URL: | http://rub.oxbupset.com/3306532eC17078468Uy0VE0Sq1fAr219897ks |
Full analysis: | https://app.any.run/tasks/e83367cc-49af-49dc-82d4-0a21809ac458 |
Verdict: | Malicious activity |
Analysis date: | April 15, 2025, 19:43:43 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Tags: | |
MD5: | 0E6089C8BDB29C48095C872CC682B998 |
SHA1: | 55E1758D811E625DE904D636CF99C95CE284AF6C |
SHA256: | 71C8CA46B9962F1B1CB04BB15FAA3544208D517910F86C21B7E42509FE6F6100 |
SSDEEP: | 3:N1KM9wJINWJDLVSdnQOIFe9W:CM90IN2EdnNIyW |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1396 | msedge.exe | GET | 302 | 91.202.5.98:80 | http://rub.oxbupset.com/3306532eC17078468Uy0VE0Sq1fAr219897ks | unknown | — | — | — |
5472 | RUXIMICS.exe | GET | 200 | 23.48.23.145:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
3080 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.145:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4208 | svchost.exe | GET | 200 | 23.48.23.145:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
3080 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5472 | RUXIMICS.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4208 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | OPTIONS | 204 | 52.73.112.217:443 | https://trc.pushnami.com/api/push/track | unknown | — | — | — |
— | — | GET | 200 | 108.138.7.108:443 | https://d3v7hbq4afry8x.cloudfront.net/css/omgsweeps/animate.css | unknown | text | 76.7 Kb | whitelisted |
— | — | GET | 302 | 34.149.113.138:443 | https://go.wiadn.com/2Q6Z62K/8LNTN96/?sub1=9064&sub2=620663500&sub3=3306532 | unknown | html | 408 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 239.255.255.250:1900 | — | — | — | whitelisted |
5472 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3080 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4208 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1396 | msedge.exe | 2.23.227.208:443 | www.bing.com | Ooredoo Q.S.C. | QA | whitelisted |
1396 | msedge.exe | 91.202.5.98:80 | rub.oxbupset.com | SOLLUTIUM EU Sp z.o.o. | PL | unknown |
1396 | msedge.exe | 18.215.180.255:443 | n1yl8me.com | AMAZON-AES | US | unknown |
1396 | msedge.exe | 54.221.98.233:443 | gwlsw7lgfi.com | AMAZON-AES | US | unknown |
3080 | MoUsoCoreWorker.exe | 23.48.23.145:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5472 | RUXIMICS.exe | 23.48.23.145:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
rub.oxbupset.com |
| unknown |
n1yl8me.com |
| unknown |
gwlsw7lgfi.com |
| unknown |
crl.microsoft.com |
| whitelisted |
go.wiadn.com |
| unknown |
www.microsoft.com |
| whitelisted |
find.retirementbenefitsguide.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] BootstrapCDN (maxcdn .bootstrapcdn .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] BootstrapCDN (maxcdn .bootstrapcdn .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |