URL:

https://fastsupport.gotoassist.com/606918100

Full analysis: https://app.any.run/tasks/4af9d62c-da04-449c-8594-91779830f80a
Verdict: Malicious activity
Analysis date: March 19, 2020, 21:49:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

4A23B92E491CE990491AC6C419E10F0C

SHA1:

EA8E5C9175E269A042800F0A88A09CAC644046B0

SHA256:

422E72DD7A351009BFE900A89F5FA12F31240553F92650781D51250317F96AB3

SSDEEP:

3:N8XXCBLCKfRMWRLdjNMVn:2HILCKfqWZJUn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GoToAssist Opener.exe (PID: 1024)
      • g2ax_customer_combined_dll_core_win32_x86_1673.exe (PID: 2412)
      • g2ax_installer_customer_admin.exe (PID: 3308)
      • g2ax_installer_customer_admin.exe (PID: 3540)
      • g2ax_installer_customer.exe (PID: 2624)
      • g2ax_service.exe (PID: 1332)
      • g2ax_service.exe (PID: 2940)
      • g2ax_service.exe (PID: 3828)
      • g2ax_comm_customer.exe (PID: 3084)
      • g2ax_user_customer.exe (PID: 2748)
      • g2ax_uninstaller_customer.exe (PID: 3096)
      • g2ax_service.exe (PID: 1136)
      • g2ax_system_customer.exe (PID: 3468)
      • g2ax_service.exe (PID: 256)
    • Loads dropped or rewritten executable

      • g2ax_installer_customer.exe (PID: 2624)
      • g2ax_installer_customer_admin.exe (PID: 3540)
      • g2ax_service.exe (PID: 1332)
      • g2ax_service.exe (PID: 2940)
      • g2ax_service.exe (PID: 3828)
      • g2ax_comm_customer.exe (PID: 3084)
      • g2ax_user_customer.exe (PID: 2748)
      • g2ax_uninstaller_customer.exe (PID: 3096)
      • g2ax_system_customer.exe (PID: 3468)
      • g2ax_service.exe (PID: 1136)
      • g2ax_service.exe (PID: 256)
      • rundll32.exe (PID: 1828)
    • Changes settings of System certificates

      • g2ax_comm_customer.exe (PID: 3084)
      • g2ax_installer_customer_admin.exe (PID: 3540)
    • Registers / Runs the DLL via REGSVR32.EXE

      • g2ax_service.exe (PID: 256)
    • Deletes the SafeBoot registry key

      • g2ax_service.exe (PID: 256)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • GoToAssist Opener.exe (PID: 1024)
      • msiexec.exe (PID: 1928)
      • iexplore.exe (PID: 3248)
      • iexplore.exe (PID: 1440)
      • g2ax_customer_combined_dll_core_win32_x86_1673.exe (PID: 2412)
      • g2ax_installer_customer_admin.exe (PID: 3540)
    • Modifies the open verb of a shell class

      • msiexec.exe (PID: 1928)
    • Starts Microsoft Installer

      • GoToAssist Opener.exe (PID: 1024)
    • Reads Internet Cache Settings

      • GoToAssist Opener.exe (PID: 1024)
    • Creates files in the user directory

      • msiexec.exe (PID: 1928)
      • g2ax_service.exe (PID: 1332)
    • Creates files in the program directory

      • g2ax_installer_customer_admin.exe (PID: 3540)
      • g2ax_service.exe (PID: 1332)
    • Creates a software uninstall entry

      • g2ax_installer_customer_admin.exe (PID: 3540)
    • Executed as Windows Service

      • g2ax_service.exe (PID: 3828)
    • Starts itself from another location

      • g2ax_comm_customer.exe (PID: 3084)
    • Starts CMD.EXE for commands execution

      • GoToAssist Opener.exe (PID: 1024)
    • Adds / modifies Windows certificates

      • g2ax_comm_customer.exe (PID: 3084)
      • g2ax_installer_customer_admin.exe (PID: 3540)
    • Connects to unusual port

