URL:

bongacams.com

Full analysis: https://app.any.run/tasks/55ca4048-d42b-49aa-9593-d6e9bbd2265b
Verdict: Malicious activity
Analysis date: March 22, 2024, 12:27:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

2A1513D9BB8E5DABC60A970339C6CE62

SHA1:

3AE20B867EC766AAD7AD64F3D90831529A78833B

SHA256:

8F525BC23951CFFB6028FD4828447F7D2196F89E0079EA506E0614539D6776DA

SSDEEP:

3:/Er2:J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 844)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Executable content was dropped or overwritten

      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
    • Process drops legitimate windows executable

      • MicrosoftEdgeSetup.exe (PID: 2668)
      • iexplore.exe (PID: 4008)
      • iexplore.exe (PID: 1308)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdgeUpdate.exe (PID: 764)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 2396)
    • Creates a software uninstall entry

      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Reads the Internet Settings

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Executes as Windows Service

      • MicrosoftEdgeUpdate.exe (PID: 3172)
    • Reads settings of System Certificates

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 3504)
      • MicrosoftEdgeUpdate.exe (PID: 3172)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 3504)
  • INFO

    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 844)
    • Reads the computer name

      • MicrosoftEdgeUpdate.exe (PID: 844)
      • MicrosoftEdgeUpdate.exe (PID: 764)
      • MicrosoftEdgeUpdate.exe (PID: 2396)
      • MicrosoftEdgeUpdate.exe (PID: 3504)
      • MicrosoftEdgeUpdate.exe (PID: 3172)
      • MicrosoftEdgeUpdate.exe (PID: 920)
      • setup.exe (PID: 2768)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
      • MicrosoftEdgeUpdate.exe (PID: 924)
    • Checks supported languages

      • MicrosoftEdgeUpdate.exe (PID: 844)
      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdgeUpdate.exe (PID: 2396)
      • MicrosoftEdgeUpdate.exe (PID: 924)
      • MicrosoftEdgeUpdate.exe (PID: 3504)
      • MicrosoftEdgeUpdate.exe (PID: 3172)
      • MicrosoftEdgeUpdate.exe (PID: 920)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
      • setup.exe (PID: 2768)
      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Create files in a temporary directory

      • MicrosoftEdgeUpdate.exe (PID: 844)
      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • The process uses the downloaded file

      • MicrosoftEdgeSetup.exe (PID: 2668)
      • iexplore.exe (PID: 4008)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 4008)
      • iexplore.exe (PID: 1308)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 4008)
      • iexplore.exe (PID: 1308)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 4008)
    • Application launched itself

      • iexplore.exe (PID: 4008)
    • Creates files in the program directory

      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • setup.exe (PID: 2768)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 3172)
      • MicrosoftEdgeUpdate.exe (PID: 3504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
14
Malicious processes
6
Suspicious processes
3

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe microsoftedgesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdatesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedge_x86_109.0.1518.140.exe setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
764"C:\Program Files\Microsoft\Temp\EUEC6E.tmp\MicrosoftEdgeUpdate.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installelevatedC:\Program Files\Microsoft\Temp\EUEC6E.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\temp\euec6e.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
844C:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0"C:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\users\admin\appdata\local\temp\eue7ab.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
920"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installsource taggedmi /sessionid "{5D4E3D44-0B6F-4686-8303-643B85250844}"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
924"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvcC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
992"C:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdateSetup.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdateSetup.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\users\admin\appdata\local\temp\eue7ab.tmp\microsoftedgeupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1308"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4008 CREDAT:988425 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2396"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2668"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\MicrosoftEdgeSetup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\MicrosoftEdgeSetup.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\microsoftedgesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2768"C:\Program Files\Microsoft\EdgeUpdate\Install\{BB8BC534-5D55-488F-A18B-0FDB49C28350}\EDGEMITMP_9BF21.tmp\setup.exe" --install-archive="C:\Program Files\Microsoft\EdgeUpdate\Install\{BB8BC534-5D55-488F-A18B-0FDB49C28350}\MicrosoftEdge_X86_109.0.1518.140.exe" --msedge --verbose-logging --do-not-launch-msedge --system-level --channel=stableC:\Program Files\Microsoft\EdgeUpdate\Install\{BB8BC534-5D55-488F-A18B-0FDB49C28350}\EDGEMITMP_9BF21.tmp\setup.exeMicrosoftEdge_X86_109.0.1518.140.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Installer
Exit code:
0
Version:
109.0.1518.140
Modules
Images
c:\program files\microsoft\edgeupdate\install\{bb8bc534-5d55-488f-a18b-0fdb49c28350}\edgemitmp_9bf21.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
2856"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4008 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
53 610
Read events
49 729
Write events
3 694
Delete events
187

Modification events

(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31095892
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31095892
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
308
Suspicious files
38
Text files
63
Unknown types
18

Dropped files

PID
Process
Filename
Type
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A16C6C16D94F76E0808C087DFC657D99_99430B8B5F4E113F6193E2BF9312EF16der
MD5:AEF432F927D93ABC504D4990BE869BD7
SHA256:70056CD86828AA8CE8CB68EEE2F591D99D426321FADA3AE8199FF033D5DFD9BC
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:6F52F7BBDD93D3D82C69B6CC5A34FDF0
SHA256:687B6BED014B1D33DCEFED0835660EB1AD038FD87FD7D20229112C91C2EEEC91
2856iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\QGMUITWZ.txttext
MD5:EA84FC677D323FD07FED4AEE4EB1A00F
SHA256:D470FB576C41FDBC6CEB29E3A7E8D12BE7E72D42388851764F225C49517ECC97
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:753DF6889FD7410A2E9FE333DA83A429
SHA256:B42DC237E44CBC9A43400E7D3F9CBD406DBDEFD62BFE87328F8663897D69DF78
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:2B11CED0C19981CE8CDEA864023BD674
SHA256:8333067ED45E13EDAF4F443EB42C9C9EF76289624C80012A2EB034AB6775DD6F
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A16C6C16D94F76E0808C087DFC657D99_99430B8B5F4E113F6193E2BF9312EF16binary
MD5:F886CB326AF7E271A77F1F1DDEB60FD7
SHA256:619FCF312F05AAB8CE4823C5FF158F0DDAB4CBA99C06194614B5D3D166FB8AD1
2856iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\N1X20SEY.txttext
MD5:22A6A651DFB54C196E0AD8EA26F63450
SHA256:531E13E58929F9E01D18CFE959959BEFC679D32FC928FC495277000D21A140BD
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAder
MD5:AC89A852C2AAA3D389B2D2DD312AD367
SHA256:0B720E19270C672F9B6E0EC40B468AC49376807DE08A814573FE038779534F45
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3F26ED5DE6B4E859CCCA6035ECB8D9CBbinary
MD5:695AAAB46F5DB28A6795E0F04C6FB3B9
SHA256:9541135656CF02CC6D28B6DA44238D349E168341A50507EC5F575BCB1815ECAD
2856iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\FC8SQY4S.htmhtml
MD5:950C384978B4970769DF34A8AB64173F
SHA256:3AC8F8823B37BC5198051C98DDBF8E740BAFE6F9D7B1E5C7AC7CC9637084B334
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
68
DNS requests
36
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2856
iexplore.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
binary
717 b
2856
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
2856
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQD6BeWhIbleexId20FpK0af
unknown
binary
472 b
2856
iexplore.exe
GET
200
69.192.161.44:80
http://x2.c.lencr.org/
unknown
binary
299 b
4008
iexplore.exe
GET
304
23.216.77.69:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?96c8eb5dfc595a04
unknown
2856
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDS57q68k6VpwlSRtIvj9A4
unknown
binary
472 b
2856
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDEPFkngtIXdBB5jPV%2BzWFe
unknown
binary
472 b
1308
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
4008
iexplore.exe
GET
304
23.216.77.69:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?76ad697231f9b13b
unknown
1308
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
binary
471 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
2856
iexplore.exe
195.85.23.89:80
bongacams.com
Cloudflare London, LLC
CZ
unknown
2856
iexplore.exe
195.85.23.96:443
de.bongacams.com
Cloudflare London, LLC
CZ
unknown
2856
iexplore.exe
23.216.77.69:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2856
iexplore.exe
23.216.77.80:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2856
iexplore.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
2856
iexplore.exe
142.250.74.200:443
www.googletagmanager.com
GOOGLE
US
unknown
2856
iexplore.exe
195.85.23.30:443
i.bgmicdn.com
Cloudflare London, LLC
CZ
unknown

DNS requests

Domain
IP
Reputation
bongacams.com
  • 195.85.23.89
  • 195.85.23.88
unknown
de.bongacams.com
  • 195.85.23.96
unknown
ctldl.windowsupdate.com
  • 23.216.77.80
  • 23.216.77.69
unknown
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
unknown
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
unknown
i.bgmicdn.com
  • 195.85.23.30
  • 195.85.23.226
unknown
www.googletagmanager.com
  • 142.250.74.200
unknown
ocsp.pki.goog
  • 142.250.184.195
unknown
x1.c.lencr.org
  • 69.192.161.44
unknown
x2.c.lencr.org
  • 69.192.161.44
unknown

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info