URL:

bongacams.com

Full analysis: https://app.any.run/tasks/55ca4048-d42b-49aa-9593-d6e9bbd2265b
Verdict: Malicious activity
Analysis date: March 22, 2024, 12:27:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

2A1513D9BB8E5DABC60A970339C6CE62

SHA1:

3AE20B867EC766AAD7AD64F3D90831529A78833B

SHA256:

8F525BC23951CFFB6028FD4828447F7D2196F89E0079EA506E0614539D6776DA

SSDEEP:

3:/Er2:J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • iexplore.exe (PID: 4008)
      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdgeUpdate.exe (PID: 764)
      • iexplore.exe (PID: 1308)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 844)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Executable content was dropped or overwritten

      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Creates a software uninstall entry

      • MicrosoftEdgeUpdate.exe (PID: 764)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 2396)
    • Reads the Internet Settings

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Executes as Windows Service

      • MicrosoftEdgeUpdate.exe (PID: 3172)
    • Reads settings of System Certificates

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 3504)
      • MicrosoftEdgeUpdate.exe (PID: 3172)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 3504)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 4008)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 1308)
      • iexplore.exe (PID: 4008)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 4008)
    • Checks supported languages

      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdate.exe (PID: 764)
      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdgeUpdate.exe (PID: 2396)
      • MicrosoftEdgeUpdate.exe (PID: 924)
      • MicrosoftEdgeUpdate.exe (PID: 844)
      • MicrosoftEdgeUpdate.exe (PID: 920)
      • MicrosoftEdgeUpdate.exe (PID: 3504)
      • MicrosoftEdgeUpdate.exe (PID: 3172)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
      • setup.exe (PID: 2768)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 1308)
      • iexplore.exe (PID: 4008)
    • The process uses the downloaded file

      • iexplore.exe (PID: 4008)
      • MicrosoftEdgeSetup.exe (PID: 2668)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 844)
    • Reads the computer name

      • MicrosoftEdgeUpdate.exe (PID: 844)
      • MicrosoftEdgeUpdate.exe (PID: 764)
      • MicrosoftEdgeUpdate.exe (PID: 924)
      • MicrosoftEdgeUpdate.exe (PID: 2396)
      • MicrosoftEdgeUpdate.exe (PID: 3504)
      • MicrosoftEdgeUpdate.exe (PID: 920)
      • MicrosoftEdgeUpdate.exe (PID: 3172)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
      • setup.exe (PID: 2768)
    • Create files in a temporary directory

      • MicrosoftEdgeUpdate.exe (PID: 844)
      • MicrosoftEdgeSetup.exe (PID: 2668)
      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Creates files in the program directory

      • MicrosoftEdgeUpdateSetup.exe (PID: 992)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 3024)
      • setup.exe (PID: 2768)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 3504)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 3504)
      • MicrosoftEdgeUpdate.exe (PID: 3172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
14
Malicious processes
6
Suspicious processes
3

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe microsoftedgesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdatesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedge_x86_109.0.1518.140.exe setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
764"C:\Program Files\Microsoft\Temp\EUEC6E.tmp\MicrosoftEdgeUpdate.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installelevatedC:\Program Files\Microsoft\Temp\EUEC6E.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\temp\euec6e.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
844C:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0"C:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\users\admin\appdata\local\temp\eue7ab.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
920"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installsource taggedmi /sessionid "{5D4E3D44-0B6F-4686-8303-643B85250844}"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
924"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvcC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
992"C:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdateSetup.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\EUE7AB.tmp\MicrosoftEdgeUpdateSetup.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\users\admin\appdata\local\temp\eue7ab.tmp\microsoftedgeupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1308"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4008 CREDAT:988425 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2396"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2668"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\MicrosoftEdgeSetup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\MicrosoftEdgeSetup.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.185.21
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\microsoftedgesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2768"C:\Program Files\Microsoft\EdgeUpdate\Install\{BB8BC534-5D55-488F-A18B-0FDB49C28350}\EDGEMITMP_9BF21.tmp\setup.exe" --install-archive="C:\Program Files\Microsoft\EdgeUpdate\Install\{BB8BC534-5D55-488F-A18B-0FDB49C28350}\MicrosoftEdge_X86_109.0.1518.140.exe" --msedge --verbose-logging --do-not-launch-msedge --system-level --channel=stableC:\Program Files\Microsoft\EdgeUpdate\Install\{BB8BC534-5D55-488F-A18B-0FDB49C28350}\EDGEMITMP_9BF21.tmp\setup.exeMicrosoftEdge_X86_109.0.1518.140.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Installer
Exit code:
0
Version:
109.0.1518.140
Modules
Images
c:\program files\microsoft\edgeupdate\install\{bb8bc534-5d55-488f-a18b-0fdb49c28350}\edgemitmp_9bf21.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
2856"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4008 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
53 610
Read events
49 729
Write events
3 694
Delete events
187

Modification events

(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31095892
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31095892
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(4008) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
308
Suspicious files
38
Text files
63
Unknown types
18

Dropped files

PID
Process
Filename
Type
2856iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\SRZUCU66.txttext
MD5:DF9917A2A7AC9BF191F909A733467ECA
SHA256:E6D07C705C5299D4823D49039364B6C5189162379BBABF8FB980B7E23E17E7DB
2856iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\VEEDYNZT.txttext
MD5:6022AFE73C1924D693B7463CF3310C7B
SHA256:0AD3AE467F3FFA7C84EA066288FAB8B5612A63963156A32F2150869480E885DF
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:B8A666BBE344638A6FAB79BBE7A3B603
SHA256:A419CF13A2AB44A325AB2B62B3D1A4FB5D29A4CC60F561FDD18B75D8D9E1676E
2856iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\QGMUITWZ.txttext
MD5:EA84FC677D323FD07FED4AEE4EB1A00F
SHA256:D470FB576C41FDBC6CEB29E3A7E8D12BE7E72D42388851764F225C49517ECC97
2856iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\N1X20SEY.txttext
MD5:22A6A651DFB54C196E0AD8EA26F63450
SHA256:531E13E58929F9E01D18CFE959959BEFC679D32FC928FC495277000D21A140BD
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAder
MD5:AC89A852C2AAA3D389B2D2DD312AD367
SHA256:0B720E19270C672F9B6E0EC40B468AC49376807DE08A814573FE038779534F45
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAbinary
MD5:D1D3839BC05D198A027AC180648E947C
SHA256:2DF424E895A759E88C7DF1FCC757ED549E7636A0F48195EF85397E643B6446A4
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:FFE84D7CEED1CD921B984B8F08C39B13
SHA256:B79338846D4DC1A563D58E429777F8F0F0A8C4F7B5F71DDF2038FD52EA24DDA4
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3F26ED5DE6B4E859CCCA6035ECB8D9CBder
MD5:7B6FC1382501CCFFBA588810F25B7696
SHA256:C0360A390C3D09356BE3815C06AF2F7204150AB9D52B9AA274B7F7369D6A4799
2856iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:0526E6CD3B75C73204A506A84278AD1F
SHA256:118B8B5DC5158F21F08DD5B87B2A5CCCD7896F6DD24A362D4E8F25A61DA2320B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
68
DNS requests
36
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2856
iexplore.exe
GET
304
23.216.77.69:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?545e1839169dd0e6
unknown
unknown
2856
iexplore.exe
GET
302
195.85.23.89:80
http://bongacams.com/
unknown
html
96 b
unknown
2856
iexplore.exe
GET
304
23.216.77.80:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a08f35fbea17b647
unknown
unknown
2856
iexplore.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQCTi7COYph7T3X5jLalBFyW
unknown
binary
2.18 Kb
unknown
2856
iexplore.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
binary
1.42 Kb
unknown
2856
iexplore.exe
GET
200
23.216.77.80:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2bcc7bd96f118a84
unknown
compressed
67.5 Kb
unknown
2856
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2856
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
2856
iexplore.exe
GET
200
69.192.161.44:80
http://x2.c.lencr.org/
unknown
binary
299 b
unknown
2856
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDS57q68k6VpwlSRtIvj9A4
unknown
binary
472 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
2856
iexplore.exe
195.85.23.89:80
bongacams.com
Cloudflare London, LLC
CZ
unknown
2856
iexplore.exe
195.85.23.96:443
de.bongacams.com
Cloudflare London, LLC
CZ
unknown
2856
iexplore.exe
23.216.77.69:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2856
iexplore.exe
23.216.77.80:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2856
iexplore.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
2856
iexplore.exe
142.250.74.200:443
www.googletagmanager.com
GOOGLE
US
unknown
2856
iexplore.exe
195.85.23.30:443
i.bgmicdn.com
Cloudflare London, LLC
CZ
unknown

DNS requests

Domain
IP
Reputation
bongacams.com
  • 195.85.23.89
  • 195.85.23.88
unknown
de.bongacams.com
  • 195.85.23.96
unknown
ctldl.windowsupdate.com
  • 23.216.77.80
  • 23.216.77.69
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
i.bgmicdn.com
  • 195.85.23.30
  • 195.85.23.226
unknown
www.googletagmanager.com
  • 142.250.74.200
whitelisted
ocsp.pki.goog
  • 142.250.184.195
whitelisted
x1.c.lencr.org
  • 69.192.161.44
whitelisted
x2.c.lencr.org
  • 69.192.161.44
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info