URL: | https://u6409736.ct.sendgrid.net/ls/click?upn=hFRyAOWJqNVu8NXJyJSca8h1Yyh4oD533C0BFa97JZmlcK8NFnknKM6Aoi0FxDBLrBpA_xFjeGo6PQplDh-2FGEMLxWrpJ7UoCZLZr3Xz-2Fcn4eGgN6NOFkK-2Bk7TIQQJ-2BIZJ9XVedPXtUCqt72YuDwuuZ-2Fml4lqDnCFoMcuW8mx41vm-2FUgdj60WbLNBzCkkfkDFMfBSWs1SrIG2BN0jlROBZLnKFM9TJ6fQsmM9TOlNdVsj6Dxi6U01M3k8d0TD2CgiFAYrTqtHlUF5KHooehkJ2YzanyQ-3D-3D |
Full analysis: | https://app.any.run/tasks/1833270a-2e1e-4802-b73d-0d8116a791a8 |
Verdict: | Malicious activity |
Analysis date: | January 24, 2022, 19:53:36 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | 475B48367574600EA86DEAAB190DDD81 |
SHA1: | AC3055CF6A74B1BFBC2DF8E79CD781169698441E |
SHA256: | 60F55D0063EAB62A4E26D3EC08136A02A0A9E1305F50187133E65DB2BCED25C6 |
SSDEEP: | 6:22TY6xC3c6Q0NU818oLjvIoIFRz/uqncvMw9SyjoJcUK1XjeOheq+Shgsppy5:22sSC3c67G82CvmzcvMw9ZkCUK1iOh3I |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1816 | "C:\Program Files\Internet Explorer\iexplore.exe" "https://u6409736.ct.sendgrid.net/ls/click?upn=hFRyAOWJqNVu8NXJyJSca8h1Yyh4oD533C0BFa97JZmlcK8NFnknKM6Aoi0FxDBLrBpA_xFjeGo6PQplDh-2FGEMLxWrpJ7UoCZLZr3Xz-2Fcn4eGgN6NOFkK-2Bk7TIQQJ-2BIZJ9XVedPXtUCqt72YuDwuuZ-2Fml4lqDnCFoMcuW8mx41vm-2FUgdj60WbLNBzCkkfkDFMfBSWs1SrIG2BN0jlROBZLnKFM9TJ6fQsmM9TOlNdVsj6Dxi6U01M3k8d0TD2CgiFAYrTqtHlUF5KHooehkJ2YzanyQ-3D-3D" | C:\Program Files\Internet Explorer\iexplore.exe | Explorer.EXE | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) | ||||
4044 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1816 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) |
PID | Process | Filename | Type | |
---|---|---|---|---|
4044 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6A2279C2CA42EBEE26F14589F0736E50 | der | |
MD5:8B153254225CF81983BAA0400492B53E | SHA256:A3EB96967C5F501B5E14CF4E0A2BB4B9DFA8933352C973A1EAE89C321804BC25 | |||
4044 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EB2C4AB8B68FFA4B7733A9139239A396_D76DB901EE986B889F30D8CC06229E2D | binary | |
MD5:6419505F7A595C495DD047B752082441 | SHA256:A82395FCEAF8B6E97EB850E729515C5E2B7A6215C9A7051C59FBC5CD282E6DE2 | |||
4044 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_93E4B2BA79A897B3100CCB27F2D3BF4F | der | |
MD5:CC0C289EA7D427477ACE1B0A0DB02D54 | SHA256:A7A7E062E466C1F51B146C74B9C252AF0BCAC6D9DE256E85384A972BA13BE432 | |||
4044 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 | der | |
MD5:E9953511B806D96C85112D07C44DE02A | SHA256:86008864D275A5005CDEE88B0DF9E38009AB1F28E731673403DDCD89078A381B | |||
4044 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771 | binary | |
MD5:1F66065935F18072E6BFA6996BE5499E | SHA256:85016B0B34137EA5DD8F1513F663703123C26999510028D43DBEB6D5101A278C | |||
4044 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C5FD5BF0CE6372B1CAFE381FD0BC969C | binary | |
MD5:6B2046A7F0A49DD8B933D7192FF0C85E | SHA256:30FFE8147B10268AB29455AAE3583F4056A5C880E0663152AD740C1FA38EC828 | |||
4044 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:31CE8F586B670FF6BC7DA1FBE8949B6A | SHA256:794356C49EC4D1FD2CA045FBFA5762F9BF54E65CF78B30D40F757499F3DFF159 | |||
4044 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C5FD5BF0CE6372B1CAFE381FD0BC969C | der | |
