URL:

http://fastsupport.com

Full analysis: https://app.any.run/tasks/c237ee95-8c78-40ee-9739-080838fbae8e
Verdict: Malicious activity
Analysis date: January 16, 2019, 20:39:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
techsupportscam
Indicators:
MD5:

9CFA33D5FC2EB3A602E41356FBEFFC60

SHA1:

91325FD8859F7415C0B74F8F3509B5121CD6D840

SHA256:

1817EECC8CA3BD1BD2E0F1A7B0A3335E07D2B714B8AB08DB06D5D417027B8854

SSDEEP:

3:N1KYZXCBLGT:CYNILGT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • dfsvc.exe (PID: 3428)
      • g2ax_installer_customer_admin.exe (PID: 3552)
      • g2ax_service.exe (PID: 2300)
      • g2ax_installer_customer.exe (PID: 2936)
      • g2ax_service.exe (PID: 2924)
      • g2ax_service.exe (PID: 2560)
      • g2ax_comm_customer.exe (PID: 2784)
      • g2ax_system_customer.exe (PID: 1164)
      • g2ax_user_customer.exe (PID: 3408)
      • g2ax_comm_customer.exe (PID: 3916)
      • g2ax_host_service.exe (PID: 2468)
    • Changes settings of System certificates

      • StarterDotNet20.exe (PID: 2172)
      • g2ax_installer_customer_admin.exe (PID: 3552)
    • Application was dropped or rewritten from another process

      • StarterDotNet20.exe (PID: 2172)
      • GoTo Opener.exe (PID: 2640)
      • g2ax_customer_combined_dll_core_win32_x86_1610.exe (PID: 3936)
      • g2ax_installer_customer.exe (PID: 2936)
      • g2ax_installer_customer_admin.exe (PID: 2280)
      • g2ax_service.exe (PID: 2300)
      • g2ax_installer_customer_admin.exe (PID: 3552)
      • g2ax_service.exe (PID: 2560)
      • g2ax_service.exe (PID: 2924)
      • g2ax_comm_customer.exe (PID: 2784)
      • g2ax_system_customer.exe (PID: 1164)
      • g2ax_user_customer.exe (PID: 3408)
      • g2ax_host_service.exe (PID: 3960)
      • g2ax_comm_customer.exe (PID: 3916)
      • g2ax_host_service.exe (PID: 2468)
  • SUSPICIOUS

    • Creates files in the user directory

      • dfsvc.exe (PID: 3428)
      • g2ax_service.exe (PID: 2300)
    • Reads internet explorer settings

      • dfsvc.exe (PID: 3428)
    • Executable content was dropped or overwritten

      • StarterDotNet20.exe (PID: 2172)
      • dfsvc.exe (PID: 3428)
      • g2ax_customer_combined_dll_core_win32_x86_1610.exe (PID: 3936)
      • GoTo Opener.exe (PID: 2640)
      • g2ax_installer_customer_admin.exe (PID: 3552)
    • Reads Environment values

      • dfsvc.exe (PID: 3428)
    • Adds / modifies Windows certificates

      • StarterDotNet20.exe (PID: 2172)
      • g2ax_installer_customer_admin.exe (PID: 3552)
    • Creates files in the program directory

      • g2ax_installer_customer_admin.exe (PID: 3552)
      • g2ax_service.exe (PID: 2300)
    • Creates a software uninstall entry

      • g2ax_installer_customer_admin.exe (PID: 3552)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • g2ax_comm_customer.exe (PID: 2784)
    • Starts itself from another location

      • g2ax_service.exe (PID: 2560)
      • g2ax_comm_customer.exe (PID: 2784)
    • Creates files in the Windows directory

      • g2ax_comm_customer.exe (PID: 2784)
    • Connects to unusual port

      • g2ax_comm_customer.exe (PID: 2784)
    • Application launched itself

      • g2ax_comm_customer.exe (PID: 2784)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3420)
  • INFO

    • Reads internet explorer settings

      • iexplore.exe (PID: 3568)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3016)
      • GoTo Opener.exe (PID: 2640)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3016)
    • Changes internet zones settings

      • iexplore.exe (PID: 3016)
    • Creates files in the user directory

      • iexplore.exe (PID: 3568)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3028)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3016)
    • Application launched itself

      • iexplore.exe (PID: 3016)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3568)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
25
Malicious processes
9
Suspicious processes
6

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs dfsvc.exe no specs dfsvc.exe starterdotnet20.exe goto opener.exe g2ax_customer_combined_dll_core_win32_x86_1610.exe g2ax_installer_customer.exe no specs g2ax_installer_customer_admin.exe no specs g2ax_installer_customer_admin.exe g2ax_service.exe no specs g2ax_service.exe no specs g2ax_service.exe no specs g2ax_comm_customer.exe g2ax_system_customer.exe no specs g2ax_user_customer.exe no specs g2ax_comm_customer.exe no specs g2ax_host_service.exe no specs g2ax_host_service.exe no specs cmd.exe no specs tree.com no specs tree.com no specs tree.com no specs tree.com no specs

Process information

PID
CMD
Path
Indicators
Parent process
864treeC:\Windows\system32\tree.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Tree Walk Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tree.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
1164"C:\Program Files\GoToAssist Remote Support Customer\1610\g2ax_system_customer.exe" "StartID={73CB5192-5D38-4606-B4A1-C4C434ED4BBB}&ResourceDll=g2ax_customer_resource_win32_x86_en_US.dll&RunningAsService=YES&Debug=On&Stat=On&StatDb=On&Index=0"C:\Program Files\GoToAssist Remote Support Customer\1610\g2ax_system_customer.exeg2ax_comm_customer.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
GoToAssist
Exit code:
0
Version:
4.5 Build 1610
Modules
Images
c:\program files\gotoassist remote support customer\1610\g2ax_system_customer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2172"C:\Users\admin\AppData\Local\Apps\2.0\CDT43PKA.YN2\5VDE9AO5.M8R\gotoopener_45c19c863f482eb1_0002.0000_bc99f6ed9ccf2bc4\StarterDotNet20.exe"C:\Users\admin\AppData\Local\Apps\2.0\CDT43PKA.YN2\5VDE9AO5.M8R\gotoopener_45c19c863f482eb1_0002.0000_bc99f6ed9ccf2bc4\StarterDotNet20.exe
dfsvc.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
GoTo Opener
Exit code:
0
Version:
2.0.491.0
Modules
Images
c:\users\admin\appdata\local\apps\2.0\cdt43pka.yn2\5vde9ao5.m8r\gotoopener_45c19c863f482eb1_0002.0000_bc99f6ed9ccf2bc4\starterdotnet20.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2280"C:\Users\admin\AppData\Local\Temp\LogMeInInc\GoToAssist Remote Support Customer\1610\g2aD39D.tmp\g2ax_installer_customer_admin.exe" "/Action Join" "/Debug On" "/EGWAddress 216.115.218.197" "/EGWDNS egw1.express.gotoassist.com" "/EGWPort 8200,80,443" "/LoaderPath C:\Users\admin\AppData\Local\GoToAssist Remote Support Customer\g2ax_customer_combined_dll_core_win32_x86_1610.exe" "/LogLevel Normal" "/LogPath C:\Users\admin\AppData\Local\Temp\LogMeInLogs\GoToAssist Remote Support Customer\1610\20190116_204058\" "/MeetingID 804455697" "/ResourceDll g2ax_customer_resource_win32_x86_en_US.dll" "/RestartReason Start" "/ServiceAllowed Yes" "/StartAsService Yes" "/Stat On" "/StatDb On" "/UninstallService Yes" "/WebsiteUrl http://support.gotoassist.com" "/colClientUiReadyEvent Global\1B44484A-261B-45EE-ABA3-664C85EA0A6F" "/sessionTrackingId e0-PyZ8EHrdGr-xktJgQu0MWxzfWC7Xb"C:\Users\admin\AppData\Local\Temp\LogMeInInc\GoToAssist Remote Support Customer\1610\g2aD39D.tmp\g2ax_installer_customer_admin.exeg2ax_installer_customer.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
GoToAssist
Exit code:
3221226540
Version:
4.5 Build 1610
Modules
Images
c:\users\admin\appdata\local\temp\logmeininc\gotoassist remote support customer\1610\g2ad39d.tmp\g2ax_installer_customer_admin.exe
c:\systemroot\system32\ntdll.dll
2300"C:\Program Files\GoToAssist Remote Support Customer\1610\g2ax_service.exe" "Start=install_manual&Action=Join&Debug=On&EGWAddress=216.115.218.197&EGWDNS=egw1.express.gotoassist.com&EGWPort=8200,80,443&LoaderPath=C:\Users\admin\AppData\Local\GoToAssist Remote Support Customer\g2ax_customer_combined_dll_core_win32_x86_1610.exe&LogLevel=Normal&LogPath=C:\Users\admin\AppData\Local\Temp\LogMeInLogs\GoToAssist Remote Support Customer\1610\20190116_204058\&MeetingID=804455697&ResourceDll=g2ax_customer_resource_win32_x86_en_US.dll&RestartReason=Start&ServiceAllowed=Yes&StartAsService=Yes&Stat=On&StatDb=On&UninstallService=Yes&WebsiteUrl=http://support.gotoassist.com&colClientUiReadyEvent=Global\1B44484A-261B-45EE-ABA3-664C85EA0A6F&sessionTrackingId=e0-PyZ8EHrdGr-xktJgQu0MWxzfWC7Xb"C:\Program Files\GoToAssist Remote Support Customer\1610\g2ax_service.exeg2ax_installer_customer_admin.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
HIGH
Description:
GoToAssist
Exit code:
0
Version:
4.5 Build 1610
Modules
Images
c:\program files\gotoassist remote support customer\1610\g2ax_service.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2460treeC:\Windows\system32\tree.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Tree Walk Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tree.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2468"C:\Program Files\GoToAssist Remote Support Customer\1610\g2ax_host_service.exe" "Debug=On&Index=0&ResourceDll=g2ax_customer_resource_win32_x86_en_US.dll&RunningAsService=YES&StartID={45CB397D-781F-4B69-955E-7EB5F5BDC348}&Stat=On&StatDb=On"C:\Program Files\GoToAssist Remote Support Customer\1610\g2ax_host_service.exeg2ax_comm_customer.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
GoToAssist
Exit code:
0
Version:
4.5 Build 1610
Modules
Images
c:\program files\gotoassist remote support customer\1610\g2ax_host_service.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2560"C:\Program Files\GoToAssist Remote Support Customer\1610\g2ax_service.exe" "Start=service"C:\Program Files\GoToAssist Remote Support Customer\1610\g2ax_service.exeservices.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
GoToAssist
Exit code:
0
Version:
4.5 Build 1610
Modules
Images
c:\program files\gotoassist remote support customer\1610\g2ax_service.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2640"C:\Users\admin\AppData\Local\Temp\GoTo Opener.exe" "/urlQsArgs citrixonline://launch.getgo.com:443/launcher2/launchclickonce/e0-PyZ8EHrdGr-xktJgQu0MWxzfWC7Xb9Hom3pnFkqdF9Knneg_F6UnoiExt4O0AtEiQjHGqMiWGp-L7jm0pnDcOf9dS9Zf-iMVUJDa2Pu-vttlKsmlRLsH1IJB1Cgh2GDzpEPScl-eoubz0qGW9KOAHsfe1UNJhdOPwsgXQikzNUOPpm2HI159Nk19IrneTpZkPVtTTNhXJyfYg9C6DnMwM_q9QWDBb1wHPIRozv1ApLxZSDUBpFR20Y94GrhqXtFxvvoL4bWERfDHCBzxNvVYKdBMCDZcEFpZsJTOMxT0LdU0kHvEm2KBOdvjcIftxmAKnz8yTIsv0MyZNCsHn2jNFfTka2bWoLB6yKWvuBRDhsic_O3CdnJEueuwjdAMcbYyM0FONwfvMHO0RScnOVVGXBLvkwSu7BBjKctsTxcbUqfTljhcGIhTvgFlekMm-TIS524upp22fbMKkigY7E7SzqBpV4D26t8hVOJ1dzyKcQGbLTzuNYAcYx5TxNTwqt5SpAE0Yl0M4KgVgwVICTTbqpq3vcA" /forceInstallCheckC:\Users\admin\AppData\Local\Temp\GoTo Opener.exe
StarterDotNet20.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
GoTo Opener
Exit code:
0
Version:
1.0.0.491
Modules
Images
c:\users\admin\appdata\local\temp\goto opener.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2784"C:\Program Files\GoToAssist Remote Support Customer\1610\g2ax_comm_customer.exe" "Action=Join&Debug=On&EGWAddress=216.115.218.197&EGWDNS=egw1.express.gotoassist.com&EGWPort=8200,80,443&LoaderPath=C:\Users\admin\AppData\Local\GoToAssist Remote Support Customer\g2ax_customer_combined_dll_core_win32_x86_1610.exe&LogLevel=Normal&LogName=C:\Users\admin\AppData\Local\Temp\LogMeInLogs\GoToAssist Remote Support Customer\1610\20190116_204058\GoToAssist Remote Support Customer.LOG&LogPath=C:\Users\admin\AppData\Local\Temp\LogMeInLogs\GoToAssist Remote Support Customer\1610\20190116_204058\&MeetingID=804455697&ResourceDll=g2ax_customer_resource_win32_x86_en_US.dll&RestartReason=Start&RunningAsService=YES&ServiceAllowed=Yes&Start=service&StartAsService=Yes&StartID={45CB397D-781F-4B69-955E-7EB5F5BDC348}&Stat=On&StatDb=On&UninstallService=Yes&UniqueId=2560&WebsiteUrl=http://support.gotoassist.com&colClientUiReadyEvent=Global\1B44484A-261B-45EE-ABA3-664C85EA0A6F&sessionTrackingId=e0-PyZ8EHrdGr-xktJgQu0MWxzfWC7Xb"C:\Program Files\GoToAssist Remote Support Customer\1610\g2ax_comm_customer.exe
g2ax_service.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
GoToAssist
Exit code:
0
Version:
4.5 Build 1610
Modules
Images
c:\program files\gotoassist remote support customer\1610\g2ax_comm_customer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
2 374
Read events
2 011
Write events
341
Delete events
22

Modification events

(PID) Process:(3016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(3016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{D635992B-19CE-11E9-BAD8-5254004A04AF}
Value:
0
(PID) Process:(3016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(3016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
3
(PID) Process:(3016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E3070100030010001400270025002101
Executable files
73
Suspicious files
38
Text files
86
Unknown types
15

Dropped files

PID
Process
Filename
Type
3016iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico
MD5:
SHA256:
3016iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3568iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\fastsupport_com[1].txt
MD5:
SHA256:
3568iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab9DDC.tmp
MD5:
SHA256:
3568iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab9DEE.tmp
MD5:
SHA256:
3568iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar9DDD.tmp
MD5:
SHA256:
3568iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab9DF0.tmp
MD5:
SHA256:
3568iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab9E01.tmp
MD5:
SHA256:
3568iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar9DEF.tmp
MD5:
SHA256:
3568iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab9E03.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
55
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3568
iexplore.exe
GET
216.115.218.200:80
http://fastsupport.com/
US
unknown
3568
iexplore.exe
GET
200
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
55.2 Kb
whitelisted
3552
g2ax_installer_customer_admin.exe
GET
200
23.51.123.27:80
http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEBxoP3uP%2B82s4ZJ9WI1JBs8%3D
NL
der
1.57 Kb
shared
3552
g2ax_installer_customer_admin.exe
GET
200
23.51.123.27:80
http://ts-ocsp.ws.symantec.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRi82PVYYKWGJWdgVNyePy5kYTdqQQUX5r1blzMzHSa1N197z%2Fb7EyALt0CEA7P9DjI%2Fr81bgTYapgbGlA%3D
NL
der
1.43 Kb
whitelisted
3568
iexplore.exe
GET
200
2.16.186.56:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
55.2 Kb
whitelisted
3568
iexplore.exe
GET
200
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
55.2 Kb
whitelisted
3364
consent.exe
GET
200
23.51.123.27:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D
NL
der
1.71 Kb
whitelisted
3364
consent.exe
GET
200
23.51.123.27:80
http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEBxoP3uP%2B82s4ZJ9WI1JBs8%3D
NL
der
1.57 Kb
shared
3016
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3568
iexplore.exe
GET
200
13.35.254.176:80
http://x.ss2.us/x.cer
US
der
1.27 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2784
g2ax_comm_customer.exe
216.115.218.197:443
egw1.express.gotoassist.com
Mobility Apps division
US
unknown
3568
iexplore.exe
216.115.218.200:80
fastsupport.com
Mobility Apps division
US
unknown
3568
iexplore.exe
216.115.218.200:443
fastsupport.com
Mobility Apps division
US
unknown
3016
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3568
iexplore.exe
13.35.253.14:443
weblibrary.cdn.getgo.com
US
unknown
3568
iexplore.exe
13.35.254.176:80
x.ss2.us
US
unknown
3568
iexplore.exe
13.35.254.82:80
x.ss2.us
US
suspicious
3568
iexplore.exe
13.35.254.54:80
x.ss2.us
US
malicious
3568
iexplore.exe
13.35.254.34:80
x.ss2.us
US
suspicious
3568
iexplore.exe
2.16.186.56:80
www.download.windowsupdate.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
fastsupport.com
  • 216.115.218.200
unknown
www.fastsupport.com
  • 216.115.218.200
unknown
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
weblibrary.cdn.getgo.com
  • 13.35.253.14
  • 13.35.253.127
  • 13.35.253.56
  • 13.35.253.25
whitelisted
x.ss2.us
  • 13.35.254.54
  • 13.35.254.34
  • 13.35.254.82
  • 13.35.254.176
whitelisted
www.download.windowsupdate.com
  • 2.16.186.56
  • 2.16.186.81
  • 93.184.221.240
whitelisted
ssl.google-analytics.com
  • 172.217.18.168
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
launch.getgo.com
  • 78.108.120.31
whitelisted
builds.cdn.getgo.com
  • 13.35.253.122
  • 13.35.253.13
  • 13.35.253.95
  • 13.35.253.71
shared

Threats

No threats detected
Process
Message
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status Originated: -1073741772 *** Source File: d:\iso_whid\x86fre\base\isolation\win32\isoreg_direct.cpp, line 1127
GoTo Opener.exe
setSafeDllSearchPath()
GoTo Opener.exe
preLoadDllsFromSystem()
GoTo Opener.exe
C:\Windows\system32\MSVCRT.DLL
GoTo Opener.exe