URL:

https://d94r2itylgwnp.cloudfront.net/Drivers/2023/2023.4/Zebra_2023.4.exe

Full analysis: https://app.any.run/tasks/8bdc6ebf-c452-4bad-ac7c-8507fc1f5c79
Verdict: Malicious activity
Analysis date: January 10, 2024, 21:07:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

AB447EE7246B80E9220C7F87F646D9CD

SHA1:

18CC206E5D79F903C64E615DDE8A706242C4F0FD

SHA256:

8E0A3E0ACF089C71657360A1AAA92C070F907831D4EFDF140F8F7649A36B26C6

SSDEEP:

3:N8ERJJRE5Il/06rdX9X0TXVXMyC:2En0VAX9X+XfC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • drvinst.exe (PID: 1492)
      • DriverEnvironmentSetup.exe (PID: 844)
    • Registers / Runs the DLL via REGSVR32.EXE

      • PrintIsolationHost.exe (PID: 1892)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Zebra_2023.4.exe (PID: 2172)
      • DriverWizard.exe (PID: 1600)
      • certutil.exe (PID: 3868)
    • Reads settings of System Certificates

      • certutil.exe (PID: 3868)
      • rundll32.exe (PID: 1696)
    • Starts CMD.EXE for commands execution

      • DriverWizard.exe (PID: 1600)
    • Creates files in the driver directory

      • drvinst.exe (PID: 1492)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 1492)
    • Adds/modifies Windows certificates

      • rundll32.exe (PID: 1696)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • PrintIsolationHost.exe (PID: 1892)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 116)
      • msedge.exe (PID: 2384)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2032)
      • Zebra_2023.4.exe (PID: 2172)
      • drvinst.exe (PID: 1492)
      • DriverWizard.exe (PID: 1600)
      • PrintIsolationHost.exe (PID: 1892)
      • DriverEnvironmentSetup.exe (PID: 844)
    • The process uses the downloaded file

      • iexplore.exe (PID: 116)
    • Create files in a temporary directory

      • Zebra_2023.4.exe (PID: 2172)
      • __ExtractWizard.exe (PID: 2168)
      • DriverWizard.exe (PID: 1600)
    • Reads the computer name

      • Zebra_2023.4.exe (PID: 2172)
      • DriverWizard.exe (PID: 1600)
      • drvinst.exe (PID: 1492)
      • wmpnscfg.exe (PID: 3288)
    • Checks supported languages

      • __ExtractWizard.exe (PID: 2168)
      • Zebra_2023.4.exe (PID: 2172)
      • DriverWizard.exe (PID: 1600)
      • drvinst.exe (PID: 1492)
      • DriverEnvironmentSetup.exe (PID: 844)
      • wmpnscfg.exe (PID: 3288)
    • Creates files in the program directory

      • DriverWizard.exe (PID: 1600)
      • cmd.exe (PID: 3652)
      • DriverEnvironmentSetup.exe (PID: 844)
      • PrintIsolationHost.exe (PID: 1892)
    • Creates files or folders in the user directory

      • certutil.exe (PID: 3868)
    • Reads the machine GUID from the registry

      • DriverWizard.exe (PID: 1600)
      • drvinst.exe (PID: 1492)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 1696)
    • Process drops legitimate windows executable

      • DriverEnvironmentSetup.exe (PID: 844)
    • The process drops C-runtime libraries

      • DriverEnvironmentSetup.exe (PID: 844)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1836)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3288)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
81
Monitored processes
36
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe zebra_2023.4.exe no specs __extractwizard.exe no specs msedge.exe driverwizard.exe no specs msedge.exe no specs driverwizard.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs cmd.exe no specs certutil.exe no specs cmd.exe no specs certutil.exe cmd.exe no specs certutil.exe no specs drvinst.exe no specs rundll32.exe no specs vssvc.exe no specs printisolationhost.exe no specs driverenvironmentsetup.exe no specs regsvr32.exe no specs netsh.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\Internet Explorer\iexplore.exe" "https://d94r2itylgwnp.cloudfront.net/Drivers/2023/2023.4/Zebra_2023.4.exe"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
568"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1228 --field-trial-handle=1312,i,5824918073967521165,6710957653905088905,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
844"C:\Program Files\Seagull\Printer Drivers\Packages\2023.4\DriverEnvironmentSetup.exe" "C:\Program Files\Seagull\Printer Drivers\Common" "C:\Program Files\Seagull\Printer Drivers\Packages\2023.4" "Zebra 90"C:\Program Files\Seagull\Printer Drivers\Packages\2023.4\DriverEnvironmentSetup.exePrintIsolationHost.exe
User:
SYSTEM
Company:
Seagull Scientific, LLC.
Integrity Level:
SYSTEM
Description:
Driver Environment Setup
Exit code:
0
Version:
2023.4
Modules
Images
c:\program files\seagull\printer drivers\packages\2023.4\driverenvironmentsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1092certutil -addstore "TrustedPublisher" "C:\Users\admin\Desktop\Seagull\2023.4\SeagullPublisher.cer"C:\Windows\System32\certutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
CertUtil.exe
Exit code:
0
Version:
6.1.7601.18151 (win7sp1_gdr.130512-1533)
Modules
Images
c:\windows\system32\certutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\certcli.dll
c:\windows\system32\atl.dll
1196"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2312 --field-trial-handle=1312,i,5824918073967521165,6710957653905088905,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1492DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{4e8af2f7-c54f-6cdb-1168-dc3bb11f490f}\Zebra.inf" "0" "638d9e193" "000004B0" "WinSta0\Default" "000005B8" "208" "C:\Users\admin\Desktop\Seagull\2023.4"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1600"C:\Users\admin\Desktop\Seagull\2023.4\DriverWizard.exe" C:\Users\admin\Desktop\Seagull\2023.4\DriverWizard.exe
Zebra_2023.4.exe
User:
admin
Company:
Seagull Scientific, LLC.
Integrity Level:
HIGH
Description:
Driver Wizard
Exit code:
0
Version:
2023.4
Modules
Images
c:\users\admin\desktop\seagull\2023.4\driverwizard.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\version.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1696rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{310fd450-acd8-4cca-9ebb-f21bc1530247} Global\{6be23a3e-dee3-587f-d121-89025a23cc72} C:\Windows\System32\DriverStore\Temp\{18c80ab1-380c-33c3-7916-3d31542eac7f}\Zebra.inf C:\Windows\System32\DriverStore\Temp\{18c80ab1-380c-33c3-7916-3d31542eac7f}\Zebra.catC:\Windows\System32\rundll32.exedrvinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1836C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1892C:\Windows\system32\PrintIsolationHost.exe -EmbeddingC:\Windows\System32\PrintIsolationHost.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
PrintIsolationHost
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\printisolationhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
35 675
Read events
35 437
Write events
234
Delete events
4

Modification events

(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
160
Suspicious files
215
Text files
63
Unknown types
1

Dropped files

PID
Process
Filename
Type
116iexplore.exeC:\Users\admin\Downloads\Zebra_2023.4.exe
MD5:
SHA256:
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8binary
MD5:7121B22EFAA015C5BDB8D93B07603929
SHA256:94E71397D9BFF48F2DBF82641F290E2BFC4AFC976A0B187831C07AAC426CCA0B
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:721DBCE2E025AB483C13C0BE45073CBF
SHA256:F8C124AD9C06C46045237CF1C70B5E84F0FCD2F9C2C9DBC088F18A8E4185894E
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:32F14F4C6A50C5AB84CC93D053FD898B
SHA256:2DC7C948B1C85AE94F47147CD8BB7B3649EBF3DA8B799B4482E59D3EEC7494FE
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:2E2A52F459A4CEE7B3B1D04B8BBCEAD0
SHA256:C7228426A5CCD5BD8FDD79F4B5FBEB729585ED017C623DDF4652CD15CEEF737D
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:8E237C0175726F1EF58E7DACD9786A0F
SHA256:8F8D5D7C9B5D7332B51F0D862019D226FF761BAA4A562DB1493EB797398B4145
116iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:B566E09460D4151E1222EBD6EFDDA5FB
SHA256:2705B0AA849632B8CCE1B0C807160A3192F5293D084646F71A39D059C684A822
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:D674AC30C4B34A55609D1DEB75BCCD81
SHA256:758B13E0CCC87D734096A8EC29C76D66A43B9F620A3101B2CB1A7B7CF65E1067
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8binary
MD5:F244888E7EC84A3D8866FFA06B9BEAA8
SHA256:F420B077BBC932487CA82425280106421DAA35F629E46693CC2282E8830350E4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
35
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?82133fd523bdb31d
GB
unknown
3868
certutil.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
US
binary
727 b
unknown
2032
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?129d20c84d8c4223
GB
compressed
4.66 Kb
unknown
116
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
unknown
116
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
unknown
116
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAqvpsXKY8RRQeo74ffHUxc%3D
US
binary
471 b
unknown
2032
iexplore.exe
GET
200
108.138.2.173:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
binary
2.02 Kb
unknown
3868
certutil.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEASbnKZ6aVbkEWzAHdvohsY%3D
US
binary
727 b
unknown
2032
iexplore.exe
GET
200
18.66.142.79:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
binary
1.49 Kb
unknown
116
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a85e8d0c2f0a71a5
GB
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2032
iexplore.exe
143.204.98.112:443
d94r2itylgwnp.cloudfront.net
AMAZON-02
US
unknown
2032
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2032
iexplore.exe
108.138.2.173:80
o.ss2.us
AMAZON-02
US
unknown
2032
iexplore.exe
18.66.142.79:80
ocsp.rootg2.amazontrust.com
AMAZON-02
US
unknown
116
iexplore.exe
152.199.19.161:443
r20swj13mr.microsoft.com
EDGECAST
US
whitelisted
116
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
116
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
116
iexplore.exe
204.79.197.200:443
ieonline.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
d94r2itylgwnp.cloudfront.net
  • 143.204.98.112
  • 143.204.98.19
  • 143.204.98.50
  • 143.204.98.93
shared
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
o.ss2.us
  • 108.138.2.173
  • 108.138.2.107
  • 108.138.2.195
  • 108.138.2.10
whitelisted
ocsp.rootg2.amazontrust.com
  • 18.66.142.79
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.66.142.79
shared
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
go.microsoft.com
  • 2.19.86.20
whitelisted

Threats

No threats detected
No debug info