File name:

FurMark_1.17.0.0_Setup.exe

Full analysis: https://app.any.run/tasks/2721c348-4556-41ec-8025-50e79e251434
Verdict: Malicious activity
Analysis date: February 13, 2024, 00:32:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

06D1F2BD3018BFDF91945F573ECA7682

SHA1:

4D63FC29D4908AD762614B4CB6224B64F429008C

SHA256:

F8F41C17711CB01AF34518DB4C9DBFC333B9D8F49620BDFF45BD5E44B7B55A01

SSDEEP:

98304:Yzggc3H5zLXC5nZ0RQj4akIP31dgf2pHT6Xj49K+63OdZJ2H+HB7Zwh9IAICqlmc:xp1PcHcOcu6N9BqNZLP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FurMark_1.17.0.0_Setup.exe (PID: 4052)
      • FurMark_1.17.0.0_Setup.exe (PID: 2752)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • FurMark_1.17.0.0_Setup.exe (PID: 2752)
      • FurMark_1.17.0.0_Setup.exe (PID: 4052)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Process drops legitimate windows executable

      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Reads the Windows owner or organization settings

      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Reads the Internet Settings

      • FurMark_1.17.0.0_Setup.tmp (PID: 3656)
      • FurMark.exe (PID: 4008)
    • Reads security settings of Internet Explorer

      • FurMark.exe (PID: 4008)
  • INFO

    • Checks supported languages

      • FurMark_1.17.0.0_Setup.tmp (PID: 3656)
      • FurMark_1.17.0.0_Setup.exe (PID: 4052)
      • FurMark_1.17.0.0_Setup.exe (PID: 2752)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
      • FurMark.exe (PID: 4008)
      • cpuburner.exe (PID: 3000)
    • Reads the computer name

      • FurMark_1.17.0.0_Setup.tmp (PID: 3656)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
      • FurMark.exe (PID: 4008)
    • Create files in a temporary directory

      • FurMark_1.17.0.0_Setup.exe (PID: 4052)
      • FurMark_1.17.0.0_Setup.exe (PID: 2752)
      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Creates files in the program directory

      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Application launched itself

      • msedge.exe (PID: 1836)
      • msedge.exe (PID: 920)
    • Reads CPU info

      • FurMark.exe (PID: 4008)
    • Creates files or folders in the user directory

      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
    • Creates a software uninstall entry

      • FurMark_1.17.0.0_Setup.tmp (PID: 3848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (71.1)
.exe | Win32 Executable Delphi generic (9.1)
.scr | Windows screen saver (8.4)
.dll | Win32 Dynamic Link Library (generic) (4.2)
.exe | Win32 Executable (generic) (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 40448
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xa5f8
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.17.0.0
ProductVersionNumber: 1.17.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Geeks3D
FileDescription: FurMark Setup
FileVersion: 1.17.0.0
LegalCopyright:
ProductName: FurMark
ProductVersion: 1.17.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
31
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start furmark_1.17.0.0_setup.exe furmark_1.17.0.0_setup.tmp no specs furmark_1.17.0.0_setup.exe furmark_1.17.0.0_setup.tmp furmark.exe msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs cpuburner.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4496 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
784"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xdc,0x6a88f598,0x6a88f5a8,0x6a88f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
848"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1420 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
920"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.ozone3d.net/redirect.php?id=201C:\Program Files\Microsoft\Edge\Application\msedge.exeFurMark.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
948"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=3520 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
952"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3496 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1192"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3772 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1572"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2212 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1604"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4540 --field-trial-handle=1392,i,17316801494481387486,8916566158248781029,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1836"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.ozone3d.net/redirect.php?id=201C:\Program Files\Microsoft\Edge\Application\msedge.exe
FurMark_1.17.0.0_Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 718
Read events
10 630
Write events
76
Delete events
12

Modification events

(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
080F000096357F2F145EDA01
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
EC1BB10FE682F1FF96995A3B1F0FEE5723046CE32AD1B2D6BF7DBD6CD96DCD70
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\Geeks3D\Benchmarks\FurMark\core3d.dll
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
0773EF0B22DBEF110AF75C4B63E9F5AD54D94E41976DAEC93E01351AAA1B6170
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.5 (a)
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\Geeks3D\Benchmarks\FurMark
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Geeks3D\Benchmarks\FurMark\
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
Geeks3D\Benchmarks\FurMark
(PID) Process:(3848) FurMark_1.17.0.0_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
19
Suspicious files
55
Text files
55
Unknown types
47

