URL:

https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.dropbox.com%2Fl%2FAAAan9tnubZM7QUZqohpbSguB7ircKYe_qI&data=05%7C01%7CLAURALEIGH.WEAVER%40VAULT.INSURANCE%7C3ba4f594450443d1764508dbf340c943%7C348d7f3f9dec4a47a2a1d314cc2e5774%7C0%7C0%7C638371231826256013%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=YwfcCfaOTKCvITCRsI6OxZmSOFwdhRx7BpYD7fTMBI0%3D&reserved=0

Full analysis: https://app.any.run/tasks/7f58362c-8892-4032-96ea-48bde803df9c
Verdict: Malicious activity
Analysis date: December 02, 2023, 15:41:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

762317878AF9AF7964A1471F999F0E56

SHA1:

13F39BDE4A138D4AB25F485827F367437F0AA314

SHA256:

8190E9D9E0D178F5266D283AF09F9BCA31E965E6E00F8316FDA4562F801BCA88

SSDEEP:

12:2G9qxQd1MH3mGqwfVwrdk7gCo7P9xKP7Rw++yIdT:2G9q+3wWGGOlojeP7N4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • GoogleUpdateSetup.exe (PID: 3308)
      • ChromeSetup.exe (PID: 3388)
      • GoogleUpdate.exe (PID: 3632)
      • 109.0.5414.120_chrome_installer.exe (PID: 2808)
      • setup.exe (PID: 1452)
    • Changes the autorun value in the registry

      • setup.exe (PID: 1452)
  • SUSPICIOUS

    • Disables SEHOP

      • GoogleUpdate.exe (PID: 3632)
    • Creates/Modifies COM task schedule object

      • GoogleUpdate.exe (PID: 3512)
    • Reads the Internet Settings

      • GoogleUpdate.exe (PID: 2064)
      • GoogleUpdate.exe (PID: 2492)
    • Executes as Windows Service

      • GoogleUpdate.exe (PID: 3608)
    • Reads settings of System Certificates

      • GoogleUpdate.exe (PID: 2064)
      • GoogleUpdate.exe (PID: 2492)
    • Reads security settings of Internet Explorer

      • GoogleUpdate.exe (PID: 2492)
    • Checks Windows Trust Settings

      • GoogleUpdate.exe (PID: 2492)
    • Creates a software uninstall entry

      • setup.exe (PID: 1452)
    • Application launched itself

      • setup.exe (PID: 3088)
      • GoogleUpdate.exe (PID: 3608)
      • setup.exe (PID: 1452)
    • Searches for installed software

      • setup.exe (PID: 1452)
    • Process drops legitimate windows executable

      • chrome.exe (PID: 984)
  • INFO

    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 1228)
      • iexplore.exe (PID: 3476)
      • chrome.exe (PID: 984)
    • Application launched itself

      • iexplore.exe (PID: 3476)
      • chrome.exe (PID: 984)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3636)
      • GoogleUpdate.exe (PID: 3200)
      • GoogleUpdate.exe (PID: 3632)
      • GoogleUpdate.exe (PID: 2064)
      • GoogleUpdate.exe (PID: 3360)
      • GoogleUpdate.exe (PID: 3512)
      • GoogleUpdate.exe (PID: 2492)
      • GoogleUpdate.exe (PID: 3608)
      • 109.0.5414.120_chrome_installer.exe (PID: 2808)
      • setup.exe (PID: 1452)
      • setup.exe (PID: 3088)
      • GoogleCrashHandler.exe (PID: 2248)
      • GoogleUpdate.exe (PID: 968)
      • GoogleUpdate.exe (PID: 284)
      • elevation_service.exe (PID: 2952)
    • Checks supported languages

      • ChromeSetup.exe (PID: 3388)
      • GoogleUpdate.exe (PID: 3200)
      • wmpnscfg.exe (PID: 3636)
      • GoogleUpdateSetup.exe (PID: 3308)
      • GoogleUpdate.exe (PID: 3632)
      • GoogleUpdate.exe (PID: 3360)
      • GoogleUpdate.exe (PID: 2492)
      • GoogleUpdate.exe (PID: 3512)
      • GoogleUpdate.exe (PID: 2064)
      • GoogleUpdate.exe (PID: 3608)
      • setup.exe (PID: 1452)
      • 109.0.5414.120_chrome_installer.exe (PID: 2808)
      • setup.exe (PID: 3088)
      • setup.exe (PID: 2456)
      • GoogleCrashHandler.exe (PID: 2248)
      • GoogleUpdate.exe (PID: 284)
      • GoogleUpdateOnDemand.exe (PID: 3460)
      • setup.exe (PID: 1420)
      • GoogleUpdate.exe (PID: 968)
      • elevation_service.exe (PID: 2952)
    • The process uses the downloaded file

      • ChromeSetup.exe (PID: 3388)
      • iexplore.exe (PID: 3476)
    • Reads the machine GUID from the registry

      • GoogleUpdate.exe (PID: 3200)
      • GoogleUpdate.exe (PID: 3632)
      • GoogleUpdate.exe (PID: 2492)
      • GoogleUpdate.exe (PID: 3608)
      • GoogleUpdate.exe (PID: 2064)
      • setup.exe (PID: 1452)
      • setup.exe (PID: 3088)
      • GoogleUpdate.exe (PID: 968)
      • GoogleUpdate.exe (PID: 284)
      • elevation_service.exe (PID: 2952)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3636)
    • Create files in a temporary directory

      • ChromeSetup.exe (PID: 3388)
      • GoogleUpdate.exe (PID: 2492)
    • Creates files in the program directory

      • GoogleUpdateSetup.exe (PID: 3308)
      • GoogleUpdate.exe (PID: 3632)
      • GoogleUpdate.exe (PID: 3512)
      • GoogleUpdate.exe (PID: 3360)
      • GoogleUpdate.exe (PID: 2064)
      • GoogleUpdate.exe (PID: 2492)
      • GoogleUpdate.exe (PID: 3608)
      • 109.0.5414.120_chrome_installer.exe (PID: 2808)
      • setup.exe (PID: 1452)
      • setup.exe (PID: 3088)
      • GoogleCrashHandler.exe (PID: 2248)
      • GoogleUpdate.exe (PID: 284)
    • Checks proxy server information

      • GoogleUpdate.exe (PID: 2492)
    • Creates files or folders in the user directory

      • GoogleUpdate.exe (PID: 2492)
    • Executes as Windows Service

      • elevation_service.exe (PID: 2952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
78
Monitored processes
37
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs chromesetup.exe no specs googleupdate.exe no specs googleupdatesetup.exe googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe googleupdate.exe googleupdate.exe 109.0.5414.120_chrome_installer.exe no specs setup.exe setup.exe no specs setup.exe no specs setup.exe no specs googlecrashhandler.exe no specs googleupdate.exe googleupdateondemand.exe no specs googleupdate.exe no specs chrome.exe chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs elevation_service.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
284"C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNi4zNDIiIHNoZWxsX3ZlcnNpb249IjEuMy4zMy4yMyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9InszMDEzMTU5Ri01MURGLTQwRDItQUI2NS04NjlFNEFFQUI5RDl9IiB1c2VyaWQ9IntCNDc5RDQ4NC1EQjYyLTQ1RTAtQjYyQS0yNTgyMUVGQTJBMDJ9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgcmVxdWVzdGlkPSJ7NjBBNUIxMEYtNEM0OC00RjUzLUI1MjktNTc1QTQ3QTRENkQyfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7OEE2OUQzNDUtRDU2NC00NjNDLUFGRjEtQTY5RDlFNTMwRjk2fSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMTA5LjAuNTQxNC4xMjAiIGFwPSJzdGFibGUtYXJjaF94ODYtc3RhdHNkZWZfMSIgbGFuZz0iZW4iIGJyYW5kPSIiIGNsaWVudD0iIiBpbnN0YWxsYWdlPSIxOTIyIiBpbnN0YWxsZGF0ZT0iNDI1NiIgaWlkPSJ7NENGRTFENkUtMzk0NS1COUJCLTg5NUYtQjVDOUQ0ODczMEYxfSIgY29ob3J0PSIxOjFnOHg6IiBjb2hvcnRuYW1lPSJXaW5kb3dzIDciPjxldmVudCBldmVudHR5cGU9IjkiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI1IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIvPjxldmVudCBldmVudHR5cGU9IjYiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIxOTY2MDkiIHVwZGF0ZV9jaGVja190aW1lX21zPSI1NjMiIHRvdGFsPSI4OTI2ODI2NCIgaW5zdGFsbF90aW1lX21zPSIxMzkyMiIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\Google\Update\GoogleUpdate.exe
GoogleUpdate.exe
User:
SYSTEM
Company:
Google Inc.
Integrity Level:
SYSTEM
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
608"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3368 --field-trial-handle=1080,i,6027927458622113672,15802231209855163602,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
968"C:\Program Files\Google\Update\GoogleUpdate.exe" /ondemand C:\Program Files\Google\Update\GoogleUpdate.exeGoogleUpdateOnDemand.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
984"C:\Program Files\Google\Chrome\Application\chrome.exe" --from-installerC:\Program Files\Google\Chrome\Application\chrome.exe
GoogleUpdate.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1068"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2084 --field-trial-handle=1080,i,6027927458622113672,15802231209855163602,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1228"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3476 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1364"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1444 --field-trial-handle=1080,i,6027927458622113672,15802231209855163602,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1420"C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\CR_23DD7.tmp\setup.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Windows\TEMP\Crashpad --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0x1ac,0x1b0,0x1b4,0x180,0x1b8,0xda8ba8,0xda8bb8,0xda8bc4C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\CR_23DD7.tmp\setup.exesetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\update\install\{8302008a-bc30-47d3-a820-f5320b21dd14}\cr_23dd7.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shell32.dll
1452"C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\CR_23DD7.tmp\setup.exe" --install-archive="C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\CR_23DD7.tmp\CHROME.PACKED.7Z" --verbose-logging --do-not-launch-chrome --system-level /installerdata="C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\guiCAF7.tmp"C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\CR_23DD7.tmp\setup.exe
109.0.5414.120_chrome_installer.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\update\install\{8302008a-bc30-47d3-a820-f5320b21dd14}\cr_23dd7.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shell32.dll
1892"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2072 --field-trial-handle=1080,i,6027927458622113672,15802231209855163602,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
35 755
Read events
35 037
Write events
608
Delete events
110

Modification events

(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
214
Suspicious files
80
Text files
70
Unknown types
0

Dropped files

PID
Process
Filename
Type
3476iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118Ader
MD5:B1E36EA43209D2309108DA041CF791BA
SHA256:091B5BFBA23DD199A8560F72FE008EA79899B428E34B446885AAFF338808C3DC
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:86B1AA8CAE41709B15B835FAB20C5675
SHA256:24A12877B3754FAD138F5ADEC10D2F75676088DB2477D2D45DD3426AA7D42FE7
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2F23D0F5E4D72862517E1CB26A329742_F6FACC49395CFA949BCE851E73323C49binary
MD5:E76FA99F530A4C8B11BF3D35CB985D7F
SHA256:D5909053AA6D95DA70B78842BEAFC58D70362D8E9029FAAC350EE02143EC9F0D
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2F23D0F5E4D72862517E1CB26A329742_F6FACC49395CFA949BCE851E73323C49binary
MD5:2B64A4B767C77A24FBDFBD195F0EF3E0
SHA256:5969BA8637FB17424E3D9D55CE607B1B10E66B436011DF33EA897047E95D0803
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E573CDF4C6D731D56A665145182FD759_E1B05D67C2B4A67676A5645B41CB9B9Cbinary
MD5:C9A63084E4A7BAA60A2E2AC2290BCF1A
SHA256:3AD9C7841777DFA5F6801D0DB9C9FB9AE382E0DA7BD627950BF265DB4C899651
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:1D55E3B1CB2EDC0B0914587544BCD82A
SHA256:3E590A68C0ADF9629C0F08B1DFBFDE4106DD74CD9FD1AA2A7D847F4E4CB55CAD
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E573CDF4C6D731D56A665145182FD759_1D978D5EA8275AA72D1BFCD66AF4A751binary
MD5:4FFFD486F78260C21ADE2DD9691CDE9A
SHA256:7DE6509701364A1FE1DA9B2E0FA356BC85074447CA7B6FA409FE99078EC32CF3
1228iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\OpenSans-Bold-webfont[1].ttfbinary
MD5:B0DBBE03FA8B4030610973E2FEA5D232
SHA256:B6CE56EE32C81DDFF0F724F95BF0347F9E7A886496BEDDBCC8F3CD2FA7042971
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E573CDF4C6D731D56A665145182FD759_1D978D5EA8275AA72D1BFCD66AF4A751binary
MD5:4087AC5E67B810F7971EC2C66658DD2F
SHA256:72BA2889877EDE0723BCC9D0E9BE55D6DEFBF7131428397CBD052CF2F9EDD123
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
69
DNS requests
39
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1228
iexplore.exe
GET
200
184.24.77.205:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ae379654bbbca709
unknown
compressed
4.66 Kb
unknown
1228
iexplore.exe
GET
200
184.24.77.205:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?25fa4254fbf74a53
unknown
compressed
4.66 Kb
unknown
1228
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAGewca9P1l7sgwzOOVR2Hc%3D
unknown
binary
471 b
unknown
1228
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
binary
471 b
unknown
1228
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAHWlVhJ1rvbwVVZSZDShpE%3D
unknown
binary
471 b
unknown
1228
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAzdRKIE6Ip1M7QqeZT4%2F1E%3D
unknown
binary
471 b
unknown
3476
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
312 b
unknown
1228
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
1228
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
1228
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEF2rtEA6xK7GEl4nbt8ZZfk%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1228
iexplore.exe
104.47.55.28:443
nam10.safelinks.protection.outlook.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
1228
iexplore.exe
184.24.77.205:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1228
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1228
iexplore.exe
162.125.66.18:443
www.dropbox.com
DROPBOX
DE
unknown
1228
iexplore.exe
104.16.99.29:443
cfl.dropboxstatic.com
CLOUDFLARENET
shared
1228
iexplore.exe
65.9.95.61:443
assets.dropbox.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
nam10.safelinks.protection.outlook.com
  • 104.47.55.28
  • 104.47.58.28
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.205
  • 184.24.77.210
  • 184.24.77.174
  • 184.24.77.176
  • 184.24.77.208
  • 184.24.77.209
  • 184.24.77.199
  • 184.24.77.194
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.dropbox.com
  • 162.125.66.18
shared
cfl.dropboxstatic.com
  • 104.16.99.29
  • 104.16.100.29
shared
assets.dropbox.com
  • 65.9.95.61
  • 65.9.95.94
  • 65.9.95.110
  • 65.9.95.126
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.136
  • 104.126.37.131
  • 104.126.37.163
  • 104.126.37.153
  • 104.126.37.137
  • 104.126.37.155
  • 104.126.37.145
  • 104.126.37.139
  • 104.126.37.162
whitelisted
www.google.com
  • 172.217.18.4
whitelisted
ocsp.pki.goog
  • 142.250.186.35
whitelisted

Threats

PID
Process
Class
Message
1228
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY Dropbox.com Offsite File Backup in Use
No debug info