| URL: | gmailc.com |
| Full analysis: | https://app.any.run/tasks/c59f5dce-5c5e-41c3-94e6-0e2411f02be9 |
| Verdict: | Malicious activity |
| Analysis date: | July 24, 2025, 20:29:36 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 16811D5F9CE6536BF94A9352826046E0 |
| SHA1: | CCAB79AAC74B9986D176257BA1191D0D4EF5576B |
| SHA256: | FB943637C354A7123B20F1D561FB4B74B83CE2010F3825639367E474AA6EBCB8 |
| SSDEEP: | 3:5hKIn:55 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 320 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=18 --always-read-main-dll --field-trial-handle=5952,i,397767658143710367,4102107004631372060,262144 --variations-seed-version --mojo-platform-channel-handle=5384 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 620 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5608,i,397767658143710367,4102107004631372060,262144 --variations-seed-version --mojo-platform-channel-handle=7148 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 828 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6708,i,397767658143710367,4102107004631372060,262144 --variations-seed-version --mojo-platform-channel-handle=6832 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1800 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2712,i,397767658143710367,4102107004631372060,262144 --variations-seed-version --mojo-platform-channel-handle=2720 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2232 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --from-ie-to-edge=8 -- "http://gmailc.com/" | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2680 | "C:\Program Files\Internet Explorer\iexplore.exe" "gmailc.com" | C:\Program Files\Internet Explorer\iexplore.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 11.00.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3688 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5576,i,397767658143710367,4102107004631372060,262144 --variations-seed-version --mojo-platform-channel-handle=1304 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 3876 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4240,i,397767658143710367,4102107004631372060,262144 --variations-seed-version --mojo-platform-channel-handle=4276 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 3932 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2304,i,397767658143710367,4102107004631372060,262144 --variations-seed-version --mojo-platform-channel-handle=2292 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 3964 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3596,i,397767658143710367,4102107004631372060,262144 --variations-seed-version --mojo-platform-channel-handle=3456 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| (PID) Process: | (2680) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2680) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2680) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2680) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2680) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (2680) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | DisableFirstRunCustomize |
Value: 1 | |||
| (PID) Process: | (2232) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2232) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2232) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2232) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF18d8e6.TMP | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF18d905.TMP | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF18d925.TMP | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF18d925.TMP | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF18d925.TMP | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6304 | msedge.exe | GET | 200 | 64.190.63.136:80 | http://ww1.gmailc.com/?usid=106&utid=d08f880c2c60e19ac0e4afd07a41fa2f | unknown | — | — | unknown |
6304 | msedge.exe | GET | 200 | 150.171.27.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:JlgX9RiePmaWOazjxvxU6VY_4bnoAWKM9ofHkJ_3Ruk&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | unknown | — | — | whitelisted |
