URL:

https://www.freevpn.win/lps/gbox-lp/index.html?cid=371380192&kw=GA_POP_145816

Full analysis: https://app.any.run/tasks/434a21df-cac3-47d7-8990-3dfcece2f6a4
Verdict: Malicious activity
Analysis date: December 02, 2023, 23:22:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

D41365375DB75934BF16AA3EEA94EB71

SHA1:

19D8E9337776E081D74A9D80ADAD24192FA5E422

SHA256:

80ECB9C41904EBA335ECE0828844FAA0AC6832EC16486F09E09CEF2BC3524E5A

SSDEEP:

3:N8DSLLbLmvwhVX1aNGMuWarhYiw2WT:2OLHLF7aNGxNYiZU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
    • Detects Cygwin installation

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
    • The process creates files with name similar to system file names

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
    • Starts SC.EXE for service management

      • nsB685.tmp (PID: 4088)
      • cmd.exe (PID: 3756)
    • Starts application with an unusual extension

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
      • cmd.exe (PID: 2912)
      • cmd.exe (PID: 2028)
    • Starts CMD.EXE for commands execution

      • nsB703.tmp (PID: 3564)
      • FreeVPN.exe (PID: 3052)
    • Drops 7-zip archiver for unpacking

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
    • The process drops C-runtime libraries

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
    • Process drops legitimate windows executable

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
    • Executes as Windows Service

      • FreeVPN.exe (PID: 3204)
    • Application launched itself

      • FreeVPN.exe (PID: 3204)
    • Reads the Internet Settings

      • FreeVPN.exe (PID: 3052)
      • cmd.exe (PID: 3792)
    • Reads Microsoft Outlook installation path

      • FreeVPN.exe (PID: 3052)
    • Checks Windows Trust Settings

      • FreeVPN.exe (PID: 3052)
    • Reads settings of System Certificates

      • FreeVPN.exe (PID: 3052)
    • Reads security settings of Internet Explorer

      • FreeVPN.exe (PID: 3052)
    • Reads Internet Explorer settings

      • FreeVPN.exe (PID: 3052)
    • Connects to unusual port

      • rathole.exe (PID: 2536)
  • INFO

    • Manual execution by a user

      • wmpnscfg.exe (PID: 1360)
      • msedge.exe (PID: 2296)
    • Application launched itself

      • iexplore.exe (PID: 564)
      • msedge.exe (PID: 1604)
      • msedge.exe (PID: 2296)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2080)
      • iexplore.exe (PID: 564)
    • Reads the computer name

      • wmpnscfg.exe (PID: 1360)
      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
      • FreeVPN.exe (PID: 1004)
      • FreeVPN.exe (PID: 3052)
      • FreeVPN.exe (PID: 2224)
      • FreeVPN.exe (PID: 3204)
      • FreeVPN.exe (PID: 3972)
      • microsocks.exe (PID: 3044)
    • Checks supported languages

      • wmpnscfg.exe (PID: 1360)
      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
      • nsB685.tmp (PID: 4088)
      • nsB703.tmp (PID: 3564)
      • FreeVPN.exe (PID: 3204)
      • FreeVPN.exe (PID: 2224)
      • FreeVPN.exe (PID: 1004)
      • FreeVPN.exe (PID: 3052)
      • chcp.com (PID: 1064)
      • FreeVPN.exe (PID: 3972)
      • chcp.com (PID: 1644)
      • rathole.exe (PID: 2536)
      • microsocks.exe (PID: 3044)
    • The process uses the downloaded file

      • iexplore.exe (PID: 564)
    • Reads the machine GUID from the registry

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
      • FreeVPN.exe (PID: 3052)
    • Create files in a temporary directory

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
    • Creates files in the program directory

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
      • FreeVPN.exe (PID: 3052)
      • FreeVPN.exe (PID: 3204)
    • Creates files or folders in the user directory

      • freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe (PID: 2364)
      • FreeVPN.exe (PID: 3052)
    • Checks proxy server information

      • FreeVPN.exe (PID: 3052)
    • Reads Environment values

      • FreeVPN.exe (PID: 3052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
95
Monitored processes
46
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe no specs freevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe nsb685.tmp no specs sc.exe no specs nsb703.tmp no specs sc.exe no specs cmd.exe no specs find.exe no specs freevpn.exe no specs freevpn.exe freevpn.exe freevpn.exe no specs freevpn.exe no specs cmd.exe no specs chcp.com no specs cmd.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs cmd.exe no specs cmd.exe no specs rathole.exe microsocks.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs chcp.com no specs cmd.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
284"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3476 --field-trial-handle=1292,i,6470229163360062062,4052798415439427079,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
564"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.freevpn.win/lps/gbox-lp/index.html?cid=371380192&kw=GA_POP_145816"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1004"C:\Program Files\FreeVPN\FreeVPN.exe" -inC:\Program Files\FreeVPN\FreeVPN.exefreevpn_setup_i_wi4c262p5l6tevetijs6v9ik.exe
User:
admin
Company:
Keen Internet Technologies Ltd
Integrity Level:
HIGH
Description:
FreeVPN
Exit code:
32
Version:
2.1.2.1
Modules
Images
c:\program files\freevpn\freevpn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\freevpn\libcurl.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wldap32.dll
1064chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1232"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1624 --field-trial-handle=1292,i,6470229163360062062,4052798415439427079,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1248"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2584 --field-trial-handle=1292,i,6470229163360062062,4052798415439427079,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1360"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1556"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2288 --field-trial-handle=1292,i,6470229163360062062,4052798415439427079,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1604"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.maxivpn.com/lps/trial.html?affid=21C:\Program Files\Microsoft\Edge\Application\msedge.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1644chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
23 509
Read events
23 367
Write events
137
Delete events
5