      • g2ax_comm_customer.exe (PID: 3084)
    • Uses RUNDLL32.EXE to load library

      • g2ax_uninstaller_customer.exe (PID: 3096)
  • INFO

    • Reads internet explorer settings

      • iexplore.exe (PID: 3248)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 1440)
      • iexplore.exe (PID: 3248)
    • Application launched itself

      • iexplore.exe (PID: 1440)
    • Creates files in the user directory

      • iexplore.exe (PID: 3248)
      • iexplore.exe (PID: 1440)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 1440)
    • Changes internet zones settings

      • iexplore.exe (PID: 1440)
    • Reads settings of System Certificates

      • GoToAssist Opener.exe (PID: 1024)
      • g2ax_installer_customer_admin.exe (PID: 3540)
      • iexplore.exe (PID: 3248)
      • iexplore.exe (PID: 1440)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1928)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1440)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
21
Malicious processes
12
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe gotoassist opener.exe msiexec.exe no specs msiexec.exe g2ax_customer_combined_dll_core_win32_x86_1673.exe g2ax_installer_customer.exe no specs g2ax_installer_customer_admin.exe no specs g2ax_installer_customer_admin.exe g2ax_service.exe no specs g2ax_service.exe no specs g2ax_service.exe no specs g2ax_comm_customer.exe g2ax_system_customer.exe no specs g2ax_user_customer.exe no specs cmd.exe no specs g2ax_uninstaller_customer.exe no specs g2ax_service.exe no specs g2ax_service.exe no specs regsvr32.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
256"C:\Program Files\GoToAssist Remote Support Customer\1673\g2ax_service.exe" "Start=remove&LogPath=C:\Users\admin\AppData\Local\Temp\LogMeInLogs\GoToAssist Remote Support Customer\1673\20200319_215012\&ResourceDll=g2ax_customer_resource_win32_x86_en_US.dll&WaitOnProcessIdFirst=3828"C:\Program Files\GoToAssist Remote Support Customer\1673\g2ax_service.exeg2ax_uninstaller_customer.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\gotoassist remote support customer\1673\g2ax_service.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
1024"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\GoToAssist Opener.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\GoToAssist Opener.exe
iexplore.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
GoTo Opener
Exit code:
0
Version:
1.0.0.533
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\gotoassist opener.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1136"C:\Program Files\GoToAssist Remote Support Customer\1673\g2ax_service.exe" "Start=force_shutdown&LogPath=C:\Users\admin\AppData\Local\Temp\LogMeInLogs\GoToAssist Remote Support Customer\1673\20200319_215012\&ResourceDll=g2ax_customer_resource_win32_x86_en_US.dll&WaitOnProcessIdFirst=3828"C:\Program Files\GoToAssist Remote Support Customer\1673\g2ax_service.exeg2ax_uninstaller_customer.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
GoToAssist
Exit code:
0
Version:
4.7 Build 1673
Modules
Images
