analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://any-screen-recorder.com/download/free_any_screen_recorder.exe

Full analysis: https://app.any.run/tasks/cffc278f-94a2-4a08-96ec-84a3f363bd5c
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: November 28, 2021, 17:39:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

CB061171DF94379C28865F015BF298B7

SHA1:

81F79C97A997AA7891A147A6FDD50FD39924B316

SHA256:

9834DDDD13E9F858C68C12C68ADE37D990E73FDCA1F3212C01E3C5658586C08F

SSDEEP:

3:N1KfoIcXw5KML0kXm0tC:C2APA6Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • free_any_screen_recorder.exe (PID: 3672)
      • free_any_screen_recorder.exe (PID: 2956)
      • Any Screen Recorder.exe (PID: 2940)
      • Any Screen Recorder.exe (PID: 2808)
      • Any Screen Recorder.exe (PID: 2400)
    • Drops executable file immediately after starts

      • free_any_screen_recorder.exe (PID: 2956)
      • free_any_screen_recorder.exe (PID: 3672)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 4044)
      • iexplore.exe (PID: 1324)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 4044)
      • iexplore.exe (PID: 2296)
      • free_any_screen_recorder.exe (PID: 2956)
      • free_any_screen_recorder.exe (PID: 3672)
      • free_any_screen_recorder.tmp (PID: 2628)
    • Reads the computer name

      • free_any_screen_recorder.tmp (PID: 3516)
      • free_any_screen_recorder.tmp (PID: 2628)
      • Any Screen Recorder.exe (PID: 2940)
    • Checks supported languages

      • free_any_screen_recorder.exe (PID: 2956)
      • free_any_screen_recorder.tmp (PID: 3516)
      • free_any_screen_recorder.exe (PID: 3672)
      • free_any_screen_recorder.tmp (PID: 2628)
      • Any Screen Recorder.exe (PID: 2940)
      • Any Screen Recorder.exe (PID: 2400)
      • Any Screen Recorder.exe (PID: 2808)
    • Creates a directory in Program Files

      • free_any_screen_recorder.tmp (PID: 2628)
    • Reads Windows owner or organization settings

      • free_any_screen_recorder.tmp (PID: 2628)
    • Reads the Windows organization settings

      • free_any_screen_recorder.tmp (PID: 2628)
    • Drops a file with too old compile date

      • free_any_screen_recorder.tmp (PID: 2628)
    • Starts Internet Explorer

      • Any Screen Recorder.exe (PID: 2940)
    • Drops a file with a compile date too recent

      • free_any_screen_recorder.tmp (PID: 2628)
    • Drops a file that was compiled in debug mode

      • free_any_screen_recorder.tmp (PID: 2628)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 4044)
      • iexplore.exe (PID: 2296)
      • iexplore.exe (PID: 3140)
      • iexplore.exe (PID: 1324)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2296)
      • iexplore.exe (PID: 1324)
    • Reads the computer name

      • iexplore.exe (PID: 2296)
      • iexplore.exe (PID: 4044)
      • iexplore.exe (PID: 1324)
      • iexplore.exe (PID: 3140)
    • Changes internet zones settings

      • iexplore.exe (PID: 2296)
      • iexplore.exe (PID: 3140)
    • Reads internet explorer settings

      • iexplore.exe (PID: 4044)
      • iexplore.exe (PID: 1324)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 2296)
      • iexplore.exe (PID: 1324)
    • Application launched itself

      • iexplore.exe (PID: 2296)
      • iexplore.exe (PID: 3140)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2296)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 2296)
      • iexplore.exe (PID: 3140)
    • Application was dropped or rewritten from another process

      • free_any_screen_recorder.tmp (PID: 3516)
      • free_any_screen_recorder.tmp (PID: 2628)
    • Creates a software uninstall entry

      • free_any_screen_recorder.tmp (PID: 2628)
    • Creates files in the program directory

      • free_any_screen_recorder.tmp (PID: 2628)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1324)
    • Creates files in the user directory

      • iexplore.exe (PID: 1324)
    • Manual execution by user

      • Any Screen Recorder.exe (PID: 2400)
      • Any Screen Recorder.exe (PID: 2808)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 1324)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
11
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start iexplore.exe iexplore.exe free_any_screen_recorder.exe free_any_screen_recorder.tmp no specs free_any_screen_recorder.exe free_any_screen_recorder.tmp any screen recorder.exe no specs iexplore.exe no specs iexplore.exe any screen recorder.exe no specs any screen recorder.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2296"C:\Program Files\Internet Explorer\iexplore.exe" "http://any-screen-recorder.com/download/free_any_screen_recorder.exe"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\rpcrt4.dll
4044"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2296 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
2956"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\free_any_screen_recorder.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\free_any_screen_recorder.exe
iexplore.exe
User:
admin
Company:
Any-Screen-Recorder
Integrity Level:
MEDIUM
Description:
Free Any Screen Recorder Setup
Exit code:
0
Version:
9.1.9
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\free_any_screen_recorder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
3516"C:\Users\admin\AppData\Local\Temp\is-J0M3F.tmp\free_any_screen_recorder.tmp" /SL5="$201A4,5544084,1098240,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\free_any_screen_recorder.exe" C:\Users\admin\AppData\Local\Temp\is-J0M3F.tmp\free_any_screen_recorder.tmpfree_any_screen_recorder.exe
User:
admin
Company:
Any-Screen-Recorder
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-j0m3f.tmp\free_any_screen_recorder.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3672"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\free_any_screen_recorder.exe" /SPAWNWND=$201D8 /NOTIFYWND=$201A4 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\free_any_screen_recorder.exe
free_any_screen_recorder.tmp
User:
admin
Company:
Any-Screen-Recorder
Integrity Level:
HIGH
Description:
Free Any Screen Recorder Setup
Exit code:
0
Version:
9.1.9
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\free_any_screen_recorder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2628"C:\Users\admin\AppData\Local\Temp\is-GMAA4.tmp\free_any_screen_recorder.tmp" /SL5="$501CE,5544084,1098240,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\free_any_screen_recorder.exe" /SPAWNWND=$201D8 /NOTIFYWND=$201A4 C:\Users\admin\AppData\Local\Temp\is-GMAA4.tmp\free_any_screen_recorder.tmp
free_any_screen_recorder.exe
User:
admin
Company:
Any-Screen-Recorder
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-gmaa4.tmp\free_any_screen_recorder.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2940"C:\Program Files\Free Any Screen Recorder\Any Screen Recorder.exe" C:\Program Files\Free Any Screen Recorder\Any Screen Recorder.exefree_any_screen_recorder.tmp
User:
admin
Company:
Mathew Sachin
Integrity Level:
HIGH
Description:
Captura
Exit code:
2148734720
Version:
0.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\free any screen recorder\any screen recorder.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3140"C:\Program Files\Internet Explorer\iexplore.exe" http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch&plcid=0x409&o1=.NETFramework,Version=v4.7.2&processName=Any Screen Recorder.exe&platform=0000&osver=5&isServer=0&shimver=4.0.30319.34209C:\Program Files\Internet Explorer\iexplore.exeAny Screen Recorder.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1324"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3140 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2808"C:\Program Files\Free Any Screen Recorder\Any Screen Recorder.exe" C:\Program Files\Free Any Screen Recorder\Any Screen Recorder.exeExplorer.EXE
User:
admin
Company:
Mathew Sachin
Integrity Level:
MEDIUM
Description:
Captura
Exit code:
2148734720
Version:
0.0.0.0
Modules
Images
c:\program files\free any screen recorder\any screen recorder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
20 815
Read events
20 519
Write events
288
Delete events
8

Modification events

(PID) Process:(2296) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(2296) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(2296) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30925950
(PID) Process:(2296) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
107872754
(PID) Process:(2296) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30925951
(PID) Process:(2296) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2296) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2296) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2296) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2296) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
165
Suspicious files
18
Text files
54
Unknown types
21

Dropped files

PID
Process
Filename
Type
2296iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF58E7D1E09FF08DA7.TMPgmc
MD5:5AFDF401CAF9D01E42979C07D6C2E00E
SHA256:5C18E4A0A6ED6FB11BA69488D6EFCBA9116827F16C4A5EF50CFBF00F6B797506
4044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\free_any_screen_recorder.exe.7m33383.partialexecutable
MD5:9B1A09556E47758903CA623D472D1D48
SHA256:E6D37A67398D23285C26543073E50A6DA6BAF6AE8474CA6838C7554B65BDDC2F
2296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776der
MD5:7E47DEC28AE0049A59AFF086D7E2CE5B
SHA256:2469F50E06494DF5BFFA0BC195CF15E5E243C2C2BF0B94C3FB61B327C371707C
2296iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFE69203B440AA1FC7.TMPgmc
MD5:E7643A4A5D9D7116E8FC2F1039685B63
SHA256:E932C723239141EA8D0AD013F857BF90D1A48E5B4E80435BF1108D8494097639
2296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{3BAA7B48-5072-11EC-BE1B-12A9866C77DE}.datbinary
MD5:7A115AEEF1BC354DFE9B65E50D40E150
SHA256:945568B9754C1DF0D951755D3CC88F48090EBF14CEAB232729752744E6BAE5C1
2296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_1DC6D7385EA816C957BA2B715AC5C442binary
MD5:09AE93CCAE6C6306F303961B86C729C0
SHA256:A0F3102F1FC1E9EC3F6043F6F9669622993BC8719499C3FA600E080096B914EA
4044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\free_any_screen_recorder[1].exeexecutable
MD5:B6F223DCA938CF08192F68F25C936669
SHA256:FED80781D46E112BA584CE0BF2AE247CF0A7BAD025898AAE23D350F9B0758B9F
2296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:8997F1B1E2D58C63E0D5697CCB875577
SHA256:3C89481B9C5976BF45A772C2D964FFCAF12CFF1E8141D3E179E6621EF6245438
2296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_1DC6D7385EA816C957BA2B715AC5C442der
MD5:529C1DF1B47247587D7DEB18BA933DE2
SHA256:9C335B13438F47B61C47826CBB282B4DB2E6CEAF839FAA27E9329A4D33FEE311
2296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:2C285264165B14825687A3D81D781B70
SHA256:A0070C83C17DC94D710C29D0DA2F36DE56DD6C85C1519E34A5C91CA7B62057E9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
34
DNS requests
19
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4044
iexplore.exe
GET
200
160.153.50.1:80
http://any-screen-recorder.com/download/free_any_screen_recorder.exe
US
executable
6.00 Mb
suspicious
2296
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA%2BnRyLFPYjID1ie%2Bx%2BdSjo%3D
US
der
1.47 Kb
whitelisted
1324
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
2296
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
1324
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
US
der
471 b
whitelisted
1324
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
US
der
471 b
whitelisted
1324
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEALnkXH7gCHpP%2BLZg4NMUMA%3D
US
der
471 b
whitelisted
1324
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA9bw6F2y3ieICDHiTyBZ7Q%3D
US
der
1.47 Kb
whitelisted
1324
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
2296
iexplore.exe
GET
200
8.253.207.121:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f3bf329def77ad5d
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2296
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2296
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
2296
iexplore.exe
8.241.79.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
unknown
1324
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2296
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
4044
iexplore.exe
160.153.50.1:80
any-screen-recorder.com
GoDaddy.com, LLC
US
suspicious
1324
iexplore.exe
104.92.93.19:443
go.microsoft.com
Akamai Technologies, Inc.
NL
unknown
1324
iexplore.exe
13.107.253.45:443
dotnet.microsoft.com
Microsoft Corporation
US
malicious
1324
iexplore.exe
92.123.195.35:443
img-prod-cms-rt-microsoft-com.akamaized.net
Akamai International B.V.
whitelisted
1324
iexplore.exe
92.123.195.97:443
statics-marketingsites-eus-ms-com.akamaized.net
Akamai International B.V.
suspicious

DNS requests

Domain
IP
Reputation
any-screen-recorder.com
  • 160.153.50.1
suspicious
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ctldl.windowsupdate.com
  • 8.253.207.121
  • 67.27.157.254
  • 8.253.95.249
  • 67.27.235.126
  • 8.241.79.254
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
go.microsoft.com
  • 104.92.93.19
whitelisted
dotnet.microsoft.com
  • 13.107.253.45
  • 13.107.226.45
whitelisted
www.microsoft.com
  • 2.21.143.74
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info