URL:

yg5sjx5kzy.com

Full analysis: https://app.any.run/tasks/4959fdc0-b544-4884-994b-85aa575d357e
Verdict: Malicious activity
Analysis date: February 15, 2024, 21:29:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

623592D45FED9C2A94B31570B4B70753

SHA1:

11578C6D0AC262EBE9C410B52D94D84D402A70DF

SHA256:

8507CB6E18B9232D11DAB1BB024A7A12AC4EB1B6D29A6CB4E5B4CA4763088384

SSDEEP:

3:z2Mn:qM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Hola-Setup (1).exe (PID: 1992)
      • Hola-Setup.exe (PID: 2384)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • Hola-Setup-Core.exe (PID: 3308)
      • Hola-Setup-Core.exe (PID: 2724)
      • Hola-Setup-Core.exe (PID: 3088)
    • Executable content was dropped or overwritten

      • Hola-Setup (1).exe (PID: 1992)
      • Hola-Setup.exe (PID: 2384)
    • Reads security settings of Internet Explorer

      • Hola-Setup-Core.exe (PID: 3308)
      • Hola-Setup-Core.exe (PID: 2724)
      • Hola-Setup-Core.exe (PID: 3088)
    • Reads settings of System Certificates

      • Hola-Setup-Core.exe (PID: 3308)
      • Hola-Setup-Core.exe (PID: 2724)
      • Hola-Setup-Core.exe (PID: 3088)
    • Adds/modifies Windows certificates

      • Hola-Setup-Core.exe (PID: 3308)
    • Reads the Internet Settings

      • Hola-Setup-Core.exe (PID: 3308)
      • Hola-Setup-Core.exe (PID: 2724)
      • Hola-Setup-Core.exe (PID: 3088)
    • Application launched itself

      • Hola-Setup-Core.exe (PID: 3308)
    • Executes as Windows Service

      • PresentationFontCache.exe (PID: 2968)
  • INFO

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3652)
      • iexplore.exe (PID: 3288)
    • Application launched itself

      • iexplore.exe (PID: 3288)
    • Checks supported languages

      • Hola-Setup (1).exe (PID: 1992)
      • Hola-Setup-Core.exe (PID: 3308)
      • PresentationFontCache.exe (PID: 2968)
      • Hola-Setup-Core.exe (PID: 2724)
      • Hola-Setup-Core.exe (PID: 3088)
      • Hola-Setup.exe (PID: 2384)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 3288)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 3288)
      • iexplore.exe (PID: 3652)
    • Reads the machine GUID from the registry

      • Hola-Setup-Core.exe (PID: 3308)
      • Hola-Setup-Core.exe (PID: 2724)
      • PresentationFontCache.exe (PID: 2968)
      • Hola-Setup-Core.exe (PID: 3088)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3288)
    • Create files in a temporary directory

      • Hola-Setup (1).exe (PID: 1992)
      • Hola-Setup-Core.exe (PID: 3308)
      • Hola-Setup-Core.exe (PID: 2724)
      • Hola-Setup.exe (PID: 2384)
      • Hola-Setup-Core.exe (PID: 3088)
    • Reads the software policy settings

      • Hola-Setup-Core.exe (PID: 3308)
      • Hola-Setup-Core.exe (PID: 2724)
      • Hola-Setup-Core.exe (PID: 3088)
    • Reads the computer name

      • Hola-Setup-Core.exe (PID: 3308)
      • Hola-Setup-Core.exe (PID: 2724)
      • PresentationFontCache.exe (PID: 2968)
      • Hola-Setup-Core.exe (PID: 3088)
    • Reads Environment values

      • Hola-Setup-Core.exe (PID: 3308)
      • Hola-Setup-Core.exe (PID: 2724)
      • Hola-Setup-Core.exe (PID: 3088)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
10
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe hola-setup (1).exe no specs hola-setup (1).exe hola-setup-core.exe hola-setup-core.exe presentationfontcache.exe no specs hola-setup.exe no specs hola-setup.exe hola-setup-core.exe