c:\program files\gotoassist remote support customer\1673\g2ax_service.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1332"C:\Program Files\GoToAssist Remote Support Customer\1673\g2ax_service.exe" "Start=install_manual&Action=Join&Debug=On&EGWAddress=216.115.218.197&EGWDNS=egw1.express.gotoassist.com&EGWPort=8200,80,443&LoaderPath=C:\Users\admin\AppData\Local\GoToAssist Remote Support Customer\g2ax_customer_combined_dll_core_win32_x86_1673.exe&LogLevel=Normal&LogPath=C:\Users\admin\AppData\Local\Temp\LogMeInLogs\GoToAssist Remote Support Customer\1673\20200319_215012\&MeetingID=606918100&ResourceDll=g2ax_customer_resource_win32_x86_en_US.dll&RestartReason=Start&ServiceAllowed=Yes&StartAsService=Yes&Stat=On&StatDb=On&UninstallService=Yes&WebsiteUrl=http://support.gotoassist.com&colClientUiReadyEvent=Global\B58A16FE-F780-4CD4-866F-AA8057CED468&sessionTrackingId=e0-uD5_R_iiTKecHw0o6epIWdv4Ae0Ex"C:\Program Files\GoToAssist Remote Support Customer\1673\g2ax_service.exeg2ax_installer_customer_admin.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
HIGH
Description:
GoToAssist
Exit code:
0
Version:
4.7 Build 1673
Modules
Images
c:\program files\gotoassist remote support customer\1673\g2ax_service.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1440"C:\Program Files\Internet Explorer\iexplore.exe" "https://fastsupport.gotoassist.com/606918100"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1828rundll32.exe "C:\Program Files\GoToAssist Remote Support Customer\1673\uninshlp.dll",DeleteExeAndDeleteSelf 32c40bf1-533c-4fee-85e3-98598fe5a70aC:\Windows\system32\rundll32.exeg2ax_uninstaller_customer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1928C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2412"C:\Users\admin\AppData\Local\GoToAssist Remote Support Customer\g2ax_customer_combined_dll_core_win32_x86_1673.exe" "/Action Join" "/Debug On" "/EGWAddress 216.115.218.197" "/EGWDNS egw1.express.gotoassist.com" "/EGWPort 8200,80,443" "/LogLevel Normal" "/MeetingID 606918100" "/ResourceDll_c g2ax_customer_resource_win32_x86_en_US.dll" "/ServiceAllowed Yes" "/StartAsService Yes" "/Stat On" "/StatDb On" "/UninstallService Yes" "/WebsiteUrl http://support.gotoassist.com" "/colClientUiReadyEvent Global\B58A16FE-F780-4CD4-866F-AA8057CED468" "/sessionTrackingId e0-uD5_R_iiTKecHw0o6epIWdv4Ae0Ex"C:\Users\admin\AppData\Local\GoToAssist Remote Support Customer\g2ax_customer_combined_dll_core_win32_x86_1673.exe
GoToAssist Opener.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
GoToAssist
Exit code:
0
Version:
4.7 Build 1673
Modules
Images
c:\users\admin\appdata\local\gotoassist remote support customer\g2ax_customer_combined_dll_core_win32_x86_1673.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2516"C:\Windows\system32\regsvr32.exe" /u /s C:\Windows\system32\g2ax_credential_provider_1673.dllC:\Windows\system32\regsvr32.exeg2ax_service.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2584"C:\Windows\system32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\0AAF1992-D8A8-4143-BA15-4A8ADA013C80\GoToOpener.msi" /q /lvx "C:\Users\admin\AppData\Local\Temp\LogMeInLogs\GoToOpenerMsi\548E8085-A790-472C-9ACC-F0D7264150D5.log"C:\Windows\system32\msiexec.exeGoToAssist Opener.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
9 629
Read events
2 956
Write events
4 920
Delete events
1 753

