URL: | https://go.microsoft.com/fwlink/?LinkId=389361 |
Full analysis: | https://app.any.run/tasks/5aed6069-7675-4a80-99e5-fd1d80e433c9 |
Verdict: | Malicious activity |
Analysis date: | October 02, 2020, 02:39:58 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | CB6B0EC6379E4ED3D469374EC9EFCF45 |
SHA1: | 9CCAC10B3B8DFF96643FB0D5E973C2EB8AFEB23B |
SHA256: | 5C2996E7961A2A8B59992694AA8D8FF34FB90CFCDD69E29266A6ED3A3DD82F3F |
SSDEEP: | 3:N8r8etR7LOCdq:2geDPOCdq |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2080 | "C:\Program Files\Internet Explorer\iexplore.exe" https://go.microsoft.com/fwlink/?LinkId=389361 | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
3908 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2080 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
|
(PID) Process: | (3908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (3908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (3908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (2080) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 1817141582 | |||
(PID) Process: | (2080) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30840933 | |||
(PID) Process: | (2080) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (2080) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (2080) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (2080) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
(PID) Process: | (2080) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3908 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Cab7928.tmp | — | |
MD5:— | SHA256:— | |||
3908 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Tar7929.tmp | — | |
MD5:— | SHA256:— | |||
3908 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\fix-error-code-550-4-4-7-in-exchange-online[1].htm | html | |
MD5:DF2238F61025DA21F35AB1B240BC8765 | SHA256:8EDB390190CFA50D7F2410A657B7656E3DE5A1E2496198E8513D5149C1F24A98 | |||
3908 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\fetch.umd.min[1].js | text | |
MD5:426331495A2310E355C95C3CABB8CF94 | SHA256:50A4426A6989263C4FCE8242EC99518ACF9F216B88043C75D10C764BF732BF17 | |||
3908 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_88614FFAD35D353421B8A7E1FE18FCE4 | binary | |
MD5:68660C8FA4EFFEB72399AF90622C0E6B | SHA256:C4332428CFA6C2380C12303405C288491FA55131590242EFCBB81D63547E5AF0 | |||
3908 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\2e5ce4ab.conceptual[1].css | text | |
MD5:54245540CD1424FE4D780E804E8B88F7 | SHA256:3EE2889EAE3BDE597280F041DE24909E4254A98757A112DE9002D433C584C2A0 | |||
3908 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\template.min[1].js | text | |
MD5:6DAED083086C521D306F7D9F77B8533B | SHA256:B1421EF2407B4F269D9E9083A99CF3219FF24BEDE5DEAC557AAF60108F197724 | |||
3908 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_BEB37ABADF39714871232B4792417E04 | binary | |
MD5:582F65967E84531E0A1382A77C948D1F | SHA256:BEF031F85419B029B118B354F2D3146364EBF8EF5CF365A7F45CDCC44070BCE3 | |||
3908 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\86c42004.site-ltr[1].css | text | |
MD5:654436667F80FD9B67A05222A5C8F56A | SHA256:B79B6E0D3C3EED731BC680FF4A9D7A5E692E268E6CD5952CD8783491B6E14F3F | |||
3908 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_BEB37ABADF39714871232B4792417E04 | der | |
MD5:25BA2EECB076727EDE28F5997B4F1036 | SHA256:C53FF850B2BB2CBA4961BF5E39A26D683735F9C9BCA0D161F34A6A6D0B2BDDF6 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3908 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAi4elAbvpzaLRZNPjlRv1U%3D | US | der | 1.47 Kb | whitelisted |
3908 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D | US | der | 1.47 Kb | whitelisted |
1056 | svchost.exe | GET | 200 | 172.217.22.67:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjqTAc%2FHIGOD%2BaUx0%3D | US | der | 492 b | whitelisted |
1056 | svchost.exe | GET | 200 | 2.16.186.120:80 | http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl | unknown | der | 781 b | whitelisted |
1056 | svchost.exe | GET | 200 | 2.16.186.120:80 | http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl | unknown | der | 550 b | whitelisted |
3908 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAiIzVJfGSRETRSlgpHeuVI%3D | US | der | 1.47 Kb | whitelisted |
1056 | svchost.exe | GET | 200 | 172.217.22.67:80 | http://ocsp.pki.goog/GTSGIAG3/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCCC7Rp3EQG0zo | US | binary | 5 b | whitelisted |
1056 | svchost.exe | GET | 200 | 2.16.186.56:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | unknown | compressed | 57.5 Kb | whitelisted |
1056 | svchost.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3D | US | der | 471 b | whitelisted |
1056 | svchost.exe | GET | 200 | 172.217.22.67:80 | http://ocsp.pki.goog/GTSGIAG3/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCCHX2nnAAq%2F8G | US | binary | 5 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3908 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2080 | iexplore.exe | 104.111.242.152:443 | docs.microsoft.com | Akamai International B.V. | NL | suspicious |
3908 | iexplore.exe | 152.199.19.160:443 | az725175.vo.msecnd.net | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3908 | iexplore.exe | 13.107.246.10:443 | wcpstatic.microsoft.com | Microsoft Corporation | US | whitelisted |
3908 | iexplore.exe | 104.111.242.152:443 | docs.microsoft.com | Akamai International B.V. | NL | suspicious |
3908 | iexplore.exe | 104.109.95.91:443 | go.microsoft.com | Akamai International B.V. | NL | unknown |
3908 | iexplore.exe | 104.18.25.243:80 | ocsp.msocsp.com | Cloudflare Inc | US | shared |
1056 | svchost.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2080 | iexplore.exe | 13.107.21.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2080 | iexplore.exe | 152.199.19.161:443 | iecvlist.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
go.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
docs.microsoft.com |
| whitelisted |
az725175.vo.msecnd.net |
| whitelisted |
wcpstatic.microsoft.com |
| whitelisted |
ocsp.msocsp.com |
| whitelisted |
www.bing.com |
| whitelisted |
api.bing.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |