File name: | IISCrypto.exe |
Full analysis: | https://app.any.run/tasks/d2533896-3843-44c4-88d9-58c89ca97057 |
Verdict: | Suspicious activity |
Analysis date: | April 03, 2018, 15:43:19 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
MD5: | 89EECBBC988F65CCC6EB17C8781BA9D6 |
SHA1: | 35E6F4EC7BBAF8FA13F395C00BB299F39F207D60 |
SHA256: | 537D2F7B9C494493ADF6E48E3821B985DC9FFD0717E758110F049AD21825A807 |
SSDEEP: | 3072:H0NcsAcZ74UJCZx5B34kGEv75jTlSwii7GvyduIQAsr5vTDTqJIR+BuB4jp38YLa:4ZZcA9gKwutN5vLqJIQBC4jR0rDr |
.exe | | | Win64 Executable (generic) (47.7) |
---|---|---|
.scr | | | Windows screen saver (22.6) |
.dll | | | Win32 Dynamic Link Library (generic) (11.3) |
.exe | | | Win32 Executable (generic) (7.7) |
.exe | | | Win16/32 Executable Delphi generic (3.5) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2016:07:16 18:36:50+02:00 |
PEType: | PE32 |
LinkerVersion: | 8 |
CodeSize: | 200704 |
InitializedDataSize: | 8704 |
UninitializedDataSize: | - |
EntryPoint: | 0x32f1e |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
FileVersionNumber: | 2.0.11.0 |
ProductVersionNumber: | 0.0.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | Secure IIS SSL/TLS |
CompanyName: | Nartac Software Inc. |
FileDescription: | IIS Crypto |
FileVersion: | 2.0.11.0 |
InternalName: | IISCrypto.Main.exe |
LegalCopyright: | Copyright © 2011-2016 Nartac Software Inc. |
LegalTrademarks: | - |
OriginalFileName: | IISCrypto.Main.exe |
ProductName: | IIS Crypto |
ProductVersion: | - |
AssemblyVersion: | 2.0.11.0 |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 16-Jul-2016 16:36:50 |
Debug artifacts: |
|
Comments: | Secure IIS SSL/TLS |
CompanyName: | Nartac Software Inc. |
FileDescription: | IIS Crypto |
FileVersion: | 2.0.11.0 |
InternalName: | IISCrypto.Main.exe |
LegalCopyright: | Copyright © 2011-2016 Nartac Software Inc. |
LegalTrademarks: | - |
OriginalFilename: | IISCrypto.Main.exe |
ProductName: | IIS Crypto |
ProductVersion: | - |
Assembly Version: | 2.0.11.0 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000080 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 3 |
Time date stamp: | 16-Jul-2016 16:36:50 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00002000 | 0x00030F24 | 0x00031000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.68192 |
.rsrc | 0x00034000 | 0x00001F23 | 0x00002000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.66734 |
.reloc | 0x00036000 | 0x0000000C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.0980042 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.28154 | 1239 | UNKNOWN | UNKNOWN | RT_MANIFEST |
2 | 4.6085 | 1128 | UNKNOWN | UNKNOWN | RT_ICON |
32512 | 2.21059 | 34 | UNKNOWN | UNKNOWN | RT_GROUP_ICON |
mscoree.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1700 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2620 CREDAT:79873 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2304 | "C:\Users\admin\AppData\Local\Temp\IISCrypto.exe" | C:\Users\admin\AppData\Local\Temp\IISCrypto.exe | — | explorer.exe | |||||||||||
User: admin Company: Nartac Software Inc. Integrity Level: MEDIUM Description: IIS Crypto Exit code: 3221226540 Version: 2.0.11.0 Modules
| |||||||||||||||
2620 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | — | IISCrypto.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 1 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3236 | "C:\Users\admin\AppData\Local\Temp\IISCrypto.exe" | C:\Users\admin\AppData\Local\Temp\IISCrypto.exe | explorer.exe | ||||||||||||