Process information

PID
CMD
Path
Indicators
Parent process
696"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Hola-Setup (1).exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Hola-Setup (1).exeiexplore.exe
User:
admin
Company:
Hola Networks Ltd.
Integrity Level:
MEDIUM
Description:
Hola Setup
Exit code:
3221226540
Version:
1.0.8678.23934
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\hola-setup (1).exe
c:\windows\system32\ntdll.dll
1992"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Hola-Setup (1).exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Hola-Setup (1).exe
iexplore.exe
User:
admin
Company:
Hola Networks Ltd.
Integrity Level:
HIGH
Description:
Hola Setup
Exit code:
0
Version:
1.0.8678.23934
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\hola-setup (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2096"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Hola-Setup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Hola-Setup.exeiexplore.exe
User:
admin
Company:
Hola Networks Ltd.
Integrity Level:
MEDIUM
Description:
Hola Setup
Exit code:
3221226540
Version:
1.0.8678.23934
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\hola-setup.exe
c:\windows\system32\ntdll.dll
2384"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Hola-Setup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Hola-Setup.exe
iexplore.exe
User:
admin
Company:
Hola Networks Ltd.
Integrity Level:
HIGH
Description:
Hola Setup
Exit code:
0
Version:
1.0.8678.23934
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\hola-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2724".\Hola-Setup-Core.exe" --monitor 1536C:\Users\admin\AppData\Local\Temp\7zSBE3A.tmp\Hola-Setup-Core.exe
Hola-Setup-Core.exe
User:
admin
Company:
Hola Networks Ltd.
Integrity Level:
HIGH
Description:
Hola VPN Setup
Exit code:
0
Version:
1.0.8678.23934
Modules
Images
c:\users\admin\appdata\local\temp\7zsbe3a.tmp\hola-setup-core.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2968C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeC:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
PresentationFontCache.exe
Exit code:
0
Version:
3.0.6920.4902 built by: NetFXw7
Modules
Images
c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3088.\Hola-Setup-Core.exeC:\Users\admin\AppData\Local\Temp\7zSD164.tmp\Hola-Setup-Core.exe
Hola-Setup.exe
User:
admin
Company:
Hola Networks Ltd.
Integrity Level:
HIGH
Description:
Hola VPN Setup
Exit code:
0
Version:
1.0.8678.23934
Modules
Images
c:\users\admin\appdata\local\temp\7zsd164.tmp\hola-setup-core.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3288"C:\Program Files\Internet Explorer\iexplore.exe" "yg5sjx5kzy.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3308.\Hola-Setup-Core.exeC:\Users\admin\AppData\Local\Temp\7zSBE3A.tmp\Hola-Setup-Core.exe
Hola-Setup (1).exe
User:
admin
Company:
Hola Networks Ltd.
Integrity Level:
HIGH
Description:
Hola VPN Setup
Exit code:
0
Version:
1.0.8678.23934
Modules
Images
c:\users\admin\appdata\local\temp\7zsbe3a.tmp\hola-setup-core.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3652"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3288 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
37 180
Read events
36 972
Write events
160
Delete events
48

Modification events

(PID) Process:(3288) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3288) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
553925104
(PID) Process:(3288) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31088726
(PID) Process:(3288) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
854086354
(PID) Process:(3288) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31088726
(PID) Process:(3288) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3288) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3288) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3288) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3288) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
10
Suspicious files
8
Text files
15
Unknown types
4

Dropped files

PID
Process
Filename
Type
3652iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\map[1].pngimage
MD5:6F9C36EE936D6277445776B5537B3952
SHA256:9A50AB927B524C6CC2BA39C809EE3BC92AE70C04DFDA9F0C34C9680BA63C8456
3652iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:EEAEC5BB9C6DCA1C52A64C88AA91E674
SHA256:55AA984692C17C30CF47E8A48392ED1AF7A1D5AAB8E40078CEDEF74A36077DB3
3652iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:50B8B7CB8CCC78BEFE63E0E1C24259B6
SHA256:12544FE2248E040E669127B4872C31E10AC424D3771360E17F051445FFF48CD2
3652iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:F174E454FF9E2FA7D3A91423FD226F44
SHA256:C11C89542027091FAFB866FD5529785204589703923C28F32065C439854336F1
3652iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\FDCC27A142E421CAE33B19B381FB4D2Dbinary
MD5:4DEE5B43249D72B379EA430A287870AE
SHA256:11EA4E715F71782F0BD640D66EABF8B3FF1161A882F0D30B560555DE32767314
3652iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\YKEZUMG5.htmhtml
MD5:87BF5007E32D76C93EE6256D779CCFBF
SHA256:39B05A5536DC7CE3ED2AEA3338AAA6B23FFB4EA147F4249501D64FD3592C564E
3652iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:F2991F15E48F930FD2157A2CB4E0CCCA
SHA256:3F886AF7A76D765C74E5A3F5E58D4FF086EBACDADCECDC148AA278371D1336F6
3652iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dder
MD5:0DD41116F35C430E6E3E889A24BDFC03
SHA256:210C4804C0ADE4A6C41EA1F1D8D1060E5DA9A558517C3A26DCDBDFC0A6475510
3652iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\unsupported_ie[1].pngimage
MD5:38DE96BE11EECF385B84CDD43D0A814B
SHA256:1CFCD41E309324FB458FCF4415D2594D1F57D82AB4C4616F9C464E2F5260AFBA
3288iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:422A382ACC22EFAA008D33C113C3430B
SHA256:F8E33E0A1C24C98B408CC2AFAE646407938367350DACEA71B21883F40AD358DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
37
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3652
iexplore.exe
GET
302
54.225.121.9:80
http://yg5sjx5kzy.com/
unknown
html
138 b
unknown
3652
iexplore.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
binary
1.42 Kb
unknown
3652
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f78d505714a595e3
unknown
unknown
3652
iexplore.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
binary
2.18 Kb
unknown
3652
iexplore.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQCkPYbZy1zGfVhAfBmc5PBx
unknown
binary
472 b
unknown
3288
iexplore.exe
GET
304
88.221.87.138:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?70d85e3b0e586cab
unknown
unknown
3288
iexplore.exe
GET
304
88.221.87.138:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?96c8eb5dfc595a04
unknown
unknown
3288
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
312 b
unknown
3288
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
1080
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6776476d79efed94
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
3652
iexplore.exe
54.225.121.9:80
yg5sjx5kzy.com
AMAZON-AES
US
unknown
4
System
192.168.100.255:137
whitelisted
3652
iexplore.exe
54.225.121.9:443
yg5sjx5kzy.com
AMAZON-AES
US
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3652
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
3652
iexplore.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
3652
iexplore.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
3652
iexplore.exe
169.150.247.39:443
cdn4.yg5sjx5kzy.com
GB
unknown
3288
iexplore.exe
23.55.222.49:443
www.bing.com
Akamai International B.V.
AU
unknown

DNS requests

Domain
IP
Reputation
yg5sjx5kzy.com
  • 54.225.121.9
  • 107.22.193.119
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
  • 88.221.87.138
  • 88.221.87.139
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
cdn4.yg5sjx5kzy.com
  • 169.150.247.39
unknown
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 23.55.222.49
  • 23.55.222.59
  • 23.55.222.43
  • 23.55.222.40
  • 23.55.222.82
  • 23.55.222.74
  • 23.55.222.75
  • 23.55.222.72
  • 23.55.222.66
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted

Threats

No threats detected
Process
Message
Hola-Setup-Core.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
Hola-Setup-Core.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
Hola-Setup-Core.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
Hola-Setup-Core.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
Hola-Setup-Core.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
Hola-Setup-Core.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
Hola-Setup-Core.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
Hola-Setup-Core.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
Hola-Setup-Core.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
Hola-Setup-Core.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144