| URL: | http://serve.popads.net/s?cid=6033967&iuid=685616388&ts=1580683223&ps=1270063132&pw=513&pl=%21Khmb414ahxMtUG08Scz%2BSGLmggRky05Lxwxwy%2FMyorS7Od4HuPg5goxL1UiDzlCSEZqlE38i%2F27NxyGpd2S2mAh4fVp85HwyA%2BdOt5pV%2BctihoVf9XS6IOoXSoyX%2FGkA%2FPW4o%2BqUUb%2FofHP%2B7JyrVD%2B8LWyIGIPhzq5oc8NSdo2c00XBX69WbCVa7Yp%2BXmJL%2F46l3c3nqt%2BDdY90deCzgtbmTwbC3gphzJvmBB4WNNzR0FE0AoCyf8bsh%2FGlcd60JvsXDRG1ij1atFRRqxM0cW8bXyYrt2JDY8VZDoaojDXbvg59zCK5IhVYDjmyoqggol5qeMfIeUyu4srX3nFotOuuW%2BZfB4tYBy3vFDUJCIu03I9EVskTegNDwlfP3rtBrsUHhBo5IA8YmPCvuCs0tG0D5Ov88jRbLFZGmCT1ZLZIW7ySQzz1l%2FGsh0lImsCcg4bTc2r4wFoiGcoMVbUtOf7XFagLDN7dewB5sBrptzEKbipdT2NwOMHkuxsFIEK3 |
| Full analysis: | https://app.any.run/tasks/9196724e-bc66-4a33-a0d4-387ff6f38fb9 |
| Verdict: | Malicious activity |
| Analysis date: | February 05, 2020, 15:10:49 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 97ECA82EFC2AEF17EA15638FA05A2E85 |
| SHA1: | 42CC68035ECB8699685FC83575F11A20C78CC1F9 |
| SHA256: | 3106703D7A75AF4694B4BB3FCF3796D0017CB9F84D10E2DD91E0E0CC3B3299A8 |
| SSDEEP: | 12:tI+RSM9LbqRL+80tsXHs6qLjOcWjz3mwkWJTUQWU/Sk:tLAM9Sh+80+7qLi3mwrL9/Z |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1524 | "C:\Program Files\Internet Explorer\iexplore.exe" http://serve.popads.net/s?cid=6033967&iuid=685616388&ts=1580683223&ps=1270063132&pw=513&pl=%21Khmb414ahxMtUG08Scz%2BSGLmggRky05Lxwxwy%2FMyorS7Od4HuPg5goxL1UiDzlCSEZqlE38i%2F27NxyGpd2S2mAh4fVp85HwyA%2BdOt5pV%2BctihoVf9XS6IOoXSoyX%2FGkA%2FPW4o%2BqUUb%2FofHP%2B7JyrVD%2B8LWyIGIPhzq5oc8NSdo2c00XBX69WbCVa7Yp%2BXmJL%2F46l3c3nqt%2BDdY90deCzgtbmTwbC3gphzJvmBB4WNNzR0FE0AoCyf8bsh%2FGlcd60JvsXDRG1ij1atFRRqxM0cW8bXyYrt2JDY8VZDoaojDXbvg59zCK5IhVYDjmyoqggol5qeMfIeUyu4srX3nFotOuuW%2BZfB4tYBy3vFDUJCIu03I9EVskTegNDwlfP3rtBrsUHhBo5IA8YmPCvuCs0tG0D5Ov88jRbLFZGmCT1ZLZIW7ySQzz1l%2FGsh0lImsCcg4bTc2r4wFoiGcoMVbUtOf7XFagLDN7dewB5sBrptzEKbipdT2NwOMHkuxsFIEK3 | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2600 | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe | — | svchost.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe® Flash® Player Installer/Uninstaller 26.0 r0 Exit code: 0 Version: 26,0,0,131 Modules
| |||||||||||||||
| 3824 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1524 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3824) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3824) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3824) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1524) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 2387338882 | |||
| (PID) Process: | (1524) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30792758 | |||
| (PID) Process: | (1524) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (1524) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1524) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1524) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (1524) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1524 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
| 1524 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
| 3824 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Cab8D15.tmp | — | |
MD5:— | SHA256:— | |||
| 3824 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Tar8D16.tmp | — | |
MD5:— | SHA256:— | |||
| 3824 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\WQ37RWQU.txt | — | |
MD5:— | SHA256:— | |||
| 3824 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\17KZOABL.txt | — | |
MD5:— | SHA256:— | |||
| 3824 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\0JMY1J0X.txt | — | |
MD5:— | SHA256:— | |||
| 3824 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\N1UZ7L2E.txt | — | |
MD5:— | SHA256:— | |||
| 3824 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\AJBSQM5A.txt | — | |
