URL: | http://svntrk.com |
Full analysis: | https://app.any.run/tasks/5a643d56-8f8a-45aa-9130-f8134bac6319 |
Verdict: | Malicious activity |
Analysis date: | August 12, 2022, 16:58:00 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | ACA2138536DD58B8AD23B01076131CF1 |
SHA1: | B7B0C7205BAEC4A30B7771EC00BB2C4B715807F0 |
SHA256: | 64651696DE724BD257F548ED9C885C91F7F7248BE9A9A9BA177FD36AFE9E42A0 |
SSDEEP: | 3:N1KNTNkGT:C7kGT |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2644 | "C:\Program Files\Internet Explorer\iexplore.exe" "http://svntrk.com" | C:\Program Files\Internet Explorer\iexplore.exe | Explorer.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
3784 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2644 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
3784 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Tar93D5.tmp | cat | |
MD5:7EE994C83F2744D702CBA18693ED1758 | SHA256:5DB917AB6DC8A42A43617850DFBE2C7F26A7F810B229B349E9DD2A2D615671D2 | |||
3784 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Cab93D4.tmp | compressed | |
MD5:589C442FC7A0C70DCA927115A700D41E | SHA256:2E5CB72E9EB43BAAFB6C6BFCC573AAC92F49A8064C483F9D378A9E8E781A526A | |||
3784 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:E7EE95067DE3F44CF1E1C767A6AE6EA2 | SHA256:500E90D8B6BDA38868BEAEA8C87335D1518A3C5EE9A6DD63F59E44314559B02F | |||
3784 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\45F37975FF0DACF951A8A9C46F6C9C5F | binary | |
MD5:92B28CE5890A70950F4DAE7A02489D6B | SHA256:14EA816B928FF30F50AD28659FC2FD15796B2D24D21B204ECB6028CFC614F4F5 | |||
3784 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:589C442FC7A0C70DCA927115A700D41E | SHA256:2E5CB72E9EB43BAAFB6C6BFCC573AAC92F49A8064C483F9D378A9E8E781A526A | |||
3784 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:6572166E6D318254B5468BB00F6214DF | SHA256:31D4DDDF7E74673954107F0C27A401E9A0E8B2B9045ECF0EA30E6298C49A5704 | |||
3784 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:CE47C756139454B13651A560152FE65B | SHA256:8180E3D9D72CC9ED28C1F3D4D2B053434919CEB20194C32D2B03C250FC2E6F08 | |||
2644 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63 | der | |
MD5:EE87BB11E233C12009CC11725035DBDC | SHA256:D82930A5B051B3C3F1639C24E83BDDF41D5AA66E467A0944D1AC3D59AE6330C5 | |||
3784 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81B | binary | |
MD5:E59147A89DCA78C312D1AB96B3A3DB49 | SHA256:A803B7026CC6330016207619B473E30F98A98AC0B625C2919D1128E29152957F | |||
2644 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63 | binary | |
MD5:72ACC3249FBEF1F4D1EF2C9126B50155 | SHA256:00F1D757A7B1669BCF52CD2C4B97A61B233150775D5A88C26F3268CE516E4E43 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3784 | iexplore.exe | GET | 200 | 151.101.2.133:80 | http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDC%2BpFRjBGCzh9lTZZA%3D%3D | US | der | 1.40 Kb | whitelisted |
3784 | iexplore.exe | GET | 200 | 151.101.2.133:80 | http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDAVP5sB10trZbAg5rQ%3D%3D | US | der | 1.40 Kb | whitelisted |
3784 | iexplore.exe | GET | 200 | 151.101.2.133:80 | http://ocsp.globalsign.com/gseccovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSTMjK03nNiYoQYvu4Izyfn9OJNdAQUWHuOdSr%2BYYCqkEABrtboB0ZuP0gCDEQg1Y49A9QQ%2BwVA7A%3D%3D | US | der | 940 b | whitelisted |
2644 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D | US | der | 1.47 Kb | whitelisted |
3784 | iexplore.exe | GET | 301 | 188.114.96.3:80 | http://svntrk.com/ | US | html | 178 b | malicious |
3784 | iexplore.exe | GET | 200 | 2.16.186.9:80 | http://e1.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBTvkAFw3ViPKmUeIVEf3NC7b1ErqwQUWvPtK%2Fw2wjd5uVIw6lRvz1XLLqwCEgT9TCB2ui7kO%2BPih7dbNWC%2Bvg%3D%3D | unknown | der | 346 b | whitelisted |
3784 | iexplore.exe | GET | 200 | 151.101.194.133:80 | http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D | US | der | 1.40 Kb | whitelisted |
3784 | iexplore.exe | GET | 200 | 151.101.194.133:80 | http://ocsp2.globalsign.com/rootr5/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQiD0S5cIHyfrLTJ1fvAkJWflH%2B2QQUPeYpSJvqB8ohREom3m7e0oPQn1kCDQHuXyKVQkkF%2BQGRqNw%3D | US | der | 1.26 Kb | whitelisted |
3784 | iexplore.exe | GET | 200 | 151.101.2.133:80 | http://ocsp.globalsign.com/rootr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHUeP1PjGFkz6V8I7O6tApc%3D | US | der | 1.41 Kb | whitelisted |
3784 | iexplore.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2f41350c62011e65 | US | compressed | 60.2 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3784 | iexplore.exe | 188.114.96.3:80 | svntrk.com | Cloudflare Inc | US | malicious |
3784 | iexplore.exe | 96.16.145.230:80 | x1.c.lencr.org | Akamai Technologies, Inc. | US | suspicious |
3784 | iexplore.exe | 188.114.96.3:443 | svntrk.com | Cloudflare Inc | US | malicious |
3784 | iexplore.exe | 2.16.186.9:80 | e1.o.lencr.org | Akamai International B.V. | — | whitelisted |
3784 | iexplore.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2644 | iexplore.exe | 131.253.33.200:443 | www.bing.com | Microsoft Corporation | US | whitelisted |
3784 | iexplore.exe | 151.101.2.133:80 | ocsp.globalsign.com | Fastly | US | malicious |
3784 | iexplore.exe | 87.250.251.77:443 | metrica.yandex.com | YANDEX LLC | RU | unknown |
3784 | iexplore.exe | 151.101.194.133:80 | ocsp.globalsign.com | Fastly | US | suspicious |
2644 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
svntrk.com |
| malicious |
ctldl.windowsupdate.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
x2.c.lencr.org |
| whitelisted |
e1.o.lencr.org |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
metrica.yandex.com |
| whitelisted |
ocsp.globalsign.com |
| whitelisted |