Modification events

(PID) Process:(1440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
1577774906
(PID) Process:(1440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30801464
(PID) Process:(1440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(1440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
49
Suspicious files
37
Text files
39
Unknown types
18

Dropped files

PID
Process
Filename
Type
3248iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab7FA8.tmp
MD5:
SHA256:
3248iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar7FA9.tmp
MD5:
SHA256:
3248iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\0N7XOESD.txt
MD5:
SHA256:
3248iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\239H7LYX.txt
MD5:
SHA256:
3248iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\V5US78OQ.txt
MD5:
SHA256:
1440iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3248iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6der
MD5:
SHA256:
3248iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1E11E75149C17A93653DA7DC0B8CF53F_244DD9FF2BA7FAFC8CC3F39A1F714CA1der
MD5:
SHA256:
3248iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619binary
MD5:
SHA256:
3248iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5887976EDAA817EEF5159B09F6FCD000_97DC20ECCF7D2206739F35D1F6087429binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
36
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3248
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
3248
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJ9L2KGL92BpjF3kAtaDtxauTmhgQUPdNQpdagre7zSmAKZdMh1Pj41g8CEAQ6rI%2F%2BE5cRwi3fO2KQGAA%3D
US
der
471 b
whitelisted
3248
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAkdKxIaplh7TRdOTZEeG50%3D
US
der
471 b
whitelisted
3248
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
3248
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJ9L2KGL92BpjF3kAtaDtxauTmhgQUPdNQpdagre7zSmAKZdMh1Pj41g8CEAQ6rI%2F%2BE5cRwi3fO2KQGAA%3D
US
der
471 b
whitelisted
3540
g2ax_installer_customer_admin.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAd33SHPXcnceFrLrioCuyY%3D
US
der
471 b
whitelisted
1024
GoToAssist Opener.exe
GET
200
13.35.254.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D
US
der
1.39 Kb
shared
1024
GoToAssist Opener.exe
GET
200
13.35.254.52:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
1440
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
3540
g2ax_installer_customer_admin.exe
GET
200
151.139.128.14:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSmEJ7s5DLYqQ4%2FaFKR54j1BHqdkgQUGqH4YRkgD8NBd0UojtE1XwYSBFUCED0aNXIwFYJjMNATcX6CQQg%3D
US
der
727 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3248
iexplore.exe
216.115.218.200:443
fastsupport.gotoassist.com
Mobility Apps division
US
unknown
3248
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3248
iexplore.exe
78.108.120.31:443
launch.getgo.com
Mobility Apps division
unknown
1440
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
1440
iexplore.exe
78.108.120.31:443
launch.getgo.com
Mobility Apps division
unknown
1024
GoToAssist Opener.exe
78.108.120.31:443
launch.getgo.com
Mobility Apps division
unknown
1024
GoToAssist Opener.exe
143.204.201.96:443
builds.cdn.getgo.com
US
shared
1024
GoToAssist Opener.exe
143.204.208.79:80
o.ss2.us
US
whitelisted
1024
GoToAssist Opener.exe
13.35.254.52:80
ocsp.rootg2.amazontrust.com
US
whitelisted
1024
GoToAssist Opener.exe
13.35.254.41:80
ocsp.rootg2.amazontrust.com
US
whitelisted

DNS requests

Domain
IP
Reputation
fastsupport.gotoassist.com
  • 216.115.218.200
unknown
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
launch.getgo.com
  • 78.108.120.31
whitelisted
builds.cdn.getgo.com
  • 143.204.201.96
  • 143.204.201.10
  • 143.204.201.82
  • 143.204.201.99
shared
o.ss2.us
  • 143.204.208.79
  • 143.204.208.160
  • 143.204.208.127
  • 143.204.208.165
whitelisted
ocsp.rootg2.amazontrust.com
  • 13.35.254.52
  • 13.35.254.57
  • 13.35.254.41
  • 13.35.254.226
whitelisted
ocsp.rootca1.amazontrust.com
  • 13.35.254.41
  • 13.35.254.52
  • 13.35.254.57
  • 13.35.254.226
shared
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted

Threats

No threats detected
Process
Message
GoToAssist Opener.exe
setSafeDllSearchPath()
GoToAssist Opener.exe
GoToAssist Opener.exe
C:\Windows\system32\BCRYPTPRIMITIVES.DLL
GoToAssist Opener.exe
preLoadDllsFromSystem()
GoToAssist Opener.exe
C:\Windows\system32\MSVCRT.DLL
GoToAssist Opener.exe
C:\Windows\system32\BCRYPTPRIMITIVES.DLL
GoToAssist Opener.exe
GoToAssist Opener.exe
GoToAssist Opener.exe
C:\Windows\system32\ADVAPI32.DLL
GoToAssist Opener.exe
C:\Windows\system32\CRYPTBASE.DLL