URL: | https://LabCorp.com/llc/LabCorp_83273039583_Aug_06_2020.doc |
Full analysis: | https://app.any.run/tasks/4e74e399-116c-4200-b3dd-b68c43115db0 |
Verdict: | Malicious activity |
Analysis date: | August 07, 2020, 16:51:59 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | 294354D24B23AC380D6D7B0D2A92204F |
SHA1: | AB378F1D2396BE59DC555EA1B405A189BCDDE43C |
SHA256: | 4502938A1FC92DB6C72E8FB21ADA7D473C6DD1495224CB328624AA5CBF2CCF42 |
SSDEEP: | 3:N8HpUZI6GP2WXSlhg6kXVFj:2HGWslhgbF9 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2272 | "C:\Program Files\Internet Explorer\iexplore.exe" https://LabCorp.com/llc/LabCorp_83273039583_Aug_06_2020.doc | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
2600 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2272 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
2600 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Cab14EB.tmp | — | |
MD5:— | SHA256:— | |||
2600 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Tar14EC.tmp | — | |
MD5:— | SHA256:— | |||
2600 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5080DC7A65DB6A5960ECD874088F3328_6CBA2C06D5985DD95AE59AF8FC7C6220 | binary | |
MD5:737F34C19471238953AB77AF281200EB | SHA256:F8EFE948C2CB38540E046BF68554166795CF1B9562D91221585E673912AE1E61 | |||
2600 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\I0ZC6OTY.txt | text | |
MD5:A3FFCD5FDACC7E10E7EA38C417F26734 | SHA256:84A52E9182606085E85D9510BE572F01056FE1D6604ACB4299E73B847CF735BF | |||
2600 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\css_XapWX_923H5enAeRV7MxUugBo4LtfoW3pjRyRH1g8-8[1].css | text | |
MD5:7A6381603636805CF35C8A1F3F8D6952 | SHA256:5DAA565FFF76DC7E5E9C079157B33152E801A382ED7E85B7A63472447D60F3EF | |||
2600 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_2DBE917624E9880FE0C7C5570D56E691 | binary | |
MD5:ABDF4A63F3130296E79C2C71F53DE078 | SHA256:F6BCD51D349FBE9383EEAE9EA778732856363935A07DD7BB9B80F976F82EFB01 | |||
2600 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1BB09BEEC155258835C193A7AA85AA5B_E4968861BB3F5F7312A8E4ACCB05DE63 | binary | |
MD5:E54CC0425C7007B5EFFA3A7D824F2B2F | SHA256:47BCE0529683D5A5C6C819D1E9BCE625DA3F18172F03B16BDF8C9F98A90CB8D2 | |||
2600 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27 | der | |
MD5:240857763B231D30EDC20FB57C5542C4 | SHA256:355E000941CD3D76076D6FD509198ED0B260FD38ADBBD19778A9D053794A577B | |||
2600 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\css_Jel-EzwpzqcHhJGa1GBosOhUDBysdIltpRaBUiikfU8[1].css | text | |
MD5:6D979E1E2D684D15356FE532F9E96F57 | SHA256:25E97E133C29CEA70784919AD46068B0E8540C1CAC74896DA516815228A47D4F | |||
2600 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\LabCorpLogo_2x[1].png | image | |
MD5:1671511567F282861C9BEE27DF7F5007 | SHA256:DAA1BBB6D23FDB9B9A7EEC87A96818917FB8B012D3BAE4259E86117ADF011AC1 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2600 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.comodoca.com/MFAwTjBMMEowSDAJBgUrDgMCGgUABBR64T7ooMQqLLQoy%2BemBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCD2ED5o25S381gWqdgCP9iQ%3D%3D | US | der | 470 b | whitelisted |
2600 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCECsuburZdTZsFIpu26N8jAc%3D | US | der | 727 b | whitelisted |
2600 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D | US | der | 1.47 Kb | whitelisted |
2600 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D | US | der | 1.47 Kb | whitelisted |
2600 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEGfe9D7xe9riT%2FWUBgbSwIQ%3D | US | der | 471 b | whitelisted |
2600 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gts1o1core/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQCp7BRe1FSElwgAAAAAS%2FYQ | US | der | 472 b | whitelisted |
2600 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D | US | der | 471 b | whitelisted |
2600 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gts1o1core/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQCp7BRe1FSElwgAAAAAS%2FYQ | US | der | 472 b | whitelisted |
2600 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/rootr1/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDkbwjNvPLFRm7zMB3V80 | US | der | 1.49 Kb | whitelisted |
2600 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | US | der | 468 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2600 | iexplore.exe | 151.139.128.14:80 | ocsp.comodoca.com | Highwinds Network Group, Inc. | US | suspicious |
— | — | 151.139.128.14:80 | ocsp.comodoca.com | Highwinds Network Group, Inc. | US | suspicious |
2600 | iexplore.exe | 172.217.23.170:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
2600 | iexplore.exe | 104.16.161.134:443 | labcorp.com | Cloudflare Inc | US | unknown |
2600 | iexplore.exe | 151.101.14.109:443 | extend.vimeocdn.com | Fastly | US | unknown |
2600 | iexplore.exe | 2.16.186.49:443 | use.typekit.net | Akamai International B.V. | — | whitelisted |
2600 | iexplore.exe | 104.16.132.229:443 | cdnjs.cloudflare.com | Cloudflare Inc | US | suspicious |
2600 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
— | — | 104.18.20.226:80 | ocsp.globalsign.com | Cloudflare Inc | US | shared |
2600 | iexplore.exe | 172.217.16.131:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
labcorp.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
www.labcorp.com |
| suspicious |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
extend.vimeocdn.com |
| shared |
cdnjs.cloudflare.com |
| whitelisted |
use.typekit.net |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |