URL:

https://sqlspreads.com:443/downloads/SQLSpreadsSetup_5.0.51.exe

Full analysis: https://app.any.run/tasks/2962c21f-00e0-471b-a3db-264c858f5274
Verdict: Malicious activity
Analysis date: March 06, 2020, 17:12:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

39A3EA450C8E7F8A4EED5F8A88FE8946

SHA1:

B4982D968D9A826D092BE6252BCFF0E5F6D6FB9B

SHA256:

1F981CED29A82F969E41356C96A1F9D2C2BB4D180C46AA04F9F318BE6A402024

SSDEEP:

3:N8ZL/GT5wkeKTaXWnyPhQSN:25w7VuWyPh9N

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • SQLSpreadsSetup_5.0.51.exe (PID: 3560)
      • SQLSpreadsSetup_4.4.7.exe (PID: 1812)
      • SQLSpreadsSetup_5.0.51.exe (PID: 3260)
      • SQLSpreadsSetup.exe (PID: 1440)
    • Loads dropped or rewritten executable

      • rundll32.exe (PID: 3744)
      • rundll32.exe (PID: 3832)
      • rundll32.exe (PID: 3916)
      • rundll32.exe (PID: 3924)
      • msiexec.exe (PID: 628)
  • SUSPICIOUS

    • Uses RUNDLL32.EXE to load library

      • MsiExec.exe (PID: 2376)
      • MsiExec.exe (PID: 780)
      • MsiExec.exe (PID: 2748)
      • MsiExec.exe (PID: 3972)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2388)
      • iexplore.exe (PID: 4004)
      • iexplore.exe (PID: 2556)
      • SQLSpreadsSetup_4.4.7.exe (PID: 1812)
      • msiexec.exe (PID: 3468)
      • rundll32.exe (PID: 3744)
      • msiexec.exe (PID: 3784)
      • msiexec.exe (PID: 2152)
      • rundll32.exe (PID: 3924)
      • msiexec.exe (PID: 628)
    • Creates files in the user directory

      • SQLSpreadsSetup_5.0.51.exe (PID: 3560)
      • SQLSpreadsSetup_5.0.51.exe (PID: 3260)
      • SQLSpreadsSetup_4.4.7.exe (PID: 1812)
      • msiexec.exe (PID: 2152)
      • SQLSpreadsSetup.exe (PID: 1440)
    • Starts Internet Explorer

      • cmd.exe (PID: 2852)
    • Starts CMD.EXE for commands execution

      • MsiExec.exe (PID: 2376)
      • MsiExec.exe (PID: 780)
      • MsiExec.exe (PID: 2748)
    • Executed as Windows Service

      • vssvc.exe (PID: 3932)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2556)
      • iexplore.exe (PID: 4004)
      • iexplore.exe (PID: 2880)
      • iexplore.exe (PID: 2788)
    • Changes internet zones settings

      • iexplore.exe (PID: 2556)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 2376)
      • MsiExec.exe (PID: 780)
      • MsiExec.exe (PID: 2748)
      • msiexec.exe (PID: 2152)
      • MsiExec.exe (PID: 3972)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2556)
    • Application launched itself

      • msiexec.exe (PID: 2152)
      • iexplore.exe (PID: 2556)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2556)
      • msiexec.exe (PID: 2152)
      • iexplore.exe (PID: 2880)
      • iexplore.exe (PID: 2788)
      • iexplore.exe (PID: 4004)
    • Creates files in the user directory

      • iexplore.exe (PID: 2556)
      • iexplore.exe (PID: 4004)
      • iexplore.exe (PID: 2880)
      • iexplore.exe (PID: 2788)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3932)
    • Reads internet explorer settings

      • iexplore.exe (PID: 4004)
      • iexplore.exe (PID: 2880)
      • iexplore.exe (PID: 2788)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2152)
    • Searches for installed software

      • msiexec.exe (PID: 2152)
    • Manual execution by user

      • SQLSpreadsSetup.exe (PID: 1440)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2556)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2556)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
68
Monitored processes
26
Malicious processes
8
Suspicious processes
5

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start start iexplore.exe iexplore.exe sqlspreadssetup_5.0.51.exe no specs msiexec.exe msiexec.exe msiexec.exe no specs rundll32.exe no specs cmd.exe no specs iexplore.exe no specs sqlspreadssetup_4.4.7.exe msiexec.exe msiexec.exe no specs rundll32.exe vssvc.exe no specs sqlspreadssetup_5.0.51.exe no specs msiexec.exe msiexec.exe no specs rundll32.exe no specs cmd.exe no specs iexplore.exe cmd.exe no specs iexplore.exe sqlspreadssetup.exe no specs msiexec.exe msiexec.exe no specs rundll32.exe

Process information

PID
CMD
Path
Indicators
Parent process
628"C:\Windows\system32\msiexec.exe" -i "C:\Users\admin\AppData\Roaming\Downloaded Installations\{BFABDB2A-7162-4003-A948-2F54AF86C567}\{F0BAD517-960E-4342-B7A0-781D5A5078B7}.msi"C:\Windows\system32\msiexec.exe
SQLSpreadsSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
780C:\Windows\system32\MsiExec.exe -Embedding CE24B12EAA9651DF86D402E18574171C CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1440"C:\Users\admin\Downloads\SQLSpreadsSetup.exe" C:\Users\admin\Downloads\SQLSpreadsSetup.exeexplorer.exe
User:
admin
Company:
Obnex Technologies AB
Integrity Level:
MEDIUM
Description:
Setup Program
Exit code:
0
Version:
4.50.148.0
Modules
Images
c:\users\admin\downloads\sqlspreadssetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1812"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\SQLSpreadsSetup_4.4.7.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\SQLSpreadsSetup_4.4.7.exe
iexplore.exe
User:
admin
Company:
Obnex Technologies AB
Integrity Level:
MEDIUM
Description:
Setup Program
Exit code:
0
Version:
4.4.7.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\sqlspreadssetup_4.4.7.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2152C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2376C:\Windows\system32\MsiExec.exe -Embedding 275742AD5361F8A44E278B03B6992485 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2388"C:\Windows\system32\msiexec.exe" -i "C:\Users\admin\AppData\Roaming\Downloaded Installations\{170FE277-5441-4BE9-8163-E7F4EFA31B27}\{CBFCB91C-7721-4DC5-B014-556FD7EDBF12}.msi"C:\Windows\system32\msiexec.exe
SQLSpreadsSetup_5.0.51.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1602
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2556"C:\Program Files\Internet Explorer\iexplore.exe" https://sqlspreads.com:443/downloads/SQLSpreadsSetup_5.0.51.exeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2748C:\Windows\system32\MsiExec.exe -Embedding E957698CD3EA86A45C7DC218ADF6B6BB CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2788"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2556 CREDAT:2757917 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
8 316
Read events
3 257
Write events
3 687
Delete events
1 372

Modification events

(PID) Process:(4004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2556) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
2180017240
(PID) Process:(2556) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30798810
(PID) Process:(2556) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2556) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2556) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2556) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2556) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2556) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
Executable files
54
Suspicious files
104
Text files
119
Unknown types
36

Dropped files

PID
Process
Filename
Type
4004iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab7F89.tmp
MD5:
SHA256:
4004iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar7F8A.tmp
MD5:
SHA256:
2556iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
4004iexplore.exeC:\Users\admin\Downloads\SQLSpreadsSetup_5.0.51.exe.qcw5v5x.partial
MD5:
SHA256:
2556iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF993E556C59BF38C2.TMP
MD5:
SHA256:
2556iexplore.exeC:\Users\admin\Downloads\SQLSpreadsSetup_5.0.51.exe.qcw5v5x.partial:Zone.Identifier
MD5:
SHA256:
3560SQLSpreadsSetup_5.0.51.exeC:\Users\admin\AppData\Roaming\Downloaded Installations\{170FE277-5441-4BE9-8163-E7F4EFA31B27}\{CBFCB91C-7721-4DC5-B014-556FD7EDBF12}.msi
MD5:
SHA256:
2388msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI37AD.tmp
MD5:
SHA256:
2388msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI385B.tmp
MD5:
SHA256:
3832rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI385B.tmp-\CustomActions.dll
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
39
TCP/UDP connections
112
DNS requests
43
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4004
iexplore.exe
GET
200
172.217.16.131:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQCgdZM8AVzzKAgAAAAALnDU
US
der
472 b
whitelisted
4004
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAKDNYJlYx4BMp3nlQdiIwE%3D
US
der
471 b
whitelisted
4004
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAKDNYJlYx4BMp3nlQdiIwE%3D
US
der
471 b
whitelisted
4004
iexplore.exe
GET
200
172.217.16.131:80
http://ocsp.pki.goog/gts1o1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEDSYZwjBCneuAgAAAABZcag%3D
US
der
471 b
whitelisted
4004
iexplore.exe
GET
200
172.217.16.131:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQCgdZM8AVzzKAgAAAAALnDU
US
der
472 b
whitelisted
4004
iexplore.exe
GET
200
172.217.16.131:80
http://ocsp.pki.goog/gts1o1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEDSYZwjBCneuAgAAAABZcag%3D
US
der
471 b
whitelisted
4004
iexplore.exe
GET
200
172.217.16.131:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQCSaJP2bCz9oAgAAAAALnFI
US
der
472 b
whitelisted
4004
iexplore.exe
GET
200
2.21.242.189:80
http://ocsp.int-x3.letsencrypt.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBR%2B5mrncpqz%2FPiiIGRsFqEtYHEIXQQUqEpqYwR93brm0Tm3pkVl7%2FOo7KECEgP4W%2B2S8yKebeyatZnLMKzmzg%3D%3D
NL
der
527 b
whitelisted
4004
iexplore.exe
GET
200
2.21.242.221:80
http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D
NL
der
1.37 Kb
whitelisted
4004
iexplore.exe
GET
200
192.35.177.64:80
http://crl.identrust.com/DSTROOTCAX3CRL.crl
US
der
994 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4004
iexplore.exe
104.196.152.243:443
sqlspreads.com
Google Inc.
US
unknown
4004
iexplore.exe
2.21.242.221:80
isrg.trustid.ocsp.identrust.com
Akamai International B.V.
NL
whitelisted
4004
iexplore.exe
2.21.242.189:80
ocsp.int-x3.letsencrypt.org
Akamai International B.V.
NL
whitelisted
2556
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
4004
iexplore.exe
192.35.177.64:80
crl.identrust.com
IdenTrust
US
malicious
4004
iexplore.exe
2.21.242.197:80
isrg.trustid.ocsp.identrust.com
Akamai International B.V.
NL
whitelisted
2556
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2556
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2556
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
4004
iexplore.exe
216.58.206.10:443
ajax.googleapis.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
sqlspreads.com
  • 104.196.152.243
unknown
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
isrg.trustid.ocsp.identrust.com
  • 2.21.242.221
  • 2.21.242.197
whitelisted
ocsp.int-x3.letsencrypt.org
  • 2.21.242.189
  • 2.21.242.245
  • 2.21.242.220
  • 2.21.242.188
  • 2.21.242.236
  • 2.21.242.227
  • 2.21.242.244
  • 2.21.242.213
  • 2.21.242.229
whitelisted
crl.identrust.com
  • 192.35.177.64
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted

Threats

No threats detected
No debug info