6956 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6304 | msedge.exe | GET | 200 | 64.190.63.136:80 | http://ww1.gmailc.com/search/tsc.php?ses=ogcKZWd7prE-M4Z9fRzgeHf1M_2TuHUk8b3fVB_51FXinAJ5XhWNtuiAYUJrf7Cbtn3VHVrhPD5ZEO6C624861y50z2pplVHHz2kz0sp-vFGwFJwo7F1dlNqs0p38yCe0dJWY2zZ2x5Xj3DD0gbgrZUg3myRjm8dFjv9Spu_EFWr28avTRQMabdza7ey9q4BxQi_YVfso6eweOxZr1tzxkVwTQDA08FGKqvZP-RwIp49xX8cemUvL5iMpGrf4H53onZ7YSDiUkC6QTJ-CkJ0AhzhHmU-BKYw8--1MZnR2hK9ytYvNDxK0kaIViqDIB7OC0Qq4CKWu869716njrZOxdJBE3v6hOvBdZPhLAGFt4qGyGwi2H2M95azu7uxQ&cv=2 | unknown | — | — | unknown |
6304 | msedge.exe | GET | 441 | 64.190.63.136:80 | http://ww1.gmailc.com/img.sedoparking.com/images/js_preloader.gif | unknown | — | — | unknown |
6304 | msedge.exe | GET | 441 | 64.190.63.136:80 | http://ww1.gmailc.com/img.sedoparking.com/images/js_preloader.gif | unknown | — | — | unknown |
6304 | msedge.exe | GET | 302 | 64.190.63.136:80 | http://ww1.gmailc.com/search/redirect.php?f=http%3A%2F%2Fxml.sedodna.com%2Fclick%3Fi%3DCcrLUHG83tI_0&v=MTFmZDdjZTY1YWFlMjQ0ZjM0MTEzZTQ5NDhiMWY0ZmIJMQl3dzEuZ21haWxjLmNvbTY4ODI5N2JjNDI4ZjE5LjY0MzU3ODI0CXd3MS5nbWFpbGMuY29tNjg4Mjk3YmM0Mjk0YzEuNjIzMzgwNDkJMTc1MzM4ODk5MAlhZF82M18w&l=ogcycCWu4PG189VGdjdddIEAfMlczAmmgbqhF5pQu6BB_7TztQ9BXIyuRzbHYRoM0ymDSlb0aKAl0YwB32-qhidhylXQz-CnhsOSRgokkyOUQgsN597pqZFl5mysU2_vYYnBlO2Ver-dbMWVvCI6iKoZvKTIGPBS7iTnpgSeQ4JKf834EGItNdkqXvm6MdMV-koIKoBOVi8lMc49y5OiZVWBZZpglOXbe2CQcLKL4vdcJ25Z4d6Pnpqaf8lVOn3dYBhA0ceWvmRx7gqt4C-UQxQW34SQQzPXv1iPoq3q1rkzlJjyetB_jjgoQqzoSav60ofP4fP8dvVI0nhrjeFcog1_M9Y-xGFkod_W-SIKfeiidfWcDYHDzHA6hYZWRUVAmcu8ar4hV0xPWyDgTDKKsfKrzCX_T8USmOBVsT7odBRu7DP_81wdVEYgRRSuQCsAcSxxq6hA97eHQkYkHabDH2ANurD_PttKtkFQWNnzzOALor50UzB8XALNocOg09P_c8oLWFGcFvtV_DnBJoYSk7ik5MWiXnORxCkWB4n0b4BnGFkrdF4aiI1HHe0YnU4oPVRpQuAN-m7IbVsiwhUJbPZQWN6b8nW8MJJNgCpwOBV3eu5afGmTOmdmKKJZGWzgX9yokCfj0IKPAb8veX0dYmNcUbyfJTU0fSrFY-uZTAT7LNFNIHeoQX8L9NZ_RxLY3JS | unknown | — | — | unknown |
6304 | msedge.exe | GET | 302 | 64.190.63.136:80 | http://ww1.gmailc.com/search/tcerider.php?f=http%3A%2F%2Fxml.sedodna.com%2Fclick%3Fi%3DCcrLUHG83tI_0&v=MTFmZDdjZTY1YWFlMjQ0ZjM0MTEzZTQ5NDhiMWY0ZmIJMQl3dzEuZ21haWxjLmNvbTY4ODI5N2JjNDI4ZjE5LjY0MzU3ODI0CXd3MS5nbWFpbGMuY29tNjg4Mjk3YmM0Mjk0YzEuNjIzMzgwNDkJMTc1MzM4ODk5MAlhZF82M18w&l=ogcycCWu4PG189VGdjdddIEAfMlczAmmgbqhF5pQu6BB_7TztQ9BXIyuRzbHYRoM0ymDSlb0aKAl0YwB32-qhidhylXQz-CnhsOSRgokkyOUQgsN597pqZFl5mysU2_vYYnBlO2Ver-dbMWVvCI6iKoZvKTIGPBS7iTnpgSeQ4JKf834EGItNdkqXvm6MdMV-koIKoBOVi8lMc49y5OiZVWBZZpglOXbe2CQcLKL4vdcJ25Z4d6Pnpqaf8lVOn3dYBhA0ceWvmRx7gqt4C-UQxQW34SQQzPXv1iPoq3q1rkzlJjyetB_jjgoQqzoSav60ofP4fP8dvVI0nhrjeFcog1_M9Y-xGFkod_W-SIKfeiidfWcDYHDzHA6hYZWRUVAmcu8ar4hV0xPWyDgTDKKsfKrzCX_T8USmOBVsT7odBRu7DP_81wdVEYgRRSuQCsAcSxxq6hA97eHQkYkHabDH2ANurD_PttKtkFQWNnzzOALor50UzB8XALNocOg09P_c8oLWFGcFvtV_DnBJoYSk7ik5MWiXnORxCkWB4n0b4BnGFkrdF4aiI1HHe0YnU4oPVRpQuAN-m7IbVsiwhUJbPZQWN6b8nW8MJJNgCpwOBV3eu5afGmTOmdmKKJZGWzgX9yokCfj0IKPAb8veX0dYmNcUbyfJTU0fSrFY-uZTAT7LNFNIHeoQX8L9NZ_RxLY3JS | unknown | — | — | unknown |
1268 | svchost.exe | GET | 200 | 2.16.168.124:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1268 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2632 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6304 | msedge.exe | 150.171.22.17:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6304 | msedge.exe | 150.171.27.11:80 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6304 | msedge.exe | 150.171.28.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6304 | msedge.exe | 2.23.227.211:443 | copilot.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
6304 | msedge.exe | 172.233.219.78:443 | gmailc.com | Akamai International B.V. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
gmailc.com |
| unknown |
copilot.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
router.parklogic.com |
| unknown |
ww1.gmailc.com |
| unknown |
login.live.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET INFO Referrer-Policy set to unsafe-url |
6304 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Suspected Phishing Domain (attacheatableoverlabor .com) |
— | — | Potentially Bad Traffic | ET INFO Possible Chrome Plugin install |