User: admin Company: Nartac Software Inc. Integrity Level: HIGH Description: IIS Crypto Exit code: 0 Version: 2.0.11.0 Modules
|
(PID) Process: | (3236) IISCrypto.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (3236) IISCrypto.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (3236) IISCrypto.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\91\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3236) IISCrypto.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F |
Operation: | write | Name: | Blob |
Value: 0F000000010000001400000084E608DD4CC47C78E2DE0F831405996C467FC35D090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B00000001000000420000005300740061007200740043006F006D002000430065007200740069006600690063006100740069006F006E00200041007500740068006F007200690074007900000053000000010000002500000030233021060B2B0601040181B53701010130123010060A2B0601040182373C0101030200C0620000000100000020000000C766A9BEF2D4071C863A31AA4920E813B2D198608CB7B7CFE21143B836DF09EA1400000001000000140000004E0BEF1AA4405BA517698730CA346843D041AEF21D0000000100000010000000155E81336FD96F7313CCB503B12F0E3C7E000000010000000800000000C00C0F7F39D3010300000001000000140000003E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F2000000001000000CD070000308207C9308205B1A003020102020101300D06092A864886F70D0101050500307D310B300906035504061302494C31163014060355040A130D5374617274436F6D204C74642E312B3029060355040B1322536563757265204469676974616C204365727469666963617465205369676E696E6731293027060355040313205374617274436F6D2043657274696669636174696F6E20417574686F72697479301E170D3036303931373139343633365A170D3336303931373139343633365A307D310B300906035504061302494C31163014060355040A130D5374617274436F6D204C74642E312B3029060355040B1322536563757265204469676974616C204365727469666963617465205369676E696E6731293027060355040313205374617274436F6D2043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A0282020100C188DB09BC6C467C789F957BB53390F27262D6C1362022245ECEE977F2430AA20664A4CC8E36F838E623F06E6DB13CDD72A3851CA1D33DB4332BD32FAFFEEAB0415967B6C4067D0A9E7485D6794C80377ADF39055259F7F41B4643A4D28585D2C371F3756234BA2C8A7F1E8FEEED34D011C796CD523DBA33D6DD4DDE0B3B4A4B9FC2262FFAB5161C723577CA3C5DE6CAE1268B1A36765C01DB741425FEEDB5A0880FDD78CA2D1F079730012D7279FA46D6132AA8B9A6AB83491DE5F2EFDDE4018E180A8F6353168562A90E193ACCB566A6C26B7407E42BE1763EB46DD8F644E173621F3BC4BEA05356256C5109F7AAABCABF76FD6D9BF39DDBBF3D66BC0C56AAAF9848953A4BDFA75850D93875A95BEA430C02FF99EBE86C4D705B29659CDDAA5DCCAF0131EC0CEBD28DE8EA9C7BE66EF727660C1A48D76E42E33FDE213E7BE10D70FB63AAA86C1A54B45C257AC9A2C98B16A6BB2C7E175E054D586E121D01EE12100DC6327F18FFFCF4FACD6E91E83649BE1A48698BC2964D1A12B26917C10A90D6FA792248BFBA7B69F870C7FA7A37D8D80DD2764F57FF90B7E391D2DDEFC260B7673ADDFEAA9CF0D48B7F7222CEC69F97B6F8AF8AA010A8D9FB18C6B6B55C523C89B6192A73010A0F03B31260F27A2F81DBA36EFF263097F58BDD8957B6AD3DB3AF2BC5B77602F0A5D62B9A86142A72F6E3338C5D094B13DFBB8C7413524B0203010001A38202523082024E300C0603551D13040530030101FF300B0603551D0F0404030201AE301D0603551D0E041604144E0BEF1AA4405BA517698730CA346843D041AEF230640603551D1F045D305B302CA02AA0288626687474703A2F2F636572742E7374617274636F6D2E6F72672F73667363612D63726C2E63726C302BA029A0278625687474703A2F2F63726C2E7374617274636F6D2E6F72672F73667363612D63726C2E63726C3082015D0603551D2004820154308201503082014C060B2B0601040181B5370101013082013B302F06082B060105050702011623687474703A2F2F636572742E7374617274636F6D2E6F72672F706F6C6963792E706466303506082B060105050702011629687474703A2F2F636572742E7374617274636F6D2E6F72672F696E7465726D6564696174652E7064663081D006082B060105050702023081C330271620537461727420436F6D6D65726369616C20285374617274436F6D29204C74642E30030201011A81974C696D69746564204C696162696C6974792C2072656164207468652073656374696F6E202A4C6567616C204C696D69746174696F6E732A206F6620746865205374617274436F6D2043657274696669636174696F6E20417574686F7269747920506F6C69637920617661696C61626C6520617420687474703A2F2F636572742E7374617274636F6D2E6F72672F706F6C6963792E706466301106096086480186F8420101040403020007303806096086480186F842010D042B16295374617274436F6D20467265652053534C2043657274696669636174696F6E20417574686F72697479300D06092A864886F70D01010505000382020100166C99F4660C34F5D0855E7D0AECDA104E381C5EDFA625054B9132C1E83BF13DDD44095B07498A29CB6602B7B19AF72598093C8E1BE1DD36872B4BBB68D339663DA026C7F239911D51AB827B7ED5CE5AE4E2035770699708F95E58A60ADF8C069A451616380A5E57F662C77A0205E6BC1EB5F29EF4A92983F8B214E36E288744C3901ADE38A93CAC434D6445CEDD28A95CF2737B04F817E8ABB1F32E5C646E73313A12B8BCB311E47D8F81519A3B8D89F44D93667B3C03EDD39A1D9AF36550F5A0D0759F2FAFF0EA824398F8699C8979C4438E4672E3643612AFF7251E388990777EC36B6AB9C3CB444BAC78908BE7C72C1E4B1144C8345227CD0A5D9F85C189D51A78F295105332DD80846675D9B56828FB612EBE84A838C0991286A51E6764AD062E2FA97085C7960F7C8965F58E43540EABDDA580399460C034C996702CA312F51F487BBD1C7E6BB79D90F4223BAEF8FC2ACAFA8252A0EFAF4B5593EBC1B5F0228BAC344E262204A1872C754AB7E57D13D7B80C64C036D2C92F86128C2309C11B823B7349A36A578794E5D678C5994363E34DE0772DE165997269041A4709E60F015624FB1FBF0E79A9582EB9C409017E95BA6D00063EB2EA4A1039D8D02BF5BFEC75BF9702C5091B08DC5537E281FB3784436220CAE7564B65EAFE6CC1249324A134EB05FF9A22AE9B7D3FF165510AA6306AB3F4881C800DFC728AE8835E | |||
(PID) Process: | (3236) IISCrypto.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F |
Operation: | write | Name: | Blob |
Value: 1900000001000000100000006D00C025527177CFA02E7D1FB659CC5B0300000001000000140000003E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F7E000000010000000800000000C00C0F7F39D3011D0000000100000010000000155E81336FD96F7313CCB503B12F0E3C1400000001000000140000004E0BEF1AA4405BA517698730CA346843D041AEF2620000000100000020000000C766A9BEF2D4071C863A31AA4920E813B2D198608CB7B7CFE21143B836DF09EA53000000010000002500000030233021060B2B0601040181B53701010130123010060A2B0601040182373C0101030200C00B00000001000000420000005300740061007200740043006F006D002000430065007200740069006600690063006100740069006F006E00200041007500740068006F0072006900740079000000090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070F000000010000001400000084E608DD4CC47C78E2DE0F831405996C467FC35D2000000001000000CD070000308207C9308205B1A003020102020101300D06092A864886F70D0101050500307D310B300906035504061302494C31163014060355040A130D5374617274436F6D204C74642E312B3029060355040B1322536563757265204469676974616C204365727469666963617465205369676E696E6731293027060355040313205374617274436F6D2043657274696669636174696F6E20417574686F72697479301E170D3036303931373139343633365A170D3336303931373139343633365A307D310B300906035504061302494C31163014060355040A130D5374617274436F6D204C74642E312B3029060355040B1322536563757265204469676974616C204365727469666963617465205369676E696E6731293027060355040313205374617274436F6D2043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A0282020100C188DB09BC6C467C789F957BB53390F27262D6C1362022245ECEE977F2430AA20664A4CC8E36F838E623F06E6DB13CDD72A3851CA1D33DB4332BD32FAFFEEAB0415967B6C4067D0A9E7485D6794C80377ADF39055259F7F41B4643A4D28585D2C371F3756234BA2C8A7F1E8FEEED34D011C796CD523DBA33D6DD4DDE0B3B4A4B9FC2262FFAB5161C723577CA3C5DE6CAE1268B1A36765C01DB741425FEEDB5A0880FDD78CA2D1F079730012D7279FA46D6132AA8B9A6AB83491DE5F2EFDDE4018E180A8F6353168562A90E193ACCB566A6C26B7407E42BE1763EB46DD8F644E173621F3BC4BEA05356256C5109F7AAABCABF76FD6D9BF39DDBBF3D66BC0C56AAAF9848953A4BDFA75850D93875A95BEA430C02FF99EBE86C4D705B29659CDDAA5DCCAF0131EC0CEBD28DE8EA9C7BE66EF727660C1A48D76E42E33FDE213E7BE10D70FB63AAA86C1A54B45C257AC9A2C98B16A6BB2C7E175E054D586E121D01EE12100DC6327F18FFFCF4FACD6E91E83649BE1A48698BC2964D1A12B26917C10A90D6FA792248BFBA7B69F870C7FA7A37D8D80DD2764F57FF90B7E391D2DDEFC260B7673ADDFEAA9CF0D48B7F7222CEC69F97B6F8AF8AA010A8D9FB18C6B6B55C523C89B6192A73010A0F03B31260F27A2F81DBA36EFF263097F58BDD8957B6AD3DB3AF2BC5B77602F0A5D62B9A86142A72F6E3338C5D094B13DFBB8C7413524B0203010001A38202523082024E300C0603551D13040530030101FF300B0603551D0F0404030201AE301D0603551D0E041604144E0BEF1AA4405BA517698730CA346843D041AEF230640603551D1F045D305B302CA02AA0288626687474703A2F2F636572742E7374617274636F6D2E6F72672F73667363612D63726C2E63726C302BA029A0278625687474703A2F2F63726C2E7374617274636F6D2E6F72672F73667363612D63726C2E63726C3082015D0603551D2004820154308201503082014C060B2B0601040181B5370101013082013B302F06082B060105050702011623687474703A2F2F636572742E7374617274636F6D2E6F72672F706F6C6963792E706466303506082B060105050702011629687474703A2F2F636572742E7374617274636F6D2E6F72672F696E7465726D6564696174652E7064663081D006082B060105050702023081C330271620537461727420436F6D6D65726369616C20285374617274436F6D29204C74642E30030201011A81974C696D69746564204C696162696C6974792C2072656164207468652073656374696F6E202A4C6567616C204C696D69746174696F6E732A206F6620746865205374617274436F6D2043657274696669636174696F6E20417574686F7269747920506F6C69637920617661696C61626C6520617420687474703A2F2F636572742E7374617274636F6D2E6F72672F706F6C6963792E706466301106096086480186F8420101040403020007303806096086480186F842010D042B16295374617274436F6D20467265652053534C2043657274696669636174696F6E20417574686F72697479300D06092A864886F70D01010505000382020100166C99F4660C34F5D0855E7D0AECDA104E381C5EDFA625054B9132C1E83BF13DDD44095B07498A29CB6602B7B19AF72598093C8E1BE1DD36872B4BBB68D339663DA026C7F239911D51AB827B7ED5CE5AE4E2035770699708F95E58A60ADF8C069A451616380A5E57F662C77A0205E6BC1EB5F29EF4A92983F8B214E36E288744C3901ADE38A93CAC434D6445CEDD28A95CF2737B04F817E8ABB1F32E5C646E73313A12B8BCB311E47D8F81519A3B8D89F44D93667B3C03EDD39A1D9AF36550F5A0D0759F2FAFF0EA824398F8699C8979C4438E4672E3643612AFF7251E388990777EC36B6AB9C3CB444BAC78908BE7C72C1E4B1144C8345227CD0A5D9F85C189D51A78F295105332DD80846675D9B56828FB612EBE84A838C0991286A51E6764AD062E2FA97085C7960F7C8965F58E43540EABDDA580399460C034C996702CA312F51F487BBD1C7E6BB79D90F4223BAEF8FC2ACAFA8252A0EFAF4B5593EBC1B5F0228BAC344E262204A1872C754AB7E57D13D7B80C64C036D2C92F86128C2309C11B823B7349A36A578794E5D678C5994363E34DE0772DE165997269041A4709E60F015624FB1FBF0E79A9582EB9C409017E95BA6D00063EB2EA4A1039D8D02BF5BFEC75BF9702C5091B08DC5537E281FB3784436220CAE7564B65EAFE6CC1249324A134EB05FF9A22AE9B7D3FF165510AA6306AB3F4881C800DFC728AE8835E | |||
(PID) Process: | (3236) IISCrypto.exe | Key: | HKEY_CURRENT_USER\Software\Nartac\IIS Crypto |
Operation: | write | Name: | LicenseAccepted |
Value: 1 | |||
(PID) Process: | (3236) IISCrypto.exe | Key: | HKEY_CURRENT_USER\Software\Nartac\IIS Crypto |
Operation: | write | Name: | LastCheckForUpdates |
Value: 4/3/2018 3:44:33 PM | |||
(PID) Process: | (3236) IISCrypto.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IISCrypto_RASAPI32 |
Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
(PID) Process: | (3236) IISCrypto.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IISCrypto_RASAPI32 |
Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
(PID) Process: | (3236) IISCrypto.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IISCrypto_RASAPI32 |
Operation: | write | Name: | FileTracingMask |
Value: 4294901760 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3236 | IISCrypto.exe | C:\Users\admin\AppData\Local\Temp\CabC898.tmp | — | |
MD5:— | SHA256:— | |||
3236 | IISCrypto.exe | C:\Users\admin\AppData\Local\Temp\TarC899.tmp | — | |
MD5:— | SHA256:— | |||
3236 | IISCrypto.exe | C:\Users\admin\AppData\Local\Temp\CabC8A9.tmp | — | |
MD5:— | SHA256:— | |||
3236 | IISCrypto.exe | C:\Users\admin\AppData\Local\Temp\TarC8AA.tmp | — | |
MD5:— | SHA256:— | |||
3236 | IISCrypto.exe | C:\Users\admin\AppData\Local\Temp\CabE924.tmp | — | |
MD5:— | SHA256:— | |||
3236 | IISCrypto.exe | C:\Users\admin\AppData\Local\Temp\TarE925.tmp | — | |
MD5:— | SHA256:— | |||
2620 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFC4261D9D870C4ABF.TMP | — | |
MD5:— | SHA256:— | |||
2620 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF68285C273F7DBFC1.TMP | — | |
MD5:— | SHA256:— | |||
2620 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFABB75EC8BA420DA0.TMP | — | |
MD5:— | SHA256:— | |||
2620 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FAB289D4-3755-11E8-B3BE-5254004AAD21}.dat | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.16.186.96:80 | http://ocsp.startssl.com/sub/class2/code/ca/MEgwRjBEMEIwQDAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCBxF5suAthUA%3D | unknown | der | 1.66 Kb | whitelisted |
— | — | GET | 200 | 2.16.186.96:80 | http://ocsp.startssl.com/ca/MEgwRjBEMEIwQDAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvvGqRAW6UXaYcwyjRoQ9BBrvICBxAA9evgOUM%3D | unknown | der | 1.72 Kb | whitelisted |
— | — | GET | 304 | 2.16.186.81:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.186.82:80 | http://aia.startssl.com/certs/ca.crt | unknown | der | 1.95 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 2.16.186.82:80 | aia.startssl.com | Akamai International B.V. | — | whitelisted |
— | — | 2.16.186.81:80 | www.download.windowsupdate.com | Akamai International B.V. | — | whitelisted |
— | — | 2.16.186.96:80 | ocsp.startssl.com | Akamai International B.V. | — | whitelisted |
— | — | 2.16.186.57:80 | crl.startssl.com | Akamai International B.V. | — | whitelisted |
— | — | 168.62.211.100:443 | update.nartac.com | Microsoft Corporation | US | whitelisted |
— | — | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
— | — | 13.107.21.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
— | — | 64.41.200.100:443 | www.ssllabs.com | QUALYS, Inc. | US | malicious |
Domain | IP | Reputation |
---|---|---|
aia.startssl.com |
| whitelisted |
www.download.windowsupdate.com |
| whitelisted |
ocsp.startssl.com |
| whitelisted |
crl.startssl.com |
| whitelisted |
update.nartac.com |
| suspicious |
dns.msftncsi.com |
| shared |
www.bing.com |
| whitelisted |
www.ssllabs.com |
| malicious |