URL: | https://ssesws.vivaregenera.com?l95r5sxu4=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvdjIuMC9hdXRob3JpemU%2FY2xpZW50X2lkPTQ3NjU0NDViLTMyYzYtNDliMC04M2U2LTFkOTM3NjUyNzZjYSZyZWRpcmVjdF91cmk9aHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRmxhbmRpbmd2MiZyZXNwb25zZV90eXBlPWNvZGUlMjBpZF90b2tlbiZzY29wZT1vcGVuaWQlMjBwcm9maWxlJTIwaHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRnYyJTJGT2ZmaWNlSG9tZS5BbGwmcmVzcG9uc2VfbW9kZT1mb3JtX3Bvc3Qmbm9uY2U9NjM4ODAzNDA1ODA2NjE1MjE4LlpXWXlOV0V3TWprdE9XUTJaaTAwTkRNNExXSTFNVGd0TldNNU5HUmpaRFUxTnpJMU5USmtZVGt4WWpBdE9XUXdPUzAwTnpsbExXSmhaR0l0WXpFME4ySXlaakV5TnpsbCZ1aV9sb2NhbGVzPWVuLVVTJm1rdD1lbi1VUyZjbGllbnQtcmVxdWVzdC1pZD00NTQwYzUzYS00OGY3LTRmNjYtOWE3ZC02YWUzYzAxOTQwODAmc3RhdGU9VjRqbUR4OFJlNGwxVVdBelhXbkM5ZTEtel9aelM2N0RCT2c3M0I1dzJSN3BVc1lTZ0pBdlRPbGhiMnF5WVZfdWVSN0JzamFzWHVlaVV4cmJJUndjS2FnQnhBZU5pTjFnQ04zd05PYXFleTYyZ1kwZlo4NmVsdk9MRjc0RG5IaHpjbWNoVHlsc2k3b1cyS2U4b0hRZVV3U01aRmdMUjhRTU0xVkdCWWtQZF9lNFIzUVprNnRKajdtVlhxX0xId2tKSE1EM0dwYnpRX19tSlJsM2x0TE9qc3UyeUg0Rk8zbEFWT1NYY2Y5NE9tc2VOa2g5Tm14MU0wQlBjOExMOVFZLWczTWxiaGRoeEE2OWp4aEVHcTkyUmcmeC1jbGllbnQtU0tVPUlEX05FVDhfMCZ4LWNsaWVudC12ZXI9OC41LjAuMA%3D%3D |
Full analysis: | https://app.any.run/tasks/aabf663f-122c-4a8f-a350-8f1b44457cb2 |
Verdict: | Malicious activity |
Analysis date: | April 15, 2025, 19:12:50 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Tags: | |
MD5: | 885516A482DA37AFEC2F91031932A442 |
SHA1: | DD3E7F27959F9B9CD04801C839BE91E0A62E18A2 |
SHA256: | 179812FD006C3187B2A3D9ED2E43276D03858B05E4B492691DD62EE6121D0625 |
SSDEEP: | 24:2p38iXhNQGL93yAkzHviTlAIXKHfHmSJ57Dmj:U38SNQBzxvJZSj |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4800 | RUXIMICS.exe | GET | 200 | 184.24.77.37:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.24.77.37:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.24.77.37:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 302 | 192.0.78.27:443 | https://ssesws.vivaregenera.com/?l95r5sxu4=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvdjIuMC9hdXRob3JpemU%2FY2xpZW50X2lkPTQ3NjU0NDViLTMyYzYtNDliMC04M2U2LTFkOTM3NjUyNzZjYSZyZWRpcmVjdF91cmk9aHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRmxhbmRpbmd2MiZyZXNwb25zZV90eXBlPWNvZGUlMjBpZF90b2tlbiZzY29wZT1vcGVuaWQlMjBwcm9maWxlJTIwaHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRnYyJTJGT2ZmaWNlSG9tZS5BbGwmcmVzcG9uc2VfbW9kZT1mb3JtX3Bvc3Qmbm9uY2U9NjM4ODAzNDA1ODA2NjE1MjE4LlpXWXlOV0V3TWprdE9XUTJaaTAwTkRNNExXSTFNVGd0TldNNU5HUmpaRFUxTnpJMU5USmtZVGt4WWpBdE9XUXdPUzAwTnpsbExXSmhaR0l0WXpFME4ySXlaakV5TnpsbCZ1aV9sb2NhbGVzPWVuLVVTJm1rdD1lbi1VUyZjbGllbnQtcmVxdWVzdC1pZD00NTQwYzUzYS00OGY3LTRmNjYtOWE3ZC02YWUzYzAxOTQwODAmc3RhdGU9VjRqbUR4OFJlNGwxVVdBelhXbkM5ZTEtel9aelM2N0RCT2c3M0I1dzJSN3BVc1lTZ0pBdlRPbGhiMnF5WVZfdWVSN0JzamFzWHVlaVV4cmJJUndjS2FnQnhBZU5pTjFnQ04zd05PYXFleTYyZ1kwZlo4NmVsdk9MRjc0RG5IaHpjbWNoVHlsc2k3b1cyS2U4b0hRZVV3U01aRmdMUjhRTU0xVkdCWWtQZF9lNFIzUVprNnRKajdtVlhxX0xId2tKSE1EM0dwYnpRX19tSlJsM2x0TE9qc3UyeUg0Rk8zbEFWT1NYY2Y5NE9tc2VOa2g5Tm14MU0wQlBjOExMOVFZLWczTWxiaGRoeEE2OWp4aEVHcTkyUmcmeC1jbGllbnQtU0tVPUlEX05FVDhfMCZ4LWNsaWVudC12ZXI9OC41LjAuMA%3D%3D | unknown | — | — | — |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4800 | RUXIMICS.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 404 | 23.215.0.136:443 | https://example.com/favicon.ico | unknown | — | — | — |
— | — | GET | — | 13.107.246.45:443 | https://xpaywalletcdn.azureedge.net/mswallet/ExpressCheckout/v2/GetEligibleSites?version=0&type=dafSite&IsStable=false | unknown | — | — | — |
— | — | POST | 200 | 20.190.160.132:443 | https://login.live.com/RST2.srf | unknown | xml | 1.24 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 239.255.255.250:1900 | — | — | — | whitelisted |
4800 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3584 | svchost.exe | 20.190.159.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4800 | RUXIMICS.exe | 184.24.77.37:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.24.77.37:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 104.168.69.104:443 | ssesws.vivaregenera.com | AS-COLOCROSSING | US | unknown |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4800 | RUXIMICS.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 95.100.186.9:443 | go.microsoft.com | AKAMAI-AS | FR | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
ssesws.vivaregenera.com |
| unknown |
www.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
href.li |
| whitelisted |
www.bing.com |
| whitelisted |
example.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Domain chain identified as Phishing (hrefexamlpe) |
— | — | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Domain chain identified as Phishing (hrefexamlpe) |