URL:

https://www.proflit.ru/Basket/Cart/SaleDirect?partnersId=77&accountNumber=40702810338050017071&contactId=64743134-0223-442c-b0f1-3f84c71bbbde&dateStart=2025-06-01&emid=811&typeAction=addToCart&category1=811&actionValue=none&campaignNumber=2042989151&priceLevelId=01e4b0ea-874f-4ab9-bbb3-e632d451f7a4&appid=265&category2=265&promoCodeId=464FF6FE-E310-EA11-BBA4-00155D627F03&btx=20530968

Full analysis: https://app.any.run/tasks/acc65a31-4ecd-47f6-9e3a-fc0bea0bb874
Verdict: Malicious activity
Analysis date: May 10, 2025, 03:23:51
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
phishing
websocket
MD5:

B8D1B54EE5DAFEA3803345D761072083

SHA1:

D06799C1625DF5B8F54DFB60E2EA641C63B461CF

SHA256:

62D4D3B8E4843208307451B66E040F52872DEFA5FE377B52E3896E0B1698EE4F

SSDEEP:

12:2V3Xat8w6iPA4KEB+XAPRuQYt3ajd5S8n:2V3mcuoAPcQu8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
0
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

No data
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
299
TCP/UDP connections
212
DNS requests
152
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
302
95.214.58.157:443
https://www.proflit.ru/Basket/Cart/SaleDirect?partnersId=77&accountNumber=40702810338050017071&contactId=64743134-0223-442c-b0f1-3f84c71bbbde&dateStart=2025-06-01&emid=811&typeAction=addToCart&category1=811&actionValue=none&campaignNumber=2042989151&priceLevelId=01e4b0ea-874f-4ab9-bbb3-e632d451f7a4&appid=265&category2=265&promoCodeId=464FF6FE-E310-EA11-BBA4-00155D627F03&btx=20530968
unknown
html
154 b
POST
200
40.126.32.72:443
https://login.live.com/RST2.srf
unknown
xml
1.24 Kb
whitelisted
GET
302
95.214.59.170:443
https://api.action-media.ru/fake-pages/cookiesync?csopid=7ef0eca5-2c30-4d1c-a203-d0bad6d4d2bd&targetUri=www.proflit.ru%2FBasket%2FCart%2FSaleDirect%3FpartnersId%3D77%26accountNumber%3D40702810338050017071%26contactId%3D64743134-0223-442c-b0f1-3f84c71bbbde%26dateStart%3D2025-06-01%26emid%3D811%26typeAction%3DaddToCart%26category1%3D811%26actionValue%3Dnone%26campaignNumber%3D2042989151%26priceLevelId%3D01e4b0ea-874f-4ab9-bbb3-e632d451f7a4%26appid%3D265%26category2%3D265%26promoCodeId%3D464FF6FE-E310-EA11-BBA4-00155D627F03%26btx%3D20530968
unknown
POST
200
20.190.160.66:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
text
16.7 Kb
whitelisted
POST
403
184.30.21.171:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
unknown
html
386 b
whitelisted
3080
MoUsoCoreWorker.exe
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1984
svchost.exe
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2208
RUXIMICS.exe
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
POST
403
184.30.21.171:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
unknown
html
386 b
whitelisted
POST
403
184.30.21.171:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
unknown
html
386 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3080
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
239.255.255.250:1900
whitelisted
1984
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2208
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1396
msedge.exe
95.214.58.157:443
www.proflit.ru
Action-digital LLC
RU
unknown
4396
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1396
msedge.exe
95.214.58.160:443
api.action-media.ru
Action-digital LLC
RU
whitelisted
3080
MoUsoCoreWorker.exe
23.216.77.21:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6432
msedge.exe
224.0.0.251:5353
unknown
1984
svchost.exe
23.216.77.21:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 216.58.212.174
whitelisted
www.proflit.ru
  • 95.214.58.157
  • 95.214.58.156
  • 95.214.59.156
  • 95.214.59.157
unknown
login.live.com
  • 20.190.160.20
  • 20.190.160.131
  • 20.190.160.5
  • 40.126.32.140
  • 40.126.32.134
  • 20.190.160.14
  • 40.126.32.68
  • 40.126.32.72
whitelisted
api.action-media.ru
  • 95.214.58.160
  • 95.214.59.170
whitelisted
crl.microsoft.com
  • 23.216.77.21
  • 23.216.77.27
  • 23.216.77.18
whitelisted
go.microsoft.com
  • 184.30.18.9
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
  • 2.16.241.201
  • 2.16.241.218
  • 104.126.37.170
  • 104.126.37.155
  • 104.126.37.129
  • 104.126.37.163
  • 104.126.37.128
  • 104.126.37.162
  • 2.19.96.128
  • 2.19.96.120
whitelisted
code.jivosite.com
  • 5.101.37.37
whitelisted

Threats

PID
Process
Class
Message
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Suspicious message detected (saved from)
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Suspicious message detected (saved from)
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
No debug info