URL:

https://mega.nz/file/juB1HCTR#DjmsKRUrETPk1NlH3S9ENjEd11EcY-UpkIYEJvVi9bU

Full analysis: https://app.any.run/tasks/4adbea35-ff42-4b8c-9976-39e96b1cf535
Verdict: Malicious activity
Analysis date: September 09, 2021, 14:44:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

B0DDF83637C9CB4101C093327A8633B9

SHA1:

FCD3331BA7EB02189B4C59A40FA4A0AAF5EA9065

SHA256:

4914D8C8E2AE340D6D4509FD47FD06E8C7ED027AA575F01C86F47E22B2EDDCDE

SSDEEP:

3:N8X/ismxYhgxHUgEBNgcwmgHMX:2VmxYh0H5E3/T

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads the Task Scheduler COM API

      • firefox.exe (PID: 2756)
    • Drops executable file immediately after starts

      • NordVPNSetup.exe (PID: 4052)
      • NordVPNSetup.exe (PID: 1624)
      • NordVPNSetup.tmp (PID: 1340)
      • dotnetfx48.exe (PID: 2244)
      • msiexec.exe (PID: 2700)
    • Actions looks like stealing of personal data

      • NordVPNSetup.tmp (PID: 1340)
      • dotnetfx48.exe (PID: 2244)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 3460)
    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 3460)
      • SetupUtility.exe (PID: 4020)
      • SetupUtility.exe (PID: 1548)
      • NordVPNPatch.exe (PID: 1456)
    • Changes settings of System certificates

      • Setup.exe (PID: 3460)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 1896)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 3964)
    • Drops a file that was compiled in debug mode

      • firefox.exe (PID: 2756)
      • NordVPNSetup.tmp (PID: 1340)
      • dotnetfx48.exe (PID: 2244)
      • msiexec.exe (PID: 2700)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 2756)
      • WinRAR.exe (PID: 560)
      • NordVPNSetup.exe (PID: 4052)
      • NordVPNSetup.exe (PID: 1624)
      • NordVPNSetup.tmp (PID: 1340)
      • dotnetfx48.exe (PID: 2244)
      • Setup.exe (PID: 3460)
      • TMP25F6.tmp.exe (PID: 2800)
      • msiexec.exe (PID: 2700)
    • Checks supported languages

      • WinRAR.exe (PID: 560)
      • NordVPNSetup.exe (PID: 4052)
      • NordVPNSetup.exe (PID: 1624)
      • NordVPNSetup.tmp (PID: 1340)
      • dotnetfx48.exe (PID: 2244)
      • Setup.exe (PID: 3460)
      • SetupUtility.exe (PID: 4020)
      • NordVPNSetup.tmp (PID: 3524)
      • SetupUtility.exe (PID: 1548)
      • TMP25F6.tmp.exe (PID: 2800)
      • NordVPNPatch.exe (PID: 1456)
    • Reads the computer name

      • WinRAR.exe (PID: 560)
      • NordVPNSetup.tmp (PID: 1340)
      • dotnetfx48.exe (PID: 2244)
      • Setup.exe (PID: 3460)
      • SetupUtility.exe (PID: 4020)
      • NordVPNSetup.tmp (PID: 3524)
      • SetupUtility.exe (PID: 1548)
      • TMP25F6.tmp.exe (PID: 2800)
      • NordVPNPatch.exe (PID: 1456)
    • Reads the Windows organization settings

      • NordVPNSetup.tmp (PID: 1340)
      • msiexec.exe (PID: 2700)
    • Reads Windows owner or organization settings

      • NordVPNSetup.tmp (PID: 1340)
      • msiexec.exe (PID: 2700)
    • Reads Environment values

      • NordVPNSetup.tmp (PID: 1340)
      • Setup.exe (PID: 3460)
    • Uses TASKKILL.EXE to kill process

      • NordVPNSetup.tmp (PID: 1340)
    • Reads CPU info

      • Setup.exe (PID: 3460)
    • Creates files in the Windows directory

      • Setup.exe (PID: 3460)
    • Executed as Windows Service

      • msiexec.exe (PID: 2700)
    • Application launched itself

      • msiexec.exe (PID: 2700)
    • Searches for installed software

      • NordVPNSetup.tmp (PID: 1340)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 3676)
      • chrome.exe (PID: 3140)
      • iexplore.exe (PID: 1896)
      • chrome.exe (PID: 3988)
      • chrome.exe (PID: 3964)
      • chrome.exe (PID: 2504)
      • chrome.exe (PID: 4000)
      • chrome.exe (PID: 3260)
      • chrome.exe (PID: 3000)
      • chrome.exe (PID: 2068)
      • chrome.exe (PID: 3760)
      • chrome.exe (PID: 1796)
      • chrome.exe (PID: 1404)
      • chrome.exe (PID: 1296)
      • chrome.exe (PID: 3408)
      • chrome.exe (PID: 3460)
      • chrome.exe (PID: 2932)
      • chrome.exe (PID: 3960)
      • chrome.exe (PID: 2876)
      • chrome.exe (PID: 3492)
      • firefox.exe (PID: 2756)
      • firefox.exe (PID: 2108)
      • firefox.exe (PID: 2344)
      • firefox.exe (PID: 2304)
      • firefox.exe (PID: 3304)
      • firefox.exe (PID: 3564)
      • chrome.exe (PID: 3952)
      • chrome.exe (PID: 2272)
      • firefox.exe (PID: 2428)
      • chrome.exe (PID: 3448)
      • taskkill.exe (PID: 1372)
      • msiexec.exe (PID: 2700)
      • MsiExec.exe (PID: 3904)
    • Changes internet zones settings

      • iexplore.exe (PID: 3676)
    • Reads the computer name

      • iexplore.exe (PID: 1896)
      • iexplore.exe (PID: 3676)
      • chrome.exe (PID: 3964)
      • chrome.exe (PID: 2504)
      • chrome.exe (PID: 3140)
      • chrome.exe (PID: 3260)
      • chrome.exe (PID: 3460)
      • chrome.exe (PID: 1404)
      • chrome.exe (PID: 2876)
      • chrome.exe (PID: 3492)
      • firefox.exe (PID: 2756)
      • firefox.exe (PID: 2304)
      • firefox.exe (PID: 2344)
      • firefox.exe (PID: 3304)
      • firefox.exe (PID: 3564)
      • chrome.exe (PID: 3952)
      • firefox.exe (PID: 2428)
      • taskkill.exe (PID: 1372)
      • msiexec.exe (PID: 2700)
      • MsiExec.exe (PID: 3904)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1896)
    • Application launched itself

      • iexplore.exe (PID: 3676)
      • chrome.exe (PID: 3964)
      • firefox.exe (PID: 2108)
      • firefox.exe (PID: 2756)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1896)
      • iexplore.exe (PID: 3676)
      • chrome.exe (PID: 2504)
      • NordVPNSetup.tmp (PID: 1340)
      • Setup.exe (PID: 3460)
      • msiexec.exe (PID: 2700)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 3676)
      • chrome.exe (PID: 3492)
      • firefox.exe (PID: 2756)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 1896)
      • iexplore.exe (PID: 3676)
      • firefox.exe (PID: 2756)
      • NordVPNSetup.tmp (PID: 1340)
      • Setup.exe (PID: 3460)
      • msiexec.exe (PID: 2700)
    • Manual execution by user

      • chrome.exe (PID: 3964)
      • firefox.exe (PID: 2108)
      • NordVPNSetup.exe (PID: 4052)
      • WinRAR.exe (PID: 560)
      • NordVPNPatch.exe (PID: 1456)
    • Reads the hosts file

      • chrome.exe (PID: 3964)
      • chrome.exe (PID: 2504)
    • Reads CPU info

      • firefox.exe (PID: 2756)
    • Creates files in the program directory

      • firefox.exe (PID: 2756)
    • Creates files in the user directory

      • firefox.exe (PID: 2756)
    • Application was dropped or rewritten from another process

      • NordVPNSetup.tmp (PID: 3524)
      • NordVPNSetup.tmp (PID: 1340)
      • dotnetfx48.exe (PID: 2244)
    • Loads dropped or rewritten executable

      • NordVPNSetup.tmp (PID: 1340)
    • Dropped object may contain Bitcoin addresses

      • Setup.exe (PID: 3460)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
91
Monitored processes
44
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe chrome.exe chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs chrome.exe no specs firefox.exe no specs chrome.exe no specs chrome.exe no specs winrar.exe nordvpnsetup.exe nordvpnsetup.tmp no specs nordvpnsetup.exe nordvpnsetup.tmp taskkill.exe no specs dotnetfx48.exe setup.exe setuputility.exe no specs setuputility.exe no specs tmp25f6.tmp.exe msiexec.exe msiexec.exe no specs nordvpnpatch.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
560"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NordVPNCrack.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1296"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1052,13697001085253785756,6890443649921692714,131072 --enable-features=PasswordImport --lang=en-US --instant-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1940 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1340"C:\Users\admin\AppData\Local\Temp\is-QNV78.tmp\NordVPNSetup.tmp" /SL5="$70186,55942334,893440,C:\Users\admin\Desktop\NordVPNCrack\NordVPNSetup.exe" /SPAWNWND=$1022A /NOTIFYWND=$10218 C:\Users\admin\AppData\Local\Temp\is-QNV78.tmp\NordVPNSetup.tmp
NordVPNSetup.exe
User:
admin
Company:
TEFINCOM S.A.
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-qnv78.tmp\nordvpnsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1372"C:\Windows\system32\taskkill.exe" /f /im NordVPN.exeC:\Windows\system32\taskkill.exeNordVPNSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
1404"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1052,13697001085253785756,6890443649921692714,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3288 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1456"C:\Users\admin\Desktop\NordVPNCrack\NordVPNPatch.exe" C:\Users\admin\Desktop\NordVPNCrack\NordVPNPatch.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\nordvpncrack\nordvpnpatch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1548SetupUtility.exe /screbootC:\9be0e8da0c6affc1af6dbc81\SetupUtility.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.5 Setup
Exit code:
0
Version:
14.8.3761.0 built by: NET48REL1
Modules
Images
c:\9be0e8da0c6affc1af6dbc81\setuputility.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1624"C:\Users\admin\Desktop\NordVPNCrack\NordVPNSetup.exe" /SPAWNWND=$1022A /NOTIFYWND=$10218 C:\Users\admin\Desktop\NordVPNCrack\NordVPNSetup.exe
NordVPNSetup.tmp
User:
admin
Company:
TEFINCOM S.A.
Integrity Level:
HIGH
Description:
NordVPN Installer
Exit code:
0
Version:
6.38.15.0
Modules
Images
c:\users\admin\desktop\nordvpncrack\nordvpnsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1796"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1052,13697001085253785756,6890443649921692714,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2512 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1896"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3676 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
53 671
Read events
53 318
Write events
349
Delete events
4

Modification events

(PID) Process:(3676) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3676) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3676) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30909833
(PID) Process:(3676) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3676) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30909833
(PID) Process:(3676) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3676) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3676) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3676) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3676) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
47
Suspicious files
219
Text files
410
Unknown types
98

Dropped files

PID
Process
Filename
Type
3964chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-613A1E00-F7C.pma
MD5:
SHA256:
3676iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF1579F98F1B1E9410.TMPgmc
MD5:
SHA256:
3676iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF2D9DF4E3DFFBE87D.TMPgmc
MD5:
SHA256:
3676iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{8C3700F2-117C-11EC-AC18-12A9866C77DE}.datbinary
MD5:
SHA256:
3676iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFF75F6CC28E3A8AD2.TMPgmc
MD5:
SHA256:
3676iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{8C3700F3-117C-11EC-AC18-12A9866C77DE}.datbinary
MD5:
SHA256:
3676iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF63C3DEBC1AEC10DE.TMPgmc
MD5:
SHA256:
3964chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\indexbinary
MD5:
SHA256:
3676iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
3676iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{8C3700F4-117C-11EC-AC18-12A9866C77DE}.datbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
55
TCP/UDP connections
130
DNS requests
198
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1084
svchost.exe
GET
304
69.16.175.10:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2599a1370b6a3aff
US
whitelisted
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/gpe7ohs3f5omwhxxpxvcdvkwva_1.3.36.101/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.101_win_adeodp7n5nw3wgk7xjdln2w2sgsq.crx3
US
whitelisted
3676
iexplore.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/Omniroot2025.crl
US
der
7.68 Kb
whitelisted
2756
firefox.exe
POST
200
142.250.185.195:80
http://ocsp.pki.goog/gts1o1core
US
der
471 b
whitelisted
2756
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
2756
firefox.exe
POST
200
142.250.185.195:80
http://ocsp.pki.goog/gts1o1core
US
der
471 b
whitelisted
2756
firefox.exe
POST
200
151.139.128.14:80
http://ocsp.sectigo.com/
US
der
471 b
whitelisted
2756
firefox.exe
POST
200
151.139.128.14:80
http://ocsp.sectigo.com/
US
der
471 b
whitelisted
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/gpe7ohs3f5omwhxxpxvcdvkwva_1.3.36.101/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.101_win_adeodp7n5nw3wgk7xjdln2w2sgsq.crx3
US
binary
9.70 Kb
whitelisted
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/gpe7ohs3f5omwhxxpxvcdvkwva_1.3.36.101/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.101_win_adeodp7n5nw3wgk7xjdln2w2sgsq.crx3
US
binary
5.64 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3676
iexplore.exe
69.16.175.10:80
ctldl.windowsupdate.com
Highwinds Network Group, Inc.
US
malicious
1896
iexplore.exe
66.203.127.18:443
mega.nz
RealNetworks, Inc.
US
suspicious
2504
chrome.exe
142.250.74.205:443
accounts.google.com
Google Inc.
US
whitelisted
3676
iexplore.exe
131.253.33.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
2504
chrome.exe
142.250.181.228:443
www.google.com
Google Inc.
US
whitelisted
3676
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2504
chrome.exe
216.58.212.138:443
fonts.googleapis.com
Google Inc.
US
whitelisted
2504
chrome.exe
142.250.185.174:443
clients2.google.com
Google Inc.
US
whitelisted
2504
chrome.exe
172.217.23.106:443
content-autofill.googleapis.com
Google Inc.
US
whitelisted
2504
chrome.exe
142.250.185.67:443
clientservices.googleapis.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
mega.nz
  • 66.203.127.18
  • 2a0b:e40:3::18
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 131.253.33.200
  • 13.107.22.200
whitelisted
ctldl.windowsupdate.com
  • 69.16.175.10
  • 69.16.175.42
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
clientservices.googleapis.com
  • 142.250.185.67
whitelisted
clients2.google.com
  • 142.250.185.174
whitelisted
accounts.google.com
  • 142.250.74.205
shared
www.google.com
  • 142.250.181.228
malicious

Threats

No threats detected
No debug info