Modification events

(PID) Process:(564) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(564) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(564) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(564) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(564) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(564) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(564) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(564) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(564) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(564) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
36
Suspicious files
107
Text files
146
Unknown types
0

Dropped files

PID
Process
Filename
Type
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:1A4100A8E2119139764797D1EB05278D
SHA256:1D0BF656C9775BE1324F9B2A925E309AD8FA01726F21434B3267F08B75825614
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464binary
MD5:F8F6A91B9D12B445DFC86CF967BB1E9F
SHA256:610C6607F184562D3890A9BBA7C65153B3EFCCDCD576C2B6AD7A19A04D3932BC
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464binary
MD5:8202A1CD02E7D69597995CABBE881A12
SHA256:58F381C3A0A0ACE6321DA22E40BD44A597BD98B9C9390AB9258426B5CF75A7A5
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:85B7888FAFD107F0F692AFE212D3D90D
SHA256:39E535F6AF7039825FF1876EB3DA02EB41E767829146E91AE592158239A0C965
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:AB5A4AF24CED0019D40E635195FA1398
SHA256:38498EAFD2C1F47467E833AAC2EAA268AAD2C6D49946A9AE29F66E96B4798A57
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27der
MD5:C05A4765F1EBB8FCAE4A6718BE8AA1A2
SHA256:A1D834BC698B78AFD57FA185D153080785827BA57DCB0BAE366C737E3B8F4D16
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\assist[1].csstext
MD5:10D03BDAF5D400D1809F239C95B61689
SHA256:1E0E06239EFB12CABCFD3FDE4E7BAB9D386F29D0DC14ED1B33A7BDCCA913066F
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:81193A8FA968420EFA631AB1264BFAA6
SHA256:11E2B09723B0BF97E2D9430B421FED55893DC919DA37F03D41DC44EF57A1FDA4
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery.min[1].jstext
MD5:8101D596B2B8FA35FE3A634EA342D7C3
SHA256:540BC6DEC1DD4B92EA4D3FB903F69EABF6D919AFD48F4E312B163C28CFF0F441
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
78
DNS requests
55
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2080
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ae379654bbbca709
unknown
compressed
4.66 Kb
unknown
2080
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?25fa4254fbf74a53
unknown
compressed
4.66 Kb
unknown
2080
iexplore.exe
GET
200
142.250.186.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2080
iexplore.exe
GET
200
142.250.186.131:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D
unknown
binary
724 b
unknown
2080
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
2080
iexplore.exe
GET
200
23.201.254.55:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
564
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
312 b
unknown
2224
FreeVPN.exe
GET
200
18.195.123.247:80
http://track.xdisctracking.pw/conversion.gif?cid=wi4c262p5l6tevetijs6v9ik&txid=8d2f2125e78a03bb54c832deec8f70f21c605cb5&et=install
unknown
image
43 b
unknown
484
lsass.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?440741f4bd306e5a
unknown
compressed
65.2 Kb
unknown
3052
FreeVPN.exe
GET
200
18.195.123.247:80
http://track.xdisctracking.pw/conversion.gif?cid=wi4c262p5l6tevetijs6v9ik&txid=8d2f2125e78a03bb54c832deec8f70f21c605cb5&et=streaming
unknown
image
43 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2080
iexplore.exe
188.114.96.3:443
www.freevpn.win
CLOUDFLARENET
NL
unknown
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2080
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2080
iexplore.exe
142.250.186.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
2080
iexplore.exe
104.17.24.14:443
cdnjs.cloudflare.com
CLOUDFLARENET
unknown
2080
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2080
iexplore.exe
18.195.123.247:443
track.xdisctracking.pw
AMAZON-02
DE
shared
2080
iexplore.exe
23.201.254.55:80
x1.c.lencr.org
AKAMAI-AS
CH
unknown

DNS requests

Domain
IP
Reputation
www.freevpn.win
  • 188.114.96.3
  • 188.114.97.3
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.pki.goog
  • 142.250.186.131
whitelisted
cdnjs.cloudflare.com
  • 104.17.24.14
  • 104.17.25.14
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
track.xdisctracking.pw
  • 18.195.123.247
unknown
x1.c.lencr.org
  • 23.201.254.55
whitelisted
www.pcboostup.com
  • 188.114.96.3
  • 188.114.97.3
unknown
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 2.23.209.187
  • 2.23.209.133
  • 2.23.209.130
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.pw domain - Likely Hostile
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.pw domain - Likely Hostile
2224
FreeVPN.exe
Misc activity
ET INFO HTTP Request to a *.pw domain
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.pw domain - Likely Hostile
3052
FreeVPN.exe
Misc activity
ET INFO HTTP Request to a *.pw domain
2784
msedge.exe
Potentially Bad Traffic
ET DNS Query to a *.pw domain - Likely Hostile
2784
msedge.exe
Potentially Bad Traffic
ET DNS Query to a *.pw domain - Likely Hostile
No debug info