.exe (PID: 7024)
  • SUSPICIOUS

    • Creates a software uninstall entry

      • BonziBuddy432.exe (PID: 7024)
    • Executable content was dropped or overwritten

      • BonziBuddy432.exe (PID: 7024)
    • Reads security settings of Internet Explorer

      • BonziBuddy432.exe (PID: 7024)
    • Creates/Modifies COM task schedule object

      • BonziBuddy432.exe (PID: 7024)
    • Process drops legitimate windows executable

      • BonziBuddy432.exe (PID: 7024)
  • INFO

    • Creates files in the program directory

      • BonziBuddy432.exe (PID: 7024)
    • Creates files or folders in the user directory

      • BonziBuddy432.exe (PID: 7024)
    • Checks supported languages

      • BonziBuddy432.exe (PID: 7024)
      • identity_helper.exe (PID: 3076)
      • identity_helper.exe (PID: 6168)
      • BonziBDY_2.EXE (PID: 5992)
      • BonziBDY_35.EXE (PID: 6456)
      • TextInputHost.exe (PID: 5144)
      • BonziBDY_2.EXE (PID: 2224)
    • Reads Environment values

      • identity_helper.exe (PID: 3076)
      • identity_helper.exe (PID: 6168)
    • Application launched itself

      • msedge.exe (PID: 6032)
      • msedge.exe (PID: 7136)
      • msedge.exe (PID: 812)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 7136)
      • BonziBuddy432.exe (PID: 7024)
      • msedge.exe (PID: 6032)
      • msedge.exe (PID: 812)
    • Manual execution by a user

      • msedge.exe (PID: 6032)
      • BonziBDY_35.EXE (PID: 6456)
      • BonziBDY_2.EXE (PID: 5992)
      • BonziBDY_2.EXE (PID: 2224)
    • Create files in a temporary directory

      • BonziBuddy432.exe (PID: 7024)
    • Reads the computer name

      • BonziBuddy432.exe (PID: 7024)
      • identity_helper.exe (PID: 3076)
      • identity_helper.exe (PID: 6168)
      • BonziBDY_2.EXE (PID: 5992)
      • BonziBDY_35.EXE (PID: 6456)
      • TextInputHost.exe (PID: 5144)
      • BonziBDY_2.EXE (PID: 2224)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (49.2)
.exe | Win32 Executable Delphi generic (16.2)
.scr | Windows screen saver (14.9)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 101376
InitializedDataSize: 20480
UninitializedDataSize: -
EntryPoint: 0x19b64
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: -
CompanyName: Bonzi Software
FileDescription: BonziBuddy432 4 Installation
FileVersion: 4
LegalCopyright: Bonzi Software
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
176
Monitored processes
56
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bonzibuddy432.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs bonzibdy_2.exe no specs bonzibdy_35.exe no specs textinputhost.exe no specs bonzibdy_2.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs bonzibuddy432.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2332 --field-trial-handle=2328,i,510336077744247546,14211038112866045332,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
420"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=788 --field-trial-handle=2356,i,15223133091440942465,10955052404592320104,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
532"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2532 --field-trial-handle=2404,i,8719529887726456607,12963316618280954746,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
812"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-windowC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
904"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --mojo-platform-channel-handle=6844 --field-trial-handle=2328,i,510336077744247546,14211038112866045332,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
904"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4088 --field-trial-handle=2356,i,15223133091440942465,10955052404592320104,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1104"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5524 --field-trial-handle=2356,i,15223133091440942465,10955052404592320104,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1236"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3992 --field-trial-handle=2356,i,15223133091440942465,10955052404592320104,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1640"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x324,0x328,0x32c,0x31c,0x334,0x7fffd4775fd8,0x7fffd4775fe4,0x7fffd4775ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1644"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6524 --field-trial-handle=2328,i,510336077744247546,14211038112866045332,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
18 943
Read events
18 650
Write events
291
Delete events
2

Modification events

(PID) Process:(7024) BonziBuddy432.exeKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BONZIBUDDY\Add-ons\StorybookReader
Operation:writeName:Path
Value:
C:\Program Files (x86)\BonziBuddy432
(PID) Process:(7024) BonziBuddy432.exeKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BONZIBUDDY\Add-ons\StorybookReader\Books
Operation:writeName:Bonz and the Polizoof
Value:
C:\Program Files (x86)\BonziBuddy432\Books\Bonz and the Polizoof\
(PID) Process:(7024) BonziBuddy432.exeKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BONZIBUDDY\Add-ons\StorybookReader\Books
Operation:writeName:Bonzi and the Alpha-net
Value:
C:\Program Files (x86)\BonziBuddy432\BonziBuddy\Books\Bonzi and the Alpha-net\
(PID) Process:(7024) BonziBuddy432.exeKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BONZIBUDDY\Add-ons\StorybookReader\Books
Operation:writeName:Bonz and the Treasure Chest
Value:
C:\Program Files (x86)\BonziBuddy432\BonziBuddy\Books\Bonz and the Treasure Chest\
(PID) Process:(7024) BonziBuddy432.exeKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BONZIBUDDY\Add-ons\StorybookReader\Books
Operation:writeName:Bonzi and the Internet
Value:
C:\Program Files (x86)\BonziBuddy432\Books\BonziBuddy\Bonzi and the Internet\
(PID) Process:(7024) BonziBuddy432.exeKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BONZIBUDDY\Add-ons\StorybookReader\Options
Operation:writeName:UseGlobalSettings
Value:
True
(PID) Process:(7024) BonziBuddy432.exeKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BONZIBUDDY\Add-ons\StorybookReader\Options
Operation:writeName:ActionBack
Value:
1
(PID) Process:(7024) BonziBuddy432.exeKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BONZIBUDDY\Add-ons\StorybookReader\Options
Operation:writeName:ActionGlobal
Value:
1
(PID) Process:(7024) BonziBuddy432.exeKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BONZIBUDDY\Add-ons\StorybookReader\Options
Operation:writeName:ActionNext
Value:
1
(PID) Process:(7024) BonziBuddy432.exeKey:HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\BONZIBUDDY\Add-ons\StorybookReader\Options
Operation:writeName:ActionOpen
Value:
1
Executable files
12
Suspicious files
207
Text files
100
Unknown types
10

Dropped files

PID
Process
Filename
Type
7024BonziBuddy432.exeC:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmp
MD5:
SHA256:
7024BonziBuddy432.exeC:\Program Files (x86)\BonziBuddy432\ActiveSkin.ocxexecutable
MD5:3D225D8435666C14ADDF17C14806C355
SHA256:2C8F92DC16CBF13542DDD3BF0A947CF84B00FED83A7124B830DDEFA92F939877
7024BonziBuddy432.exeC:\Users\admin\AppData\Local\Temp\$inst\16.tmptext
MD5:38851B1E45D75C5A7489188440C23BA8
SHA256:F783ADE814F65F9E750ACBB0BD27312CBFC86D699EDFA2C77773C67094C11FC8
7024BonziBuddy432.exeC:\Users\admin\AppData\Local\Temp\$inst\7.tmpimage
MD5:420AEE57B5E083D256D28E45EF887ADB
SHA256:1EFB1A8831F68B443A3E3A06599E914162DC1A9B1B8F9EBC8020B40B72BBFB80
7024BonziBuddy432.exeC:\Users\admin\AppData\Local\Temp\$inst\2.tmpcompressed
MD5:4B332A1B235922A7870595ABEF346CB6
SHA256:4690EA1B97998F45A2BD991085DFB08177DD074BEC58A9E07B61E3ED721BEDCE
7024BonziBuddy432.exeC:\Program Files (x86)\BonziBuddy432\AUTPRX32.DLLexecutable
MD5:6E62806F4121EED119EF7D361F3322CA
SHA256:0563E77B6BD63EB0561F6264BADB5D07DACB7287CE029DC3CA3279A964EA6A6D
7024BonziBuddy432.exeC:\Program Files (x86)\BonziBuddy432\BonziBDY.vbwtext
MD5:B4D876161A7ABB7BCAEA37003DAE158F
SHA256:4DD98F95113B70772308A4671A482B9B59BBA5FBF41E928F2A833366C54424E4
7024BonziBuddy432.exeC:\Program Files (x86)\BonziBuddy432\BonziBUDDY_Killer.exeexecutable
MD5:913D38CB9D132C8C92B21CFF05A7EB62
SHA256:6D80BD5A3D5EC6630E9A411A978C8E2C196F530F6A5B580FA982C5AD1622BD0C
7024BonziBuddy432.exeC:\Program Files (x86)\BonziBuddy432\BonziBDY_2.EXEexecutable
MD5:8A30BD00D45A659E6E393915E5AEF701
SHA256:1E2994763A7674A0F1EC117DAE562B05B614937FF61C83B316B135AFAB02D45A
7024BonziBuddy432.exeC:\Program Files (x86)\BonziBuddy432\BonziCTB.dllexecutable
MD5:6A4C7D730AED29B0405B03E128C1655A
SHA256:F85525A3EBE334F7403F031EC47C2B32461650224223EE728107DCE0E879EA93
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
165
TCP/UDP connections
79
DNS requests
72
Threats
29

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
401
13.107.6.158:443
https://business.bing.com/api/v1/user/token/microsoftgraph?&clienttype=edge-omnibox
unknown
GET
104.21.78.241:443
https://bonzibuddy.tk/
unknown
5092
msedge.exe
GET
301
104.21.78.241:80
http://bonzibuddy.tk/
unknown
unknown
GET
304
13.107.21.239:443
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
unknown
GET
304
13.107.42.16:443
https://config.edge.skype.com/config/v1/Edge/122.0.2365.59?clientId=4489578223053569932&agents=EdgeRuntime%2CEdgeRuntimeConfig%2CEdgeDomainActions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=39&mngd=0&installdate=1661339457&edu=0&bphint=2&soobedate=1504771245&fg=1
unknown
GET
104.21.78.241:443
https://bonzibuddy.tk/
unknown
HEAD
200
23.53.42.162:443
https://assets.msn.com/statics/icons/favicon.ico
unknown
GET
200
13.107.246.67:443
https://edge-mobile-static.azureedge.net/eccp/get?settenant=edge-config&setplatform=win&setmkt=en-US&setchannel=stable
unknown
binary
12.6 Kb
POST
204
92.123.104.31:443
https://www.bing.com/threshold/xls.aspx
unknown
GET
200
204.79.197.239:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=122.0.2365.59&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
unknown
binary
479 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5092
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6032
msedge.exe
239.255.255.250:1900
whitelisted
5092
msedge.exe
13.107.246.67:443
edge-mobile-static.azureedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
5092
msedge.exe
13.107.6.158:443
business.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5092
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.46
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
bonzibuddy.tk
  • 104.21.78.241
  • 172.67.138.185
unknown
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.67
whitelisted
www.bing.com
  • 92.123.104.31
  • 92.123.104.32
  • 92.123.104.34
  • 92.123.104.33
whitelisted
edgeservices.bing.com
  • 92.123.104.34
  • 92.123.104.31
  • 92.123.104.33
  • 92.123.104.32
whitelisted
ntp.msn.com
  • 204.79.197.203
whitelisted

Threats

PID
Process
Class
Message
5092
msedge.exe
Potentially Bad Traffic
ET DNS Query to a .tk domain - Likely Hostile
5092
msedge.exe
Potentially Bad Traffic
ET DNS Query to a .tk domain - Likely Hostile
5092
msedge.exe
Potentially Bad Traffic
ET DNS Query to a .tk domain - Likely Hostile
5092
msedge.exe
Potentially Bad Traffic
ET DNS Query to a .tk domain - Likely Hostile
Generic Protocol Command Decode
SURICATA HTTP Request abnormal Content-Encoding header
Potentially Bad Traffic
ET POLICY HTTP Request to a *.tk domain
Generic Protocol Command Decode
SURICATA HTTP Request abnormal Content-Encoding header
Generic Protocol Command Decode
SURICATA HTTP Request abnormal Content-Encoding header
Generic Protocol Command Decode
SURICATA HTTP Request abnormal Content-Encoding header
5092
msedge.exe
Potentially Bad Traffic
ET POLICY HTTP Request to a *.tk domain
2 ETPRO signatures available at the full report
No debug info