MD5:— | SHA256:— | |||
| 3824 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\43397a51[1].js | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3824 | iexplore.exe | GET | 200 | 192.124.249.41:80 | http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D | US | der | 1.66 Kb | whitelisted |
3824 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D | US | der | 471 b | whitelisted |
3824 | iexplore.exe | GET | 200 | 2.16.186.98:80 | http://ocsp.trustwave.com//MFQwUjBQME4wTDAJBgUrDgMCGgUABBRKUAJ27jxxuy1zYtpUHfLy0MHHugQUys4dGAN3HhzzfFiymnCoCIAW9K4CEwb2ERmVhkt3hCu3D%2F9%2BbwFXBWo%3D | unknown | der | 638 b | whitelisted |
3824 | iexplore.exe | GET | 200 | 172.217.23.131:80 | http://ocsp.pki.goog/gts1o1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEFa0PH9RdFNVCAAAAAAqsjw%3D | US | der | 471 b | whitelisted |
3824 | iexplore.exe | GET | 200 | 2.16.186.98:80 | http://ocsp.trustwave.com//MFQwUjBQME4wTDAJBgUrDgMCGgUABBRKUAJ27jxxuy1zYtpUHfLy0MHHugQUys4dGAN3HhzzfFiymnCoCIAW9K4CEwb2ERmVhkt3hCu3D%2F9%2BbwFXBWo%3D | unknown | der | 638 b | whitelisted |
3824 | iexplore.exe | GET | 200 | 216.21.13.16:80 | http://serve.popads.net/s?cid=6033967&iuid=685616388&ts=1580683223&ps=1270063132&pw=513&pl=%21Khmb414ahxMtUG08Scz%2BSGLmggRky05Lxwxwy%2FMyorS7Od4HuPg5goxL1UiDzlCSEZqlE38i%2F27NxyGpd2S2mAh4fVp85HwyA%2BdOt5pV%2BctihoVf9XS6IOoXSoyX%2FGkA%2FPW4o%2BqUUb%2FofHP%2B7JyrVD%2B8LWyIGIPhzq5oc8NSdo2c00XBX69WbCVa7Yp%2BXmJL%2F46l3c3nqt%2BDdY90deCzgtbmTwbC3gphzJvmBB4WNNzR0FE0AoCyf8bsh%2FGlcd60JvsXDRG1ij1atFRRqxM0cW8bXyYrt2JDY8VZDoaojDXbvg59zCK5IhVYDjmyoqggol5qeMfIeUyu4srX3nFotOuuW%2BZfB4tYBy3vFDUJCIu03I9EVskTegNDwlfP3rtBrsUHhBo5IA8YmPCvuCs0tG0D5Ov88jRbLFZGmCT1ZLZIW7ySQzz1l%2FGsh0lImsCcg4bTc2r4wFoiGcoMVbUtOf7XFagLDN7dewB5sBrptzEKbipdT2NwOMHkuxsFIEK3 | US | html | 237 b | whitelisted |
3824 | iexplore.exe | GET | 200 | 192.124.249.41:80 | http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D | US | der | 1.69 Kb | whitelisted |
3824 | iexplore.exe | GET | 200 | 2.16.186.98:80 | http://ocsp.trustwave.com//MFQwUjBQME4wTDAJBgUrDgMCGgUABBRKUAJ27jxxuy1zYtpUHfLy0MHHugQUys4dGAN3HhzzfFiymnCoCIAW9K4CEwb2JH68PZkPnXkY5Q6ArzL5POM%3D | unknown | der | 638 b | whitelisted |
3824 | iexplore.exe | GET | 200 | 2.16.186.98:80 | http://ocsp.trustwave.com//MFQwUjBQME4wTDAJBgUrDgMCGgUABBRKUAJ27jxxuy1zYtpUHfLy0MHHugQUys4dGAN3HhzzfFiymnCoCIAW9K4CEwcIOBXEZWPNC278KAXrxm8JFb8%3D | unknown | der | 638 b | whitelisted |
3824 | iexplore.exe | GET | 200 | 13.225.84.145:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3824 | iexplore.exe | 216.21.13.16:80 | — | Total Uptime Technologies, LLC | US | suspicious |
1524 | iexplore.exe | 216.21.13.16:80 | — | Total Uptime Technologies, LLC | US | suspicious |
3824 | iexplore.exe | 2.16.187.8:443 | us.shein.com | Akamai International B.V. | — | whitelisted |
1524 | iexplore.exe | 13.107.21.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3824 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3824 | iexplore.exe | 172.217.22.14:443 | apis.google.com | Google Inc. | US | whitelisted |
3824 | iexplore.exe | 2.16.187.33:443 | us.shein.com | Akamai International B.V. | — | whitelisted |
3824 | iexplore.exe | 216.58.206.14:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
3824 | iexplore.exe | 3.123.68.2:443 | recommender.scarabresearch.com | — | US | unknown |
3824 | iexplore.exe | 172.217.18.104:443 | www.googletagmanager.com | Google Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
serve.popads.net |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
us.shein.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
sheinsz.ltwebstatic.com |
| suspicious |
img.shein.com |
| whitelisted |
apis.google.com |
| whitelisted |
static.criteo.net |
| whitelisted |
count.shein.com |
| whitelisted |