Dropped files

PID
Process
Filename
Type
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\core3d.dllexecutable
MD5:035ED540B59FA630AB4DECC7550EEA8D
SHA256:234EB0E494F3C688A372D8627F74F4E4D573132E99AC252FF75D8B3153C69B72
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\is-CKTAQ.tmptext
MD5:7D2690B4D6D7DD53D69A773664BC4850
SHA256:37F80B2998523E0E780CBAB2774E1EE7EB4B7945F1FF232F5ECE22CE037B6282
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\EULA.txttext
MD5:437355A61054204B195FFD5956F4BE67
SHA256:2B13E3B7C487732A74F42D3250F0D6BAC153F59D62D59BC7ABA35A2677369DD3
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\is-VIR34.tmpexecutable
MD5:035ED540B59FA630AB4DECC7550EEA8D
SHA256:234EB0E494F3C688A372D8627F74F4E4D573132E99AC252FF75D8B3153C69B72
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\freeimage-license.txttext
MD5:7D2690B4D6D7DD53D69A773664BC4850
SHA256:37F80B2998523E0E780CBAB2774E1EE7EB4B7945F1FF232F5ECE22CE037B6282
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\furmark-gpu-monitoring.csvbinary
MD5:7C8B9C1B29097525A81307273327662B
SHA256:CF90740D55DB6AC13FEAABE6ADB3AF018C7931E3B46B5FDFEA41207ED627EB98
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\is-K4S60.tmpexecutable
MD5:CB1C50B16863E835371A2A8FCEA3A653
SHA256:A2ED0DD0A52847645A05A2C61F64284CB5CBEFA9CD8E168AF5E8C6138EF7FE4B
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\is-7M0M6.tmpbinary
MD5:7C8B9C1B29097525A81307273327662B
SHA256:CF90740D55DB6AC13FEAABE6ADB3AF018C7931E3B46B5FDFEA41207ED627EB98
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\is-64S1J.tmpexecutable
MD5:01D32EB253D5DC3D33C508397B2A4EF8
SHA256:41DF514CCC10B5169D2CB72100646CEBD4D83A0A10BAF4E0D269FEDDE084FBFA
3848FurMark_1.17.0.0_Setup.tmpC:\Program Files\Geeks3D\Benchmarks\FurMark\is-62IGC.tmpxml
MD5:2D724BF3F3DE895E6C9E0FC5DD0C11E8
SHA256:B635F4008732E871D06BE99845B9D6D77CB4E5D81BB73E185B2ED2305DD2C1E4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
41
DNS requests
43
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
848
msedge.exe
GET
302
83.166.138.97:80
http://www.ozone3d.net/redirect.php?id=201
unknown
unknown
4008
FurMark.exe
GET
200
83.166.138.97:80
http://www.ozone3d.net/benchmarks/fur/furmark_version.php
unknown
text
34 b
unknown
848
msedge.exe
GET
302
83.166.138.97:80
http://www.ozone3d.net/redirect.php?id=201
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
848
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1836
msedge.exe
239.255.255.250:1900
unknown
848
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4008
FurMark.exe
83.166.138.97:80
www.ozone3d.net
Infomaniak Network SA
CH
unknown
848
msedge.exe
83.166.138.97:80
www.ozone3d.net
Infomaniak Network SA
CH
unknown
848
msedge.exe
195.15.220.232:443
geeks3d.com
Infomaniak Network SA
CH
unknown
848
msedge.exe
172.217.18.106:443
fonts.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.ozone3d.net
  • 83.166.138.97
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
geeks3d.com
  • 195.15.220.232
whitelisted
fonts.googleapis.com
  • 172.217.18.106
whitelisted
fonts.gstatic.com
  • 142.250.185.227
whitelisted
www.google.com
  • 142.250.181.228
whitelisted
www.geeks3d.com
  • 195.15.220.232
unknown
pagead2.googlesyndication.com
  • 142.250.186.34
whitelisted
secure.gravatar.com
  • 192.0.73.2
whitelisted

Threats

No threats detected
Process
Message
msedge.exe
[0213/003342.850:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)