| File name: | bt-ddl.exe |
| Full analysis: | https://app.any.run/tasks/a8f75484-0e0f-4da9-bab7-b088692105ce |
| Verdict: | Malicious activity |
| Analysis date: | November 30, 2020, 00:15:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | MS-DOS executable, MZ for MS-DOS |
| MD5: | 0CCA673D5DDB45871D05F6A733059E56 |
| SHA1: | 77F250C949E5F7D3E7BA33968C74428740FA1031 |
| SHA256: | 6C121282C56F9C651FA0C56C9B495B55CD56F7A9F02E4E6F7324735C230DBD71 |
| SSDEEP: | 24576:XhQMSJvM7f824wEvwLAj1TXt3l9L4Qy44Dx+fGjNE938:N/hU1BlqVRNE9M |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2014:07:26 18:04:19+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 477696 |
| InitializedDataSize: | 272384 |
| UninitializedDataSize: | 670720 |
| EntryPoint: | 0xa4071 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.5.4.26 |
| ProductVersionNumber: | 2.0.2.13 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Adobe |
| FileDescription: | Adobe Installation Helper |
| FileVersion: | 3.5.4.26 |
| InternalName: | host.exe |
| LegalCopyright: | Copyright © Adobe Systems Incorporated |
| OriginalFileName: | host.exe |
| ProductName: | Adobe Installation Helper |
| ProductVersion: | 2.0.2.13 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 26-Jul-2014 16:04:19 |
| Detected languages: |
|
| CompanyName: | Adobe |
| FileDescription: | Adobe Installation Helper |
| FileVersion: | 3.5.4.26 |
| InternalName: | host.exe |
| LegalCopyright: | Copyright © Adobe Systems Incorporated |
| OriginalFilename: | host.exe |
| ProductName: | Adobe Installation Helper |
| ProductVersion: | 2.0.2.13 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0040 |
| Pages in file: | 0x0001 |
| Relocations: | 0x0000 |
| Size of header: | 0x0002 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0xB400 |
| OEM information: | 0xCD09 |
| Address of NE header: | 0x00000040 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 3 |
| Time date stamp: | 26-Jul-2014 16:04:19 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.MPRESS1 | 0x00001000 | 0x000A3000 | 0x00033400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.99914 |
.MPRESS2\xdb\x0b | 0x000A4000 | 0x00000BDB | 0x00000C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.99777 |
.rsrc | 0x000A5000 | 0x0000E75C | 0x0000E800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.15781 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.18054 | 1167 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 3.96398 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 4.24411 | 1384 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 2.1281 | 7336 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 2.14203 | 3240 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 2.36423 | 872 | Latin 1 / Western European | English - United States | RT_ICON |
7 | 2.23335 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
8 | 2.30773 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
9 | 2.67423 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
10 | 4.87994 | 3752 | UNKNOWN | English - United States | RT_ICON |
KERNEL32.DLL |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 560 | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe | — | svchost.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe® Flash® Player Installer/Uninstaller 26.0 r0 Exit code: 0 Version: 26,0,0,131 Modules
| |||||||||||||||
| 2180 | "C:\Users\admin\AppData\Local\Temp\bt-ddl.exe" | C:\Users\admin\AppData\Local\Temp\bt-ddl.exe | — | explorer.exe | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe Installation Helper Exit code: 0 Version: 3.5.4.26 Modules
| |||||||||||||||
| 2916 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3264 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2992 | "C:\Users\admin\AppData\Local\Temp\bt-ddl.exe" -Elevated | C:\Users\admin\AppData\Local\Temp\bt-ddl.exe | bt-ddl.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: HIGH Description: Adobe Installation Helper Exit code: 0 Version: 3.5.4.26 Modules
| |||||||||||||||
