URL:

bongacams.com

Full analysis: https://app.any.run/tasks/55ca4048-d42b-49aa-9593-d6e9bbd2265b
Verdict: Malicious activity
Analysis date: March 22, 2024, 12:27:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

2A1513D9BB8E5DABC60A970339C6CE62

SHA1:

3AE20B867EC766AAD7AD64F3D90831529A78833B

SHA256:

8F525BC23951CFFB6028FD4828447F7D2196F89E0079EA506E0614539D6776DA

SSDEEP:

3:/Er2:J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • iexplore.exe (PID: 4008)
      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdgeUpdate.exe (PID: 764)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
      • iexplore.exe (PID: 1308)
    • Executable content was dropped or overwritten

      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 844)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 2396)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Creates a software uninstall entry

      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Reads the Internet Settings

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Executes as Windows Service

      • MicrosoftEdgeUpdate.exe (PID: 3172)
    • Reads settings of System Certificates

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 3504)
      • MicrosoftEdgeUpdate.exe (PID: 3172)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 3504)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 4008)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 1308)
      • iexplore.exe (PID: 4008)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 4008)
    • The process uses the downloaded file

      • iexplore.exe (PID: 4008)
      • MicrosoftEdgeSetup.exe (PID: 2668)
    • Checks supported languages

      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdgeUpdate.exe (PID: 924)
      • MicrosoftEdgeUpdate.exe (PID: 764)
      • MicrosoftEdgeUpdate.exe (PID: 2396)
      • MicrosoftEdgeUpdate.exe (PID: 3504)
      • MicrosoftEdgeUpdate.exe (PID: 920)
      • MicrosoftEdgeUpdate.exe (PID: 3172)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
      • setup.exe (PID: 2768)
      • MicrosoftEdgeUpdate.exe (PID: 844)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 1308)
      • iexplore.exe (PID: 4008)
    • Create files in a temporary directory

      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdate.exe (PID: 844)
      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Reads the computer name

      • MicrosoftEdgeUpdate.exe (PID: 844)
      • MicrosoftEdgeUpdate.exe (PID: 924)
      • MicrosoftEdgeUpdate.exe (PID: 764)
      • MicrosoftEdgeUpdate.exe (PID: 2396)
      • MicrosoftEdgeUpdate.exe (PID: 3504)
      • MicrosoftEdgeUpdate.exe (PID: 3172)
      • MicrosoftEdgeUpdate.exe (PID: 920)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
      • setup.exe (PID: 2768)
    • Creates files in the program directory

      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
      • setup.exe (PID: 2768)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 3504)
      • MicrosoftEdgeUpdate.exe (PID: 3172)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 844)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
14
Malicious processes
6
Suspicious processes
3

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe microsoftedgesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdatesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedge_x86_109.0.1518.140.exe setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
764"C:\Program Files\Microsoft\Temp\EUEC6E.tmp\MicrosoftEdgeUpdate.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installelevatedC:\Program Files\Microsoft\Temp\EUEC6E.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\temp\euec6e.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
844C:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0"C:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\users\admin\appdata\local\temp\eue7ab.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
920"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installsource taggedmi /sessionid "{5D4E3D44-0B6F-4686-8303-643B85250844}"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
924"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvcC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
992"C:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdateSetup.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdateSetup.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\users\admin\appdata\local\temp\eue7ab.tmp\microsoftedgeupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1308"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4008 CREDAT:988425 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2396"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2668"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\MicrosoftEdgeSetup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\MicrosoftEdgeSetup.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\microsoftedgesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2768"C:\Program Files\Microsoft\EdgeUpdate\Install\{BB8BC534-5D55-488F-A18B-0FDB49C28350}\EDGEMITMP_9BF21.tmp\setup.exe" --install-archive="C:\Program Files\Microsoft\EdgeUpdate\Install\{BB8BC534-5D55-488F-A18B-0FDB49C28350}\MicrosoftEdge_X86_109.0.1518.140.exe" --msedge --verbose-logging --do-not-launch-msedge --system-level --channel=stableC:\Program Files\Microsoft\EdgeUpdate\Install\{BB8BC534-5D55-488F-A18B-0FDB49C28350}\EDGEMITMP_9BF21.tmp\setup.exeMicrosoftEdge_X86_109.0.1518.140.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Installer
Exit code:
0
Version:
109.0.1518.140
Modules
Images
c:\program files\microsoft\edgeupdate\install\{bb8bc534-5d55-488f-a18b-0fdb49c28350}\edgemitmp_9bf21.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
2856"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4008 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
53 610
Read events
49 729
Write events
3 694
Delete events
187

Modification events

(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31095892
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31095892
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
308
Suspicious files
38
Text files
63
Unknown types
18

Dropped files

PID
Process
Filename
Type
2856iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\VEEDYNZT.txttext
MD5:6022AFE73C1924D693B7463CF3310C7B
SHA256:0AD3AE467F3FFA7C84EA066288FAB8B5612A63963156A32F2150869480E885DF
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Eder
MD5:8E111DD59E6AC104EC96931D9DADDB52
SHA256:2AF2A019DEF88C161803F1CFA264F50AC28D5CAEE002CF8D73DAA7C93E3C998B
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:FFE84D7CEED1CD921B984B8F08C39B13
SHA256:B79338846D4DC1A563D58E429777F8F0F0A8C4F7B5F71DDF2038FD52EA24DDA4
2856iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\M3H0U47Y.txttext
MD5:1CB0919DC6083415FD47B734C57F03B2
SHA256:CE94DECDCE5E9CF4416864902E603E1894199B66D4007C7B19F771531CC80643
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:B8A666BBE344638A6FAB79BBE7A3B603
SHA256:A419CF13A2AB44A325AB2B62B3D1A4FB5D29A4CC60F561FDD18B75D8D9E1676E
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A16C6C16D94F76E0808C087DFC657D99_99430B8B5F4E113F6193E2BF9312EF16binary
MD5:F886CB326AF7E271A77F1F1DDEB60FD7
SHA256:619FCF312F05AAB8CE4823C5FF158F0DDAB4CBA99C06194614B5D3D166FB8AD1
2856iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\SRZUCU66.txttext
MD5:DF9917A2A7AC9BF191F909A733467ECA
SHA256:E6D07C705C5299D4823D49039364B6C5189162379BBABF8FB980B7E23E17E7DB
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAder
MD5:AC89A852C2AAA3D389B2D2DD312AD367
SHA256:0B720E19270C672F9B6E0EC40B468AC49376807DE08A814573FE038779534F45
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:2B11CED0C19981CE8CDEA864023BD674
SHA256:8333067ED45E13EDAF4F443EB42C9C9EF76289624C80012A2EB034AB6775DD6F
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:0526E6CD3B75C73204A506A84278AD1F
SHA256:118B8B5DC5158F21F08DD5B87B2A5CCCD7896F6DD24A362D4E8F25A61DA2320B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
68
DNS requests
36
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2856
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2856
iexplore.exe
GET
200
23.216.77.80:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2bcc7bd96f118a84
unknown
compressed
67.5 Kb
unknown
2856
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
2856
iexplore.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
4008
iexplore.exe
GET
304
23.216.77.69:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?96c8eb5dfc595a04
unknown
unknown
2856
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDEPFkngtIXdBB5jPV%2BzWFe
unknown
binary
472 b
unknown
2856
iexplore.exe
GET
304
23.216.77.69:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?545e1839169dd0e6
unknown
unknown
1308
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
binary
471 b
unknown
2856
iexplore.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQCTi7COYph7T3X5jLalBFyW
unknown
binary
2.18 Kb
unknown
2856
iexplore.exe
GET
200
23.216.77.69:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?af0106393379bc3d
unknown
compressed
67.5 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
2856
iexplore.exe
195.85.23.89:80
bongacams.com
Cloudflare London, LLC
CZ
unknown
2856
iexplore.exe
195.85.23.96:443
de.bongacams.com
Cloudflare London, LLC
CZ
unknown
2856
iexplore.exe
23.216.77.69:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2856
iexplore.exe
23.216.77.80:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2856
iexplore.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
2856
iexplore.exe
142.250.74.200:443
www.googletagmanager.com
GOOGLE
US
unknown
2856
iexplore.exe
195.85.23.30:443
i.bgmicdn.com
Cloudflare London, LLC
CZ
unknown

DNS requests

Domain
IP
Reputation
bongacams.com
  • 195.85.23.89
  • 195.85.23.88
unknown
de.bongacams.com
  • 195.85.23.96
unknown
ctldl.windowsupdate.com
  • 23.216.77.80
  • 23.216.77.69
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
i.bgmicdn.com
  • 195.85.23.30
  • 195.85.23.226
unknown
www.googletagmanager.com
  • 142.250.74.200
whitelisted
ocsp.pki.goog
  • 142.250.184.195
whitelisted
x1.c.lencr.org
  • 69.192.161.44
whitelisted
x2.c.lencr.org
  • 69.192.161.44
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info