URL:

https://linkvertise.com/258316/your-of-folder-here-89ycz?o=sharing

Full analysis: https://app.any.run/tasks/d19cfbd0-15c1-41c3-ac8b-91023b83fdc0
Verdict: Malicious activity
Analysis date: January 06, 2022, 10:22:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

F4C877CA62819FD1EE6C1CA4882809CE

SHA1:

DA37AC719E5B38764541BD81A44B5E6C122C7808

SHA256:

68F0645781B46C9A941DBC27B5AD1EB8E8931CCE217D2733A2CB900B6913F679

SSDEEP:

3:N8MLRBXAyTK4WRcWybNAXvcJ7NE6C:2MNi27icMXvcQ6C

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 1700)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 2444)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 2556)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 520)
    • Application was dropped or rewritten from another process

      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 1700)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 2444)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 2556)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 520)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 3304)
      • iexplore.exe (PID: 1108)
      • iexplore.exe (PID: 1072)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 1964)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 1964)
      • chrome.exe (PID: 1768)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 1700)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 2444)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2980)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 2556)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 520)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 484)
    • Drops a file with a compile date too recent

      • chrome.exe (PID: 1768)
    • Checks supported languages

      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 1700)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 4036)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 2444)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2980)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 2556)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 520)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2492)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 484)
    • Reads the computer name

      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 4036)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2980)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2492)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 484)
    • Reads Windows owner or organization settings

      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2980)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 484)
    • Reads the Windows organization settings

      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2980)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 484)
    • Drops a file that was compiled in debug mode

      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2980)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 484)
    • Drops a file with too old compile date

      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2980)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 484)
    • Starts Internet Explorer

      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 484)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 3756)
      • iexplore.exe (PID: 3304)
      • chrome.exe (PID: 1964)
      • chrome.exe (PID: 1456)
      • chrome.exe (PID: 3364)
      • chrome.exe (PID: 1768)
      • chrome.exe (PID: 508)
      • chrome.exe (PID: 2700)
      • chrome.exe (PID: 3644)
      • chrome.exe (PID: 2244)
      • chrome.exe (PID: 1008)
      • chrome.exe (PID: 3664)
      • chrome.exe (PID: 2752)
      • chrome.exe (PID: 344)
      • chrome.exe (PID: 2916)
      • chrome.exe (PID: 1748)
      • chrome.exe (PID: 2460)
      • chrome.exe (PID: 2456)
      • chrome.exe (PID: 2464)
      • chrome.exe (PID: 268)
      • chrome.exe (PID: 2188)
      • chrome.exe (PID: 2696)
      • chrome.exe (PID: 3196)
      • chrome.exe (PID: 2436)
      • chrome.exe (PID: 4032)
      • chrome.exe (PID: 3692)
      • chrome.exe (PID: 3692)
      • chrome.exe (PID: 4060)
      • chrome.exe (PID: 2220)
      • chrome.exe (PID: 2180)
      • chrome.exe (PID: 2916)
      • chrome.exe (PID: 1520)
      • chrome.exe (PID: 1244)
      • chrome.exe (PID: 3276)
      • chrome.exe (PID: 1572)
      • chrome.exe (PID: 3676)
      • chrome.exe (PID: 3356)
      • chrome.exe (PID: 1704)
      • chrome.exe (PID: 448)
      • iexplore.exe (PID: 1108)
      • explorer.exe (PID: 3660)
      • iexplore.exe (PID: 1072)
      • iexplore.exe (PID: 2784)
    • Reads the computer name

      • iexplore.exe (PID: 3756)
      • iexplore.exe (PID: 3304)
      • chrome.exe (PID: 1964)
      • chrome.exe (PID: 3364)
      • chrome.exe (PID: 1768)
      • chrome.exe (PID: 2244)
      • chrome.exe (PID: 2460)
      • chrome.exe (PID: 2456)
      • chrome.exe (PID: 2220)
      • chrome.exe (PID: 3356)
      • chrome.exe (PID: 3676)
      • iexplore.exe (PID: 1108)
      • explorer.exe (PID: 3660)
      • iexplore.exe (PID: 2784)
      • iexplore.exe (PID: 1072)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3304)
      • iexplore.exe (PID: 3756)
      • chrome.exe (PID: 1768)
      • chrome.exe (PID: 1964)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2980)
      • iexplore.exe (PID: 1108)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 484)
      • iexplore.exe (PID: 1072)
    • Application launched itself

      • iexplore.exe (PID: 3756)
      • chrome.exe (PID: 1964)
      • iexplore.exe (PID: 2784)
    • Creates files in the user directory

      • iexplore.exe (PID: 3304)
      • iexplore.exe (PID: 3756)
      • iexplore.exe (PID: 1108)
      • iexplore.exe (PID: 1072)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3756)
      • iexplore.exe (PID: 1072)
    • Changes internet zones settings

      • iexplore.exe (PID: 3756)
      • iexplore.exe (PID: 2784)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3304)
      • iexplore.exe (PID: 3756)
      • chrome.exe (PID: 1964)
      • iexplore.exe (PID: 1108)
      • iexplore.exe (PID: 1072)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3304)
      • iexplore.exe (PID: 1108)
      • iexplore.exe (PID: 1072)
    • Manual execution by user

      • chrome.exe (PID: 1964)
      • explorer.exe (PID: 3660)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe (PID: 2556)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3756)
      • iexplore.exe (PID: 1072)
    • Reads the hosts file

      • chrome.exe (PID: 1964)
      • chrome.exe (PID: 1768)
    • Reads the date of Windows installation

      • chrome.exe (PID: 3356)
    • Application was dropped or rewritten from another process

      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 4036)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2980)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2492)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 484)
    • Loads dropped or rewritten executable

      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 2980)
      • Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp (PID: 484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
100
Monitored processes
51
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs your of folder here 89ycz - linkvertise downloader_m-ijdb1.exe your of folder here 89ycz - linkvertise downloader_m-ijdb1.tmp no specs your of folder here 89ycz - linkvertise downloader_m-ijdb1.exe your of folder here 89ycz - linkvertise downloader_m-ijdb1.tmp iexplore.exe explorer.exe no specs your of folder here 89ycz - linkvertise downloader_m-ijdb1.exe your of folder here 89ycz - linkvertise downloader_m-ijdb1.tmp no specs your of folder here 89ycz - linkvertise downloader_m-ijdb1.exe your of folder here 89ycz - linkvertise downloader_m-ijdb1.tmp iexplore.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1052,14141422831198794535,7064801505745928594,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3124 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
344"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1052,14141422831198794535,7064801505745928594,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3268 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
448"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --field-trial-handle=1052,14141422831198794535,7064801505745928594,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=4772 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
484"C:\Users\admin\AppData\Local\Temp\is-H35KF.tmp\Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp" /SL5="$302BA,1785071,899584,C:\Users\admin\Downloads\Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe" /SPAWNWND=$202BC /NOTIFYWND=$90252 C:\Users\admin\AppData\Local\Temp\is-H35KF.tmp\Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp
Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-h35kf.tmp\your of folder here 89ycz - linkvertise downloader_m-ijdb1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
508"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1052,14141422831198794535,7064801505745928594,131072 --enable-features=PasswordImport --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1692 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
520"C:\Users\admin\Downloads\Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe" /SPAWNWND=$202BC /NOTIFYWND=$90252 C:\Users\admin\Downloads\Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.exe
Your OF Folder Here 89yCZ - Linkvertise Downloader_m-iJdB1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Linkvertise GmbH & Co. KG
Exit code:
0
Version:
2.0.0.13
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\downloads\your of folder here 89ycz - linkvertise downloader_m-ijdb1.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\usp10.dll
1008"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1052,14141422831198794535,7064801505745928594,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2820 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1072"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2784 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1108"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3756 CREDAT:2954560 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iertutil.dll
1244"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1052,14141422831198794535,7064801505745928594,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=30 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3248 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shlwapi.dll
Total events
64 612
Read events
64 039
Write events
557
Delete events
16

Modification events

(PID) Process:(3756) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3756) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3756) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30933735
(PID) Process:(3756) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3756) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30933735
(PID) Process:(3756) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3756) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3756) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3756) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3756) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
12
Suspicious files
309
Text files
296
Unknown types
65

Dropped files

PID
Process
Filename
Type
3304iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27der
MD5:
SHA256:
3304iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:
SHA256:
3304iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\ads[1].jstext
MD5:
SHA256:
3304iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6der
MD5:
SHA256:
3304iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6binary
MD5:
SHA256:
3304iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\your-of-folder-here-89ycz[1].htmhtml
MD5:
SHA256:
3304iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\styles.8f4b5fad6c933a6ecaaf[1].csstext
MD5:
SHA256:
3304iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\polyfills-es2015.1736b721c9dceedbc82d[1].jstext
MD5:
SHA256:
3304iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\polyfills-es5.481e21a15f8209d0e3d2[1].jstext
MD5:
SHA256:
3304iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
240
DNS requests
156
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3304
iexplore.exe
GET
200
142.250.186.163:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
der
1.41 Kb
whitelisted
3304
iexplore.exe
GET
200
142.250.186.163:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
3304
iexplore.exe
GET
200
104.18.30.182:80
http://crl.comodoca.com/AAACertificateServices.crl
US
der
506 b
whitelisted
3304
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
3304
iexplore.exe
GET
200
13.225.84.49:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
3756
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
3304
iexplore.exe
GET
200
143.204.214.142:80
http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEAiWCjlDT3ik76CESNb5DS8%3D
US
der
471 b
whitelisted
3304
iexplore.exe
GET
200
13.32.23.104:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
3304
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
US
der
471 b
whitelisted
3304
iexplore.exe
GET
200
104.18.30.182:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQCCpp%2FB6wb3ghw0FkPuQvUm
US
der
472 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3304
iexplore.exe
162.159.138.85:443
linkvertise.com
Cloudflare Inc
malicious
3304
iexplore.exe
209.197.3.8:80
ctldl.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
3304
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3304
iexplore.exe
104.16.19.94:443
cdnjs.cloudflare.com
Cloudflare Inc
US
suspicious
3304
iexplore.exe
13.225.80.129:443
js.chargebee.com
US
malicious
3304
iexplore.exe
195.181.175.49:443
maxst.icons8.com
Datacamp Limited
DE
suspicious
3304
iexplore.exe
184.87.212.24:443
contextual.media.net
Bharti Airtel Ltd., Telemedia Services
US
unknown
3304
iexplore.exe
104.18.31.182:80
ocsp.comodoca.com
Cloudflare Inc
US
unknown
3304
iexplore.exe
142.250.186.163:80
ocsp.pki.goog
Google Inc.
US
whitelisted
3756
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
linkvertise.com
  • 162.159.138.85
  • 162.159.137.85
whitelisted
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
cdnjs.cloudflare.com
  • 104.16.19.94
  • 104.16.18.94
whitelisted
fonts.googleapis.com
  • 142.250.186.42
  • 142.250.181.234
whitelisted
maxst.icons8.com
  • 195.181.175.49
  • 195.181.175.45
  • 185.59.220.17
  • 195.181.174.6
  • 195.181.175.54
  • 195.181.175.46
whitelisted
stackpath.bootstrapcdn.com
  • 104.18.10.207
  • 104.18.11.207
whitelisted
use.typekit.net
  • 92.123.225.10
  • 92.123.225.18
  • 2.16.186.49
  • 2.16.186.59
whitelisted
js.chargebee.com
  • 13.225.80.129
  • 13.225.80.9
  • 13.225.80.95
  • 13.225.80.93
shared
contextual.media.net
  • 184.87.212.24
  • 2.18.235.93
shared

Threats

No threats detected
No debug info