| 3264 | "C:\Program Files\Internet Explorer\iexplore.exe" https://get.adobe.com/flashplayer/completion/aih/?exitcode=-1 | C:\Program Files\Internet Explorer\iexplore.exe | bt-ddl.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (2180) bt-ddl.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2180) bt-ddl.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2180) bt-ddl.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2992) bt-ddl.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2992) bt-ddl.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 |
| Operation: | write | Name: | Blob |
Value: 040000000100000010000000CB17E431673EE209FE455793F30AFA1C0F0000000100000014000000E91E1E972B8F467AB4E0598FA92285387DEE94C90300000001000000140000004EB6D578499B1CCF5F581EAD56BE3D9B6744A5E57E00000001000000080000000040D0D1B0FFD4017F000000010000000C000000300A06082B060105050703011D0000000100000010000000C6CBCAFA17955C4CFD41ECA0C654C3610B000000010000001200000056006500720069005300690067006E0000001400000001000000140000007FD365A7C2DDECBBF03009F34339FA02AF3331336200000001000000200000009ACFAB7E43C8D880D06B262A94DEEEE4B4659989C3D0CAF19BAF6405E41AB7DF09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000004600000030443021060B6086480186F8450107170630123010060A2B0601040182373C0101030200C0301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0190000000100000010000000D8B5FB368468620275D142FFD2AADE372000000001000000D7040000308204D3308203BBA003020102021018DAD19E267DE8BB4A2158CDCC6B3B4A300D06092A864886F70D01010505003081CA310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303620566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79314530430603550403133C566572695369676E20436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479202D204735301E170D3036313130383030303030305A170D3336303731363233353935395A3081CA310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303620566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79314530430603550403133C566572695369676E20436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479202D20473530820122300D06092A864886F70D01010105000382010F003082010A0282010100AF240808297A359E600CAAE74B3B4EDC7CBC3C451CBB2BE0FE2902F95708A364851527F5F1ADC831895D22E82AAAA642B38FF8B955B7B1B74BB3FE8F7E0757ECEF43DB66621561CF600DA4D8DEF8E0C362083D5413EB49CA59548526E52B8F1B9FEBF5A191C23349D843636A524BD28FE870514DD189697BC770F6B3DC1274DB7B5D4B56D396BF1577A1B0F4A225F2AF1C926718E5F40604EF90B9E400E4DD3AB519FF02BAF43CEEE08BEB378BECF4D7ACF2F6F03DAFDD759133191D1C40CB7424192193D914FEAC2A52C78FD50449E48D6347883C6983CBFE47BD2B7E4FC595AE0E9DD4D143C06773E314087EE53F9F73B8330ACF5D3F3487968AEE53E825150203010001A381B23081AF300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106306D06082B0601050507010C0461305FA15DA05B3059305730551609696D6167652F6769663021301F300706052B0E03021A04148FE5D31A86AC8D8E6BC3CF806AD448182C7B192E30251623687474703A2F2F6C6F676F2E766572697369676E2E636F6D2F76736C6F676F2E676966301D0603551D0E041604147FD365A7C2DDECBBF03009F34339FA02AF333133300D06092A864886F70D0101050500038201010093244A305F62CFD81A982F3DEADC992DBD77F6A5792238ECC4A7A07812AD620E457064C5E797662D98097E5FAFD6CC2865F201AA081A47DEF9F97C925A0869200DD93E6D6E3C0D6ED8E606914018B9F8C1EDDFDB41AAE09620C9CD64153881C994EEA284290B136F8EDB0CDD2502DBA48B1944D2417A05694A584F60CA7E826A0B02AA251739B5DB7FE784652A958ABD86DE5E8116832D10CCDEFDA8822A6D281F0D0BC4E5E71A2619E1F4116F10B595FCE7420532DBCE9D515E28B69E85D35BEFA57D4540728EB70E6B0E06FB33354871B89D278BC4655F0D86769C447AF6955CF65D320833A454B6183F685CF2424A853854835FD1E82CF2AC11D6A8ED636A | |||
| (PID) Process: | (2992) bt-ddl.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2992) bt-ddl.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2992) bt-ddl.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2992) bt-ddl.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2992) bt-ddl.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2992 | bt-ddl.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\E8BN7OJ1.txt | — | |
MD5:— | SHA256:— | |||
| 2992 | bt-ddl.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\1XFSFNSN.txt | — | |
MD5:— | SHA256:— | |||
| 2992 | bt-ddl.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\1RFY276D.txt | — | |
