File name:

FurMark_1.17.0.0_Setup.exe

Full analysis: https://app.any.run/tasks/2721c348-4556-41ec-8025-50e79e251434
Verdict: Malicious activity
Analysis date: February 13, 2024, 00:32:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

06D1F2BD3018BFDF91945F573ECA7682

SHA1:

4D63FC29D4908AD762614B4CB6224B64F429008C

SHA256:

F8F41C17711CB01AF34518DB4C9DBFC333B9D8F49620BDFF45BD5E44B7B55A01

SSDEEP:

98304:Yzggc3H5zLXC5nZ0RQj4akIP31dgf2pHT6Xj49K+63OdZJ2H+HB7Zwh9IAICqlmc:xp1PcHcOcu6N9BqNZLP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FurMark_1.17.0.0_Setup.exe (PID: 4052)
      • FurMark_1.17.0.0_Setup.exe (PID: 2752)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • FurMark_1.17.0.0_Setup.exe (PID: 4052)
      • FurMark_1.17.0.0_Setup.exe (PID: 2752)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Process drops legitimate windows executable

      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Reads the Windows owner or organization settings

      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Reads the Internet Settings

      • FurMark.exe (PID: 4008)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3656)
    • Reads security settings of Internet Explorer

      • FurMark.exe (PID: 4008)
  • INFO

    • Checks supported languages

      • FurMark_1.17.0.0_Setup.exe (PID: 4052)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3656)
      • FurMark_1.17.0.0_Setup.exe (PID: 2752)
      • FurMark.exe (PID: 4008)
      • cpuburner.exe (PID: 3000)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Create files in a temporary directory

      • FurMark_1.17.0.0_Setup.exe (PID: 4052)
      • FurMark_1.17.0.0_Setup.exe (PID: 2752)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Reads the computer name

      • FurMark_1.17.0.0_Setup.tmp (PID: 3656)
      • FurMark.exe (PID: 4008)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Reads CPU info

      • FurMark.exe (PID: 4008)
    • Application launched itself

      • msedge.exe (PID: 1836)
      • msedge.exe (PID: 920)
    • Creates files in the program directory

      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Creates files or folders in the user directory

      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Creates a software uninstall entry

      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (71.1)
.exe | Win32 Executable Delphi generic (9.1)
.scr | Windows screen saver (8.4)
.dll | Win32 Dynamic Link Library (generic) (4.2)
.exe | Win32 Executable (generic) (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 40448
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xa5f8
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.17.0.0
ProductVersionNumber: 1.17.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Geeks3D
FileDescription: FurMark Setup
FileVersion: 1.17.0.0
LegalCopyright:
ProductName: FurMark
ProductVersion: 1.17.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
31
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start furmark_1.17.0.0_setup.exe furmark_1.17.0.0_setup.tmp no specs furmark_1.17.0.0_setup.exe furmark_1.17.0.0_setup.tmp furmark.exe msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs cpuburner.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4496 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
784"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xdc,0x6a88f598,0x6a88f5a8,0x6a88f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
848"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1420 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
920"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.ozone3d.net/redirect.php?id=201C:\Program Files\Microsoft\Edge\Application\msedge.exeFurMark.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
948"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=3520 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
952"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3496 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1192"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3772 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1572"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2212 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1604"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4540 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1836"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.ozone3d.net/redirect.php?id=201C:\Program Files\Microsoft\Edge\Application\msedge.exe
FurMark_1.17.0.0_Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 718
Read events
10 630
Write events
76
Delete events
12

Modification events

(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
080F000096357F2F145EDA01
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
EC1BB10FE682F1FF96995A3B1F0FEE5723046CE32AD1B2D6BF7DBD6CD96DCD70
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\Geeks3D\Benchmarks\FurMark\core3d.dll
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
0773EF0B22DBEF110AF75C4B63E9F5AD54D94E41976DAEC93E01351AAA1B6170
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.5 (a)
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\Geeks3D\Benchmarks\FurMark
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Geeks3D\Benchmarks\FurMark\
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
Geeks3D\Benchmarks\FurMark
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
19
Suspicious files
55
Text files
55
Unknown types
47

Dropped files

PID
Process
Filename
Type
4052FurMark_1.17.0.0_Setup.exeC:\Users\admin\AppData\Local\Temp\is-QK84F.tmp\FurMark_1.17.0.0_Setup.tmpexecutable
MD5:9303156631EE2436DB23827E27337BE4
SHA256:BAE22F27C12BCE1FAEB64B6EB733302AFF5867BAA8EED832397A7CE284A86FF4
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\cpuburner.exeexecutable
MD5:8A2A6B3AAAA5B6162C6085EDAC54D5F2
SHA256:589C0DC8076AE39E3C40FA091C8B91F748E34F7099C94BA5EBB4E0EEEFEB9019
2752FurMark_1.17.0.0_Setup.exeC:\Users\admin\AppData\Local\Temp\is-4RON2.tmp\FurMark_1.17.0.0_Setup.tmpexecutable
MD5:9303156631EE2436DB23827E27337BE4
SHA256:BAE22F27C12BCE1FAEB64B6EB733302AFF5867BAA8EED832397A7CE284A86FF4
3848FurMark_1.17.0.0_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-2CCUF.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\is-5JT21.tmpexecutable
MD5:5D8A767EC277AA29ADB517E5C4A5752D
SHA256:23AF1C71C27EE6A5A4DBEF411CD7F1183FBE716E6809408B38D62A4F8074C45D
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\unins000.exeexecutable
MD5:5D8A767EC277AA29ADB517E5C4A5752D
SHA256:23AF1C71C27EE6A5A4DBEF411CD7F1183FBE716E6809408B38D62A4F8074C45D
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\is-OT5AQ.tmptext
MD5:437355A61054204B195FFD5956F4BE67
SHA256:2B13E3B7C487732A74F42D3250F0D6BAC153F59D62D59BC7ABA35A2677369DD3
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\core3d.dllexecutable
MD5:035ED540B59FA630AB4DECC7550EEA8D
SHA256:234EB0E494F3C688A372D8627F74F4E4D573132E99AC252FF75D8B3153C69B72
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\is-33SKS.tmpexecutable
MD5:8A2A6B3AAAA5B6162C6085EDAC54D5F2
SHA256:589C0DC8076AE39E3C40FA091C8B91F748E34F7099C94BA5EBB4E0EEEFEB9019
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\EULA.txttext
MD5:437355A61054204B195FFD5956F4BE67
SHA256:2B13E3B7C487732A74F42D3250F0D6BAC153F59D62D59BC7ABA35A2677369DD3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
41
DNS requests
43
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4008
FurMark.exe
GET
200
83.166.138.97:80
http://www.ozone3d.net/benchmarks/fur/furmark_version.php
unknown
text
34 b
unknown
848
msedge.exe
GET
302
83.166.138.97:80
http://www.ozone3d.net/redirect.php?id=201
unknown
unknown
848
msedge.exe
GET
302
83.166.138.97:80
http://www.ozone3d.net/redirect.php?id=201
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
848
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1836
msedge.exe
239.255.255.250:1900
unknown
848
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4008
FurMark.exe
83.166.138.97:80
www.ozone3d.net
Infomaniak Network SA
CH
unknown
848
msedge.exe
83.166.138.97:80
www.ozone3d.net
Infomaniak Network SA
CH
unknown
848
msedge.exe
195.15.220.232:443
geeks3d.com
Infomaniak Network SA
CH
unknown
848
msedge.exe
172.217.18.106:443
fonts.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.ozone3d.net
  • 83.166.138.97
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
geeks3d.com
  • 195.15.220.232
whitelisted
fonts.googleapis.com
  • 172.217.18.106
whitelisted
fonts.gstatic.com
  • 142.250.185.227
whitelisted
www.google.com
  • 142.250.181.228
whitelisted
www.geeks3d.com
  • 195.15.220.232
unknown
pagead2.googlesyndication.com
  • 142.250.186.34
whitelisted
secure.gravatar.com
  • 192.0.73.2
whitelisted

Threats

No threats detected
Process
Message
msedge.exe
[0213/003342.850:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)