URL:

https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.dropbox.com%2Fl%2FAAAan9tnubZM7QUZqohpbSguB7ircKYe_qI&data=05%7C01%7CLAURALEIGH.WEAVER%40VAULT.INSURANCE%7C3ba4f594450443d1764508dbf340c943%7C348d7f3f9dec4a47a2a1d314cc2e5774%7C0%7C0%7C638371231826256013%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=YwfcCfaOTKCvITCRsI6OxZmSOFwdhRx7BpYD7fTMBI0%3D&reserved=0

Full analysis: https://app.any.run/tasks/7f58362c-8892-4032-96ea-48bde803df9c
Verdict: Malicious activity
Analysis date: December 02, 2023, 15:41:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

762317878AF9AF7964A1471F999F0E56

SHA1:

13F39BDE4A138D4AB25F485827F367437F0AA314

SHA256:

8190E9D9E0D178F5266D283AF09F9BCA31E965E6E00F8316FDA4562F801BCA88

SSDEEP:

12:2G9qxQd1MH3mGqwfVwrdk7gCo7P9xKP7Rw++yIdT:2G9q+3wWGGOlojeP7N4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ChromeSetup.exe (PID: 3388)
      • GoogleUpdateSetup.exe (PID: 3308)
      • GoogleUpdate.exe (PID: 3632)
      • setup.exe (PID: 1452)
      • 109.0.5414.120_chrome_installer.exe (PID: 2808)
    • Changes the autorun value in the registry

      • setup.exe (PID: 1452)
  • SUSPICIOUS

    • Reads the Internet Settings

      • GoogleUpdate.exe (PID: 2064)
      • GoogleUpdate.exe (PID: 2492)
    • Creates/Modifies COM task schedule object

      • GoogleUpdate.exe (PID: 3512)
    • Disables SEHOP

      • GoogleUpdate.exe (PID: 3632)
    • Reads settings of System Certificates

      • GoogleUpdate.exe (PID: 2064)
      • GoogleUpdate.exe (PID: 2492)
    • Reads security settings of Internet Explorer

      • GoogleUpdate.exe (PID: 2492)
    • Checks Windows Trust Settings

      • GoogleUpdate.exe (PID: 2492)
    • Executes as Windows Service

      • GoogleUpdate.exe (PID: 3608)
    • Application launched itself

      • setup.exe (PID: 1452)
      • setup.exe (PID: 3088)
      • GoogleUpdate.exe (PID: 3608)
    • Searches for installed software

      • setup.exe (PID: 1452)
    • Creates a software uninstall entry

      • setup.exe (PID: 1452)
    • Process drops legitimate windows executable

      • chrome.exe (PID: 984)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3476)
      • chrome.exe (PID: 984)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3636)
      • ChromeSetup.exe (PID: 3388)
      • GoogleUpdate.exe (PID: 3200)
      • GoogleUpdateSetup.exe (PID: 3308)
      • GoogleUpdate.exe (PID: 3632)
      • GoogleUpdate.exe (PID: 3512)
      • GoogleUpdate.exe (PID: 3360)
      • GoogleUpdate.exe (PID: 2064)
      • GoogleUpdate.exe (PID: 2492)
      • GoogleUpdate.exe (PID: 3608)
      • 109.0.5414.120_chrome_installer.exe (PID: 2808)
      • setup.exe (PID: 1420)
      • setup.exe (PID: 1452)
      • setup.exe (PID: 3088)
      • setup.exe (PID: 2456)
      • GoogleUpdate.exe (PID: 284)
      • GoogleUpdateOnDemand.exe (PID: 3460)
      • GoogleUpdate.exe (PID: 968)
      • elevation_service.exe (PID: 2952)
      • GoogleCrashHandler.exe (PID: 2248)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3636)
      • GoogleUpdate.exe (PID: 3200)
      • GoogleUpdate.exe (PID: 3360)
      • GoogleUpdate.exe (PID: 3512)
      • GoogleUpdate.exe (PID: 2064)
      • GoogleUpdate.exe (PID: 2492)
      • GoogleUpdate.exe (PID: 3608)
      • 109.0.5414.120_chrome_installer.exe (PID: 2808)
      • setup.exe (PID: 1452)
      • setup.exe (PID: 3088)
      • GoogleCrashHandler.exe (PID: 2248)
      • elevation_service.exe (PID: 2952)
      • GoogleUpdate.exe (PID: 284)
      • GoogleUpdate.exe (PID: 968)
      • GoogleUpdate.exe (PID: 3632)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 1228)
      • iexplore.exe (PID: 3476)
      • chrome.exe (PID: 984)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3636)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3476)
      • ChromeSetup.exe (PID: 3388)
    • Create files in a temporary directory

      • ChromeSetup.exe (PID: 3388)
      • GoogleUpdate.exe (PID: 2492)
    • Reads the machine GUID from the registry

      • GoogleUpdate.exe (PID: 3200)
      • GoogleUpdate.exe (PID: 3632)
      • GoogleUpdate.exe (PID: 2492)
      • GoogleUpdate.exe (PID: 3608)
      • GoogleUpdate.exe (PID: 2064)
      • setup.exe (PID: 1452)
      • setup.exe (PID: 3088)
      • GoogleUpdate.exe (PID: 284)
      • GoogleUpdate.exe (PID: 968)
      • elevation_service.exe (PID: 2952)
    • Creates files in the program directory

      • GoogleUpdateSetup.exe (PID: 3308)
      • GoogleUpdate.exe (PID: 3360)
      • GoogleUpdate.exe (PID: 3512)
      • GoogleUpdate.exe (PID: 2492)
      • GoogleUpdate.exe (PID: 2064)
      • 109.0.5414.120_chrome_installer.exe (PID: 2808)
      • GoogleUpdate.exe (PID: 3608)
      • setup.exe (PID: 1452)
      • setup.exe (PID: 3088)
      • GoogleCrashHandler.exe (PID: 2248)
      • GoogleUpdate.exe (PID: 284)
      • GoogleUpdate.exe (PID: 3632)
    • Checks proxy server information

      • GoogleUpdate.exe (PID: 2492)
    • Creates files or folders in the user directory

      • GoogleUpdate.exe (PID: 2492)
    • Executes as Windows Service

      • elevation_service.exe (PID: 2952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
78
Monitored processes
37
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs chromesetup.exe no specs googleupdate.exe no specs googleupdatesetup.exe googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe googleupdate.exe googleupdate.exe 109.0.5414.120_chrome_installer.exe no specs setup.exe setup.exe no specs setup.exe no specs setup.exe no specs googlecrashhandler.exe no specs googleupdate.exe googleupdateondemand.exe no specs googleupdate.exe no specs chrome.exe chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs elevation_service.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
284"C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNi4zNDIiIHNoZWxsX3ZlcnNpb249IjEuMy4zMy4yMyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9InszMDEzMTU5Ri01MURGLTQwRDItQUI2NS04NjlFNEFFQUI5RDl9IiB1c2VyaWQ9IntCNDc5RDQ4NC1EQjYyLTQ1RTAtQjYyQS0yNTgyMUVGQTJBMDJ9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgcmVxdWVzdGlkPSJ7NjBBNUIxMEYtNEM0OC00RjUzLUI1MjktNTc1QTQ3QTRENkQyfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7OEE2OUQzNDUtRDU2NC00NjNDLUFGRjEtQTY5RDlFNTMwRjk2fSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMTA5LjAuNTQxNC4xMjAiIGFwPSJzdGFibGUtYXJjaF94ODYtc3RhdHNkZWZfMSIgbGFuZz0iZW4iIGJyYW5kPSIiIGNsaWVudD0iIiBpbnN0YWxsYWdlPSIxOTIyIiBpbnN0YWxsZGF0ZT0iNDI1NiIgaWlkPSJ7NENGRTFENkUtMzk0NS1COUJCLTg5NUYtQjVDOUQ0ODczMEYxfSIgY29ob3J0PSIxOjFnOHg6IiBjb2hvcnRuYW1lPSJXaW5kb3dzIDciPjxldmVudCBldmVudHR5cGU9IjkiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI1IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIvPjxldmVudCBldmVudHR5cGU9IjYiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIxOTY2MDkiIHVwZGF0ZV9jaGVja190aW1lX21zPSI1NjMiIHRvdGFsPSI4OTI2ODI2NCIgaW5zdGFsbF90aW1lX21zPSIxMzkyMiIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\Google\Update\GoogleUpdate.exe
GoogleUpdate.exe
User:
SYSTEM
Company:
Google Inc.
Integrity Level:
SYSTEM
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
608"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3368 --field-trial-handle=1080,i,6027927458622113672,15802231209855163602,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
968"C:\Program Files\Google\Update\GoogleUpdate.exe" /ondemand C:\Program Files\Google\Update\GoogleUpdate.exeGoogleUpdateOnDemand.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
984"C:\Program Files\Google\Chrome\Application\chrome.exe" --from-installerC:\Program Files\Google\Chrome\Application\chrome.exe
GoogleUpdate.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1068"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2084 --field-trial-handle=1080,i,6027927458622113672,15802231209855163602,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1228"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3476 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1364"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1444 --field-trial-handle=1080,i,6027927458622113672,15802231209855163602,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1420"C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\CR_23DD7.tmp\setup.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Windows\TEMP\Crashpad --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0x1ac,0x1b0,0x1b4,0x180,0x1b8,0xda8ba8,0xda8bb8,0xda8bc4C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\CR_23DD7.tmp\setup.exesetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\update\install\{8302008a-bc30-47d3-a820-f5320b21dd14}\cr_23dd7.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shell32.dll
1452"C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\CR_23DD7.tmp\setup.exe" --install-archive="C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\CR_23DD7.tmp\CHROME.PACKED.7Z" --verbose-logging --do-not-launch-chrome --system-level /installerdata="C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\guiCAF7.tmp"C:\Program Files\Google\Update\Install\{8302008A-BC30-47D3-A820-F5320B21DD14}\CR_23DD7.tmp\setup.exe
109.0.5414.120_chrome_installer.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\update\install\{8302008a-bc30-47d3-a820-f5320b21dd14}\cr_23dd7.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shell32.dll
1892"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2072 --field-trial-handle=1080,i,6027927458622113672,15802231209855163602,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
35 755
Read events
35 037
Write events
608
Delete events
110

Modification events

(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3476) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
214
Suspicious files
80
Text files
70
Unknown types
0

Dropped files

PID
Process
Filename
Type
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:88036C0240A6591B8E561ECD7BA207D1
SHA256:56ED8E5DC18F2F8A798D869FB868B2445FCE33251988B8A1FB7C8B3A0B30F139
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2F23D0F5E4D72862517E1CB26A329742_F6FACC49395CFA949BCE851E73323C49binary
MD5:2B64A4B767C77A24FBDFBD195F0EF3E0
SHA256:5969BA8637FB17424E3D9D55CE607B1B10E66B436011DF33EA897047E95D0803
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:86B1AA8CAE41709B15B835FAB20C5675
SHA256:24A12877B3754FAD138F5ADEC10D2F75676088DB2477D2D45DD3426AA7D42FE7
1228iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3476iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118Ader
MD5:B1E36EA43209D2309108DA041CF791BA
SHA256:091B5BFBA23DD199A8560F72FE008EA79899B428E34B446885AAFF338808C3DC
1228iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\OpenSans-Light-webfont[1].ttfbinary
MD5:B202959A841A37B5BFB12FE69B6BF0D1
SHA256:01E40EBAA4275BC99729D90B4EA47B977B88B8D734850EAE816B9037A32C825A
1228iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\OpenSans-Bold-webfont[1].ttfbinary
MD5:B0DBBE03FA8B4030610973E2FEA5D232
SHA256:B6CE56EE32C81DDFF0F724F95BF0347F9E7A886496BEDDBCC8F3CD2FA7042971
1228iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\bowl-empty[1].svgimage
MD5:43352FB70EDCD6382EE84C65C0BADADC
SHA256:ACE8AC28EBCCDF5EC27385ECEA8C0FC7E98502596B9C249874EF2950F4456C0C
1228iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\OpenSans-Semibold-webfont[1].ttfbinary
MD5:B32ACEA6FD3C228B5059042C7AD21C55
SHA256:9F8567EA7C2D954377D5A3C26BDAF666FF993DD6A2D4E7E6931917A0286514A2
3476iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118Abinary
MD5:D8FC3D96E9F8A59F23923E99C1063800
SHA256:EF9C2B6B02BE3256CC9CB3B24307BCCCE920D9B7539C2B97FDF967144777AEF2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
69
DNS requests
39
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1228
iexplore.exe
GET
200
184.24.77.205:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ae379654bbbca709
unknown
compressed
4.66 Kb
unknown
1228
iexplore.exe
GET
200
184.24.77.205:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?25fa4254fbf74a53
unknown
compressed
4.66 Kb
unknown
1228
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAGewca9P1l7sgwzOOVR2Hc%3D
unknown
binary
471 b
unknown
1228
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
binary
471 b
unknown
1228
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAHWlVhJ1rvbwVVZSZDShpE%3D
unknown
binary
471 b
unknown
1228
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAzdRKIE6Ip1M7QqeZT4%2F1E%3D
unknown
binary
471 b
unknown
3476
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
312 b
unknown
1228
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
1228
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQChuVoVf7HVAxLxWCb2kXo7
unknown
binary
472 b
unknown
1228
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1228
iexplore.exe
104.47.55.28:443
nam10.safelinks.protection.outlook.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
1228
iexplore.exe
184.24.77.205:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1228
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1228
iexplore.exe
162.125.66.18:443
www.dropbox.com
DROPBOX
DE
unknown
1228
iexplore.exe
104.16.99.29:443
cfl.dropboxstatic.com
CLOUDFLARENET
shared
1228
iexplore.exe
65.9.95.61:443
assets.dropbox.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
nam10.safelinks.protection.outlook.com
  • 104.47.55.28
  • 104.47.58.28
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.205
  • 184.24.77.210
  • 184.24.77.174
  • 184.24.77.176
  • 184.24.77.208
  • 184.24.77.209
  • 184.24.77.199
  • 184.24.77.194
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.dropbox.com
  • 162.125.66.18
shared
cfl.dropboxstatic.com
  • 104.16.99.29
  • 104.16.100.29
shared
assets.dropbox.com
  • 65.9.95.61
  • 65.9.95.94
  • 65.9.95.110
  • 65.9.95.126
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.136
  • 104.126.37.131
  • 104.126.37.163
  • 104.126.37.153
  • 104.126.37.137
  • 104.126.37.155
  • 104.126.37.145
  • 104.126.37.139
  • 104.126.37.162
whitelisted
www.google.com
  • 172.217.18.4
whitelisted
ocsp.pki.goog
  • 142.250.186.35
whitelisted

Threats

PID
Process
Class
Message
1228
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY Dropbox.com Offsite File Backup in Use
No debug info