MD5:— | SHA256:— | |||
| 2992 | bt-ddl.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\C0ISBZJS.txt | — | |
MD5:— | SHA256:— | |||
| 2992 | bt-ddl.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\mainwindow[1].htm | html | |
MD5:0749DA7ECD810D2FE5300A6538FBB114 | SHA256:0AC31F9BE06A9200968462EE577CD0E7132162F28AEF542205D9286456EE2F69 | |||
| 2992 | bt-ddl.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\A0BU8Y1A.txt | text | |
MD5:— | SHA256:— | |||
| 2992 | bt-ddl.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\icon-complete-error[1].gif | image | |
MD5:9C0FB23D2B2F05454E4CE898B2F79052 | SHA256:DEFF98C9B6E64B7BBC2516EAE50E5BEAB2C2A4EC8C3942525B5197C7F5BA6166 | |||
| 2992 | bt-ddl.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\YE35GAR4.txt | text | |
MD5:— | SHA256:— | |||
| 2916 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Cab68BE.tmp | — | |
MD5:— | SHA256:— | |||
| 2916 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Tar68BF.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2992 | bt-ddl.exe | GET | 302 | 54.72.205.114:80 | http://stats.adobe.com/b/ss/adbacdcprod/1/H.25.4/s8252581608748?AQB=1&ndh=1&t=30%2F10%2F2020%200%3A16%3A9%201%200&fid=3DE7416053BAF34B-182565CBCD9C29F1&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_aih_launched&g=http%3A%2F%2F127.0.0.1%3A49181%2Fmainwindow.html&ch=acdc_flashplayer&events=event96%2Cevent19&products=%3Bflashplayer_aih&c1=aih&c2=acdc%20downloads&c3=get.adobe.com&c4=en&c5=en%3Aacdc_fp_aih_launched&v18=new&v22=sunday%20-%205%3A00pm&v73=acdc_flashplayer&s=1280x720&c=32&j=1.6&v=Y&k=Y&bw=728&bh=248&ct=lan&hp=N&AQE=1 | IE | — | — | whitelisted |
2916 | iexplore.exe | GET | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D | US | der | 1.47 Kb | whitelisted |
2916 | iexplore.exe | GET | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D | US | der | 1.47 Kb | whitelisted |
2916 | iexplore.exe | GET | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D | US | der | 471 b | whitelisted |
2916 | iexplore.exe | GET | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAza5nSVYZrPeIlAtSf0Rcs%3D | US | der | 471 b | whitelisted |
2916 | iexplore.exe | GET | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAZ2JfwMCbGcYKxKdYCjCAA%3D | US | der | 471 b | whitelisted |
2916 | iexplore.exe | GET | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAlARbj%2FknDlKb7yqTuYQmg%3D | US | der | 471 b | whitelisted |
2916 | iexplore.exe | GET | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D | US | der | 471 b | whitelisted |
2916 | iexplore.exe | GET | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAZ2JfwMCbGcYKxKdYCjCAA%3D | US | der | 471 b | whitelisted |
2916 | iexplore.exe | GET | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAlARbj%2FknDlKb7yqTuYQmg%3D | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2992 | bt-ddl.exe | 193.104.215.66:443 | get.adobe.com | Level 3 Communications, Inc. | — | malicious |
2992 | bt-ddl.exe | 54.72.205.114:80 | stats.adobe.com | Amazon.com, Inc. | IE | unknown |
2916 | iexplore.exe | 104.16.149.64:443 | cdn.cookielaw.org | Cloudflare Inc | US | unknown |
2916 | iexplore.exe | 23.46.165.49:443 | wwwimages2.adobe.com | Cox Communications Inc. | US | unknown |
3264 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2916 | iexplore.exe | 18.202.70.164:443 | dpm.demdex.net | — | US | unknown |
3264 | iexplore.exe | 193.104.215.66:443 | get.adobe.com | Level 3 Communications, Inc. | — | malicious |
2916 | iexplore.exe | 18.202.158.78:443 | sstats.adobe.com | — | US | unknown |
2916 | iexplore.exe | 2.20.242.16:443 | use.typekit.net | Akamai International B.V. | — | whitelisted |
2916 | iexplore.exe | 23.46.165.38:443 | assets.adobedtm.com | Cox Communications Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
get.adobe.com |
| whitelisted |
stats.adobe.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
wwwimages2.adobe.com |
| whitelisted |
www.adobe.com |
| whitelisted |
use.typekit.net |
| whitelisted |
cdn.cookielaw.org |
| whitelisted |
assets.adobedtm.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |