URL:

https://www.uschovna.cz/poslat-zasilku

Full analysis: https://app.any.run/tasks/32126cda-6962-44c6-b1ec-87db7fc24f66
Verdict: Malicious activity
Analysis date: July 14, 2023, 11:53:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

BD23A7DB2CBDD447F1F8F2DFDD6746EF

SHA1:

081FB594DF0AF6B524C84761BA828D012797CFC8

SHA256:

8A6322A5CB39F6A853B962F772C2E1DAAADA559AAFFA32872E253B196C839B68

SSDEEP:

3:N8DSLG2tt1:2OLGAL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 856)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 3028)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 2868)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 4036)
      • saBSI.exe (PID: 2984)
      • advanced-bat-to-exe-converter-4.23-installer.exe (PID: 680)
      • setupinf.exe (PID: 3740)
      • aB2Econv.exe (PID: 3664)
    • Loads dropped or rewritten executable

      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 1188)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3788)
      • aB2Econv.exe (PID: 3664)
      • advanced-bat-to-exe-converter-4.23-installer.exe (PID: 680)
    • Creates a writable file the system directory

      • advanced-bat-to-exe-converter-4.23-installer.exe (PID: 680)
  • SUSPICIOUS

    • Reads the Internet Settings

      • cookie_exporter.exe (PID: 2604)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3788)
      • saBSI.exe (PID: 2984)
    • Executable content was dropped or overwritten

      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 856)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3788)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 3028)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 2868)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 4036)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 1188)
      • advanced-bat-to-exe-converter-4.23-installer.exe (PID: 680)
    • Reads settings of System Certificates

      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3788)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 1188)
      • saBSI.exe (PID: 2984)
    • Reads the Windows owner or organization settings

      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3788)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 1188)
    • Adds/modifies Windows certificates

      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 3028)
    • The process creates files with name similar to system file names

      • advanced-bat-to-exe-converter-4.23-installer.exe (PID: 680)
    • Reads security settings of Internet Explorer

      • saBSI.exe (PID: 2984)
    • Checks Windows Trust Settings

      • saBSI.exe (PID: 2984)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 2756)
      • msedge.exe (PID: 856)
      • iexplore.exe (PID: 1132)
      • msedge.exe (PID: 1084)
    • Checks supported languages

      • cookie_exporter.exe (PID: 2604)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 856)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 2952)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 3028)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3788)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 2868)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3556)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 4036)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 1188)
      • saBSI.exe (PID: 2984)
      • advanced-bat-to-exe-converter-4.23-installer.exe (PID: 680)
      • setupinf.exe (PID: 3740)
      • aB2Econv.exe (PID: 3664)
    • Reads the computer name

      • cookie_exporter.exe (PID: 2604)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 2952)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3788)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3556)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 1188)
      • saBSI.exe (PID: 2984)
      • advanced-bat-to-exe-converter-4.23-installer.exe (PID: 680)
    • The process checks LSA protection

      • explorer.exe (PID: 4036)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 2952)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3788)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3556)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 1188)
      • saBSI.exe (PID: 2984)
      • advanced-bat-to-exe-converter-4.23-installer.exe (PID: 680)
      • setupinf.exe (PID: 3740)
      • aB2Econv.exe (PID: 3664)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 1084)
      • msedge.exe (PID: 3744)
      • msedge.exe (PID: 2124)
    • The process uses the downloaded file

      • msedge.exe (PID: 1580)
    • Manual execution by a user

      • explorer.exe (PID: 4036)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 856)
      • opera.exe (PID: 952)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 2868)
      • aB2Econv.exe (PID: 3664)
    • Create files in a temporary directory

      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 856)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 3028)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3788)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 2868)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe (PID: 4036)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 1188)
      • advanced-bat-to-exe-converter-4.23-installer.exe (PID: 680)
      • setupinf.exe (PID: 3740)
      • aB2Econv.exe (PID: 3664)
    • Application was dropped or rewritten from another process

      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 2952)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3788)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3556)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 1188)
    • Reads the machine GUID from the registry

      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 3788)
      • advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp (PID: 1188)
      • saBSI.exe (PID: 2984)
      • setupinf.exe (PID: 3740)
      • aB2Econv.exe (PID: 3664)
    • Creates files in the program directory

      • saBSI.exe (PID: 2984)
      • advanced-bat-to-exe-converter-4.23-installer.exe (PID: 680)
    • Creates files or folders in the user directory