MD5:05A107E6DC6505593DCF49D3741E740A | SHA256:8780E23F6600511AB4F8B5201E888FFA258C3C0E00A95A5B7E13B01AB197632D | |||
1816 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63 | binary | |
MD5:52E5A9F76112A99BA7FDF3B01BAF3E25 | SHA256:817E65E79C08A3C18F0497C39F061A5046E46DBACFE96596191C7F6E1107C208 | |||
4044 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 | binary | |
MD5:FEAB4AA2520A05B6DC8C77D9BAB7B585 | SHA256:83C85D279D95FE760275BC6FC3B4E91FFBC24B7082836B07D3D8AEFD61FB1853 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4044 | iexplore.exe | GET | 200 | 52.222.206.67:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D | US | der | 1.39 Kb | shared |
1816 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D | US | der | 1.47 Kb | whitelisted |
4044 | iexplore.exe | GET | 200 | 52.222.206.35:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
4044 | iexplore.exe | GET | 200 | 192.124.249.41:80 | http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D | US | der | 1.69 Kb | whitelisted |
4044 | iexplore.exe | GET | 200 | 192.124.249.41:80 | http://crl.godaddy.com/gdroot.crl | US | der | 429 b | whitelisted |
4044 | iexplore.exe | GET | 200 | 192.124.249.41:80 | http://ocsp.godaddy.com//MEkwRzBFMEMwQTAJBgUrDgMCGgUABBS2CA1fbGt26xPkOKX4ZguoUjM0TgQUQMK9J47MNIMwojPX%2B2yz8LQsgM4CCAFQWPc8P68%2F | US | der | 1.74 Kb | whitelisted |
4044 | iexplore.exe | GET | 200 | 192.124.249.24:80 | http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D | US | der | 1.66 Kb | whitelisted |
4044 | iexplore.exe | GET | 200 | 18.66.92.168:80 | http://s.ss2.us/r.crl | US | der | 434 b | whitelisted |
4044 | iexplore.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?10b36a5eed54e262 | US | compressed | 4.70 Kb | whitelisted |
4044 | iexplore.exe | GET | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQC2PrP09fGo%2BgoAAAABK3x6 | US | der | 472 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4044 | iexplore.exe | 192.124.249.41:80 | ocsp.godaddy.com | Sucuri | US | suspicious |
1816 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
4044 | iexplore.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | Highwinds Network Group, Inc. | US | whitelisted |
4044 | iexplore.exe | 192.124.249.24:80 | ocsp.godaddy.com | Sucuri | US | suspicious |
4044 | iexplore.exe | 167.89.115.54:443 | u6409736.ct.sendgrid.net | SendGrid, Inc. | US | suspicious |
4044 | iexplore.exe | 18.66.92.28:80 | o.ss2.us | Massachusetts Institute of Technology | US | suspicious |
— | — | 131.253.33.200:443 | www.bing.com | Microsoft Corporation | US | whitelisted |
4044 | iexplore.exe | 18.66.92.168:80 | s.ss2.us | Massachusetts Institute of Technology | US | unknown |
4044 | iexplore.exe | 52.73.106.208:443 | www.sec3ure.com | Amazon.com, Inc. | US | unknown |
1816 | iexplore.exe | 131.253.33.200:443 | www.bing.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
u6409736.ct.sendgrid.net |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.godaddy.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl.godaddy.com |
| whitelisted |
www.sec3ure.com |
| unknown |
o.ss2.us |
| whitelisted |
s.ss2.us |
| whitelisted |