      • advanced-bat-to-exe-converter-4.23-installer.exe (PID: 680)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
95
Malicious processes
9
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe ie_to_edge_stub.exe no specs ie_to_edge_stub.exe no specs ie_to_edge_stub.exe no specs ie_to_edge_stub.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs ie_to_edge_stub.exe no specs ie_to_edge_stub.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs ie_to_edge_stub.exe no specs ie_to_edge_stub.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs cookie_exporter.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs opera.exe msedge.exe no specs msedge.exe no specs explorer.exe no specs msedge.exe no specs advanced-bat-to-exe-converter-4.23-installer_tdff-x1.exe advanced-bat-to-exe-converter-4.23-installer_tdff-x1.tmp no specs advanced-bat-to-exe-converter-4.23-installer_tdff-x1.exe advanced-bat-to-exe-converter-4.23-installer_tdff-x1.tmp msedge.exe no specs advanced-bat-to-exe-converter-4.23-installer_tdff-x1.exe advanced-bat-to-exe-converter-4.23-installer_tdff-x1.tmp no specs advanced-bat-to-exe-converter-4.23-installer_tdff-x1.exe advanced-bat-to-exe-converter-4.23-installer_tdff-x1.tmp msedge.exe no specs sabsi.exe advanced-bat-to-exe-converter-4.23-installer.exe msedge.exe setupinf.exe no specs ab2econv.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2420 --field-trial-handle=1216,i,8607904822743172121,4343649401682983710,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
312"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3492 --field-trial-handle=1216,i,8607904822743172121,4343649401682983710,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
528"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2108 --field-trial-handle=1216,i,8607904822743172121,4343649401682983710,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\microsoft\edge\application\msedge.exe
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
632"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3700 --field-trial-handle=1276,i,9666411208683906154,16429138658214644922,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\msedge.exe
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cryptbase.dll
632"C:\Program Files\Microsoft\Edge\Application\109.0.1518.115\BHO\ie_to_edge_stub.exe" --from-ie-to-edge=1 --customer-type=1 -- "http://www.bing.com/search?q=advanced+bat+to+exe+converter+download&src=IE-SearchBox&FORM=IESR3A&pc=EUPP_UE10"C:\Program Files\Microsoft\Edge\Application\109.0.1518.115\BHO\ie_to_edge_stub.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
IEToEdge BHO
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\109.0.1518.115\bho\ie_to_edge_stub.exe
c:\windows\system32\ntdll.dll
680"C:\Users\admin\Downloads\advanced-bat-to-exe-converter-4.23-installer.exe" C:\Users\admin\Downloads\advanced-bat-to-exe-converter-4.23-installer.exe
advanced-bat-to-exe-converter-4.23-installer_tDff-X1.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\downloads\advanced-bat-to-exe-converter-4.23-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
736"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=46 --mojo-platform-channel-handle=6416 --field-trial-handle=1216,i,8607904822743172121,4343649401682983710,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
832"C:\Program Files\Microsoft\Edge\Application\109.0.1518.115\BHO\ie_to_edge_stub.exe" --create-cache-container=0C:\Program Files\Microsoft\Edge\Application\109.0.1518.115\BHO\ie_to_edge_stub.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
IEToEdge BHO
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\109.0.1518.115\bho\ie_to_edge_stub.exe
c:\windows\system32\ntdll.dll
856"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --from-ie-to-edge=1 --customer-type=1 --single-argument http://www.bing.com/search?q=advanced+bat+to+exe+downlaod&src=IE-TopResult&FORM=IETR02&pc=EUPP_UE10&conversationid=C:\Program Files\Microsoft\Edge\Application\msedge.exeie_to_edge_stub.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
856"C:\Users\admin\Downloads\advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe" C:\Users\admin\Downloads\advanced-bat-to-exe-converter-4.23-installer_tDff-X1.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Capturāl Lmk
Exit code:
0
Version:
8.7.2431
Modules
Images
c:\users\admin\downloads\advanced-bat-to-exe-converter-4.23-installer_tdff-x1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\lpk.dll
Total events
52 370
Read events
51 962
Write events
374
Delete events
34

Modification events

(PID) Process:(1132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
43
Suspicious files
431
Text files
383
Unknown types
1

Dropped files

PID
Process
Filename
Type
2756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.datbinary
MD5:A2B913D3BC9B6344C76B056712064197
SHA256:CC7E7F39A2B36FFD7D6EC45A4AA70BFB8DBEBC58EEB784D08218B0036D3AD564
3624iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
2084msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\CrashpadMetrics.pmabinary
MD5:886E82F2CA62ECCCE64601B30592078A
SHA256:E5E13D53601100FF3D6BB71514CBCCC4C73FE9B7EF5E930100E644187B42948E
3624iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab298.tmpcompressed
MD5:3AC860860707BAAF32469FA7CC7C0192
SHA256:D015145D551ECD14916270EFAD773BBC9FD57FAD2228D2C24559F696C961D904
3624iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar2AB.tmpbinary
MD5:4FF65AD929CD9A367680E0E5B1C08166
SHA256:C8733C93CC5AAF5CA206D06AF22EE8DBDEC764FB5085019A6A9181FEB9DFDEE6
3624iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\v1[1].xmlxml
MD5:DB1AADD13ECD5B5FA97119B7B5000D85
SHA256:4BF5F613A25A5D431C32870C9402F3476263193307DFB6A7B9A31ADA831E50E7
3624iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:3AC860860707BAAF32469FA7CC7C0192
SHA256:D015145D551ECD14916270EFAD773BBC9FD57FAD2228D2C24559F696C961D904
2756msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Variationsbinary
MD5:961E3604F228B0D10541EBF921500C86
SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED
3624iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:DE9A8214692ED66D1B86ABF75032587A
SHA256:90CD337EBC538AE1EC388F030F38ECD58BBA7205E9E7E5A035BD24EC47ACDCC0
3624iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_D46D6FA25B74360E1349F9015B5CCE53binary
MD5:C578E0E3BCCCF16596E46D9DD5A429E9
SHA256:2B4FFBEA6319300269F4C8048980ACBA6DE8DF29761F8BCDC42CC35BD4BAEAF6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
46
TCP/UDP connections
405
DNS requests
309
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3624
iexplore.exe
GET
142.250.185.99:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCECyP1HvZSJrzEIqeU6yEBFk%3D
US
whitelisted
3624
iexplore.exe
GET
200
8.238.30.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?470891137287efc4
US
compressed
62.3 Kb
whitelisted
3624
iexplore.exe
GET
200
8.238.30.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a079bccc846085c6
US
compressed
4.70 Kb
whitelisted
3624
iexplore.exe
GET
200
104.84.250.230:80
http://x1.c.lencr.org/
US
binary
717 b
whitelisted
3624
iexplore.exe
GET
200
8.238.30.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?efa354005cfcb512
US
compressed
62.3 Kb
whitelisted
3624
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEALnkXH7gCHpP%2BLZg4NMUMA%3D
US
binary
471 b
whitelisted
3624
iexplore.exe
GET
200
8.238.30.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b8d8ffc7f83be446
US
compressed
4.70 Kb
whitelisted
3624
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
US
binary
471 b
whitelisted
3624
iexplore.exe
GET
200
142.250.185.99:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEHFqGvcZW4luEC%2Bj74dtJbY%3D
US
binary
471 b
whitelisted
3624
iexplore.exe
GET
200
142.250.185.99:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3624
iexplore.exe
88.221.179.76:443
go.microsoft.com
AKAMAI-AS
GB
suspicious
3624
iexplore.exe
77.78.95.234:443
CASABLANCA INT a.s.
CZ
unknown
3624
iexplore.exe
8.238.30.254:80
ctldl.windowsupdate.com
LEVEL3
US
suspicious
3388
svchost.exe
239.255.255.250:1900
whitelisted
3624
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3624
iexplore.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3624
iexplore.exe
104.84.250.230:80
x1.c.lencr.org
AKAMAI-AS
GB
unknown
3624
iexplore.exe
23.215.61.11:80
r3.o.lencr.org
Akamai International B.V.
GB
unknown

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 88.221.179.76
whitelisted
ctldl.windowsupdate.com
  • 8.238.30.254
  • 8.248.145.254
  • 8.241.9.254
  • 8.238.34.126
  • 8.241.9.126
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
x1.c.lencr.org
  • 104.84.250.230
whitelisted
r3.o.lencr.org
  • 23.215.61.11
  • 23.212.109.152
shared
fonts.googleapis.com
  • 142.250.185.138
whitelisted
pagead2.googlesyndication.com
  • 142.250.186.130
  • 142.250.185.66
whitelisted
cdn.performax.cz
  • 109.123.210.83
  • 109.123.210.85
  • 109.123.210.81
unknown
cms.tiscali.cz
  • 81.0.235.157
  • 109.123.210.18
  • 82.208.7.53
unknown

Threats

PID
Process
Class
Message
3744
msedge.exe
Misc activity
ET INFO Observed ZeroSSL SSL/TLS Certificate
Process
Message
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-PAR6K.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-PAR6K.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-PAR6K.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-PAR6K.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-PAR6K.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-PAR6K.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory