URL:

https://winscp.net

Full analysis: https://app.any.run/tasks/089f7a2e-a441-4dde-8233-5cd3cabff247
Verdict: Malicious activity
Analysis date: May 16, 2023, 15:23:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

17DAD2677EB12E36D321B0596908DBD4

SHA1:

5B63971038273FC0E9D6FA393F44D7AB4C50432D

SHA256:

BAB4A736BDAF75A7961E5B45C165C8BB97AC0842057C4C9894DCE946B6FD346F

SSDEEP:

3:N8dn0:2p0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • WinSCP-5.21.8-Setup.exe (PID: 2748)
      • WinSCP-5.21.8-Setup.exe (PID: 1276)
      • WinSCP.exe (PID: 2996)
      • WinSCP.exe (PID: 332)
      • WinSCP.exe (PID: 3592)
      • WinSCP.exe (PID: 1964)
    • Registers / Runs the DLL via REGSVR32.EXE

      • WinSCP-5.21.8-Setup.tmp (PID: 3480)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinSCP-5.21.8-Setup.exe (PID: 2748)
      • WinSCP-5.21.8-Setup.exe (PID: 1276)
      • WinSCP-5.21.8-Setup.tmp (PID: 3480)
    • Reads the Windows owner or organization settings

      • WinSCP-5.21.8-Setup.tmp (PID: 3480)
    • Searches for installed software

      • WinSCP.exe (PID: 2996)
      • WinSCP.exe (PID: 332)
      • WinSCP.exe (PID: 3592)
      • WinSCP.exe (PID: 1964)
    • Reads the Internet Settings

      • WinSCP-5.21.8-Setup.tmp (PID: 3480)
  • INFO

    • Checks supported languages

      • WinSCP-5.21.8-Setup.exe (PID: 2748)
      • WinSCP-5.21.8-Setup.tmp (PID: 3312)
      • WinSCP-5.21.8-Setup.exe (PID: 1276)
      • WinSCP-5.21.8-Setup.tmp (PID: 3480)
      • WinSCP.exe (PID: 2996)
      • WinSCP.exe (PID: 332)
      • WinSCP.exe (PID: 3592)
      • WinSCP.exe (PID: 1964)
    • Application launched itself

      • iexplore.exe (PID: 3904)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 784)
      • iexplore.exe (PID: 3904)
    • Create files in a temporary directory

      • WinSCP-5.21.8-Setup.exe (PID: 2748)
      • iexplore.exe (PID: 3904)
      • iexplore.exe (PID: 784)
      • WinSCP-5.21.8-Setup.exe (PID: 1276)
      • WinSCP-5.21.8-Setup.tmp (PID: 3480)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3904)
    • Reads the computer name

      • WinSCP-5.21.8-Setup.tmp (PID: 3312)
      • WinSCP-5.21.8-Setup.tmp (PID: 3480)
      • WinSCP.exe (PID: 2996)
      • WinSCP.exe (PID: 332)
      • WinSCP.exe (PID: 3592)
      • WinSCP.exe (PID: 1964)
    • Application was dropped or rewritten from another process

      • WinSCP-5.21.8-Setup.tmp (PID: 3312)
      • WinSCP-5.21.8-Setup.tmp (PID: 3480)
    • The process checks LSA protection

      • WinSCP-5.21.8-Setup.tmp (PID: 3312)
      • WinSCP-5.21.8-Setup.tmp (PID: 3480)
      • WinSCP.exe (PID: 2996)
      • WinSCP.exe (PID: 332)
      • WinSCP.exe (PID: 3592)
      • WinSCP.exe (PID: 1964)
    • Creates files or folders in the user directory

      • WinSCP-5.21.8-Setup.tmp (PID: 3480)
      • WinSCP.exe (PID: 2996)
      • WinSCP.exe (PID: 3592)
      • WinSCP.exe (PID: 332)
      • WinSCP.exe (PID: 1964)
    • Creates files in the program directory

      • WinSCP-5.21.8-Setup.tmp (PID: 3480)
    • Reads product name

      • WinSCP.exe (PID: 2996)
      • WinSCP.exe (PID: 332)
      • WinSCP.exe (PID: 3592)
      • WinSCP.exe (PID: 1964)
    • Reads the machine GUID from the registry

      • WinSCP.exe (PID: 2996)
      • WinSCP.exe (PID: 332)
      • WinSCP.exe (PID: 3592)
      • WinSCP.exe (PID: 1964)
    • Process checks Powershell version

      • WinSCP.exe (PID: 2996)
      • WinSCP.exe (PID: 332)
      • WinSCP.exe (PID: 3592)
      • WinSCP.exe (PID: 1964)
    • Reads Environment values

      • WinSCP.exe (PID: 2996)
      • WinSCP.exe (PID: 332)
      • WinSCP.exe (PID: 3592)
      • WinSCP.exe (PID: 1964)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
12
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe winscp-5.21.8-setup.exe winscp-5.21.8-setup.tmp no specs winscp-5.21.8-setup.exe winscp-5.21.8-setup.tmp regsvr32.exe no specs winscp.exe no specs winscp.exe no specs winscp.exe no specs winscp.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
332"C:\Program Files\WinSCP\WinSCP.exe" /ImportSitesIfAnyC:\Program Files\WinSCP\WinSCP.exeWinSCP-5.21.8-Setup.tmp
User:
admin
Company:
Martin Prikryl
Integrity Level:
HIGH
Description:
WinSCP: SFTP, FTP, WebDAV, S3 and SCP client
Exit code:
0
Version:
5.21.8.13000
Modules
Images
c:\program files\winscp\winscp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\crypt32.dll
784"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3904 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
1276"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\WinSCP-5.21.8-Setup.exe" /SPAWNWND=$20214 /NOTIFYWND=$601CE /ALLUSERSC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\WinSCP-5.21.8-Setup.exe
WinSCP-5.21.8-Setup.tmp
User:
admin
Company:
Martin Prikryl
Integrity Level:
HIGH
Description:
Setup for WinSCP 5.21.8 (SFTP, FTP, WebDAV and SCP client)
Exit code:
0
Version:
5.21.8
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\winscp-5.21.8-setup.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1964"C:\Program Files\WinSCP\WinSCP.exe"C:\Program Files\WinSCP\WinSCP.exeWinSCP-5.21.8-Setup.tmp
User:
admin
Company:
Martin Prikryl
Integrity Level:
MEDIUM
Description:
WinSCP: SFTP, FTP, WebDAV, S3 and SCP client
Exit code:
0
Version:
5.21.8.13000
Modules
Images
c:\program files\winscp\winscp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\secur32.dll
c:\windows\system32\msasn1.dll
2748"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\WinSCP-5.21.8-Setup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\WinSCP-5.21.8-Setup.exe
iexplore.exe
User:
admin
Company:
Martin Prikryl
Integrity Level:
MEDIUM
Description:
Setup for WinSCP 5.21.8 (SFTP, FTP, WebDAV and SCP client)
Exit code:
0
Version:
5.21.8
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\winscp-5.21.8-setup.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
2996"C:\Program Files\WinSCP\WinSCP.exe" /RegisterForDefaultProtocolsC:\Program Files\WinSCP\WinSCP.exeWinSCP-5.21.8-Setup.tmp
User:
admin
Company:
Martin Prikryl
Integrity Level:
HIGH
Description:
WinSCP: SFTP, FTP, WebDAV, S3 and SCP client
Exit code:
0
Version:
5.21.8.13000
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winscp\winscp.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
3124"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3904 CREDAT:3347738 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iertutil.dll
3200"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\WinSCP\DragExt.dll"C:\Windows\System32\regsvr32.exeWinSCP-5.21.8-Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3312"C:\Users\admin\AppData\Local\Temp\is-AD1B3.tmp\WinSCP-5.21.8-Setup.tmp" /SL5="$601CE,10350331,864768,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\WinSCP-5.21.8-Setup.exe" C:\Users\admin\AppData\Local\Temp\is-AD1B3.tmp\WinSCP-5.21.8-Setup.tmpWinSCP-5.21.8-Setup.exe
User:
admin
Company:
Martin Prikryl
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-ad1b3.tmp\winscp-5.21.8-setup.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3480"C:\Users\admin\AppData\Local\Temp\is-QIIVG.tmp\WinSCP-5.21.8-Setup.tmp" /SL5="$30210,10350331,864768,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\WinSCP-5.21.8-Setup.exe" /SPAWNWND=$20214 /NOTIFYWND=$601CE /ALLUSERSC:\Users\admin\AppData\Local\Temp\is-QIIVG.tmp\WinSCP-5.21.8-Setup.tmp
WinSCP-5.21.8-Setup.exe
User:
admin
Company:
Martin Prikryl
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-qiivg.tmp\winscp-5.21.8-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
39 612
Read events
38 811
Write events
713
Delete events
88

Modification events

(PID) Process:(3904) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3904) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3904) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3904) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3904) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3904) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3904) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3904) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3904) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3904) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
96
Suspicious files
109
Text files
214
Unknown types
4

Dropped files

PID
Process
Filename
Type
784iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_23FFFDCAABB8E63694AD1202ED02BF57binary
MD5:5A9E6BDD04C59358269796976A4C8339
SHA256:D8DAAECC351B1F49610DFC53F1586F04781B315FCE174D8AACB325A79C7C1135
784iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14561BF7422BB6F70A9CB14F5AA8A7DA_12C1F7D538D0C040D9E2C14261CCE53Abinary
MD5:AC38FC9F6542D3B05CF856E3986F0B22
SHA256:821DE762ED8598873E4994E467BE47F14EE93F8A95C4E3407B840F7453AE5192
784iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_23FFFDCAABB8E63694AD1202ED02BF57binary
MD5:2F64C3682C1BAAC6093FDE4FD004C7BF
SHA256:A5636133BBA7A40F4E54EFBB275A887C5B830BCA625FE6E44C8E88245551DD9E
784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\search[1].pngimage
MD5:02239BA51D942F95068EAE32DAE325EA
SHA256:13496B3E35B13DAE5A14976CA30D669080C01C75D121A61D86F06F64880BB494
784iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14561BF7422BB6F70A9CB14F5AA8A7DA_12C1F7D538D0C040D9E2C14261CCE53Abinary
MD5:45E21F2705C996A27D2F3E21013EA4B5
SHA256:2DFF35173F8784B2E55DDB7FF4830AAB446173BDF8F663D5CE20D1A3C01F2DFE
784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\index[1].htmhtml
MD5:49245CBF2B34A73A439C3E190EE345C4
SHA256:DB713FD6D1F1112A1C1578D64680A44B0D648CCF459936FC04E4038AED445F5F
784iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
784iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:C620B2BCB1ABECF146CB42A2B3391262
SHA256:18B1D9CA1DA2F3B261DBF6A13063A34DA9DD03A72FD849ACF13022331B960A76
784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\widgets[1].jstext
MD5:9E99725B7A4CD730A934AFBA2A438BB5
SHA256:392C9FA9CD1273A2A89D1A83A69CD1F63F21D1D55E7BE21E1D8F51F25145668B
784iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D0E1C4B6144E7ECAB3F020E4A19EFC29_B5F77004C894173A10E3A199871D2D90binary
MD5:402FA7FD623EBD09375CB64C4B9FCD90
SHA256:10E876550EE666934EDE7248513E5B961441201B5E6DE7223FC6E9E343ABD1B6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
40
TCP/UDP connections
212
DNS requests
56
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
784
iexplore.exe
GET
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ff857a48f4d7edd1
US
whitelisted
784
iexplore.exe
GET
172.64.155.188:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd
US
whitelisted
784
iexplore.exe
GET
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?99edbf4e41fa2b7e
US
whitelisted
784
iexplore.exe
GET
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?af46f82c3c4971a7
US
whitelisted
784
iexplore.exe
GET
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e59738a84e2a182d
US
whitelisted
784
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQlOydjtpho0%2Bholo77zGjGxETUEQQU8JyF%2FaKffY%2FJaLvV1IlNHb7TkP8CEAP%2F67tZSZpNKmuaXW96vcU%3D
US
der
727 b
whitelisted
784
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?de07c9e7420c5a1c
US
compressed
4.70 Kb
whitelisted
784
iexplore.exe
GET
200
104.18.32.68:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D
US
binary
1.42 Kb
whitelisted
3904
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
784
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAoFmyX1Sz2HlMxmMUd1OKM%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
784
iexplore.exe
142.250.184.194:443
pagead2.googlesyndication.com
GOOGLE
US
suspicious
784
iexplore.exe
142.250.185.67:80
ocsp.pki.goog
GOOGLE
US
whitelisted
784
iexplore.exe
172.64.155.188:80
ocsp.comodoca.com
CLOUDFLARENET
US
suspicious
784
iexplore.exe
192.0.73.2:443
www.gravatar.com
AUTOMATTIC
US
whitelisted
784
iexplore.exe
23.201.254.55:80
x1.c.lencr.org
AKAMAI-AS
CH
unknown
784
iexplore.exe
2.16.241.15:80
r3.o.lencr.org
Akamai International B.V.
DE
suspicious
3904
iexplore.exe
2.23.209.185:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4
System
192.168.100.255:137
whitelisted
3372
svchost.exe
239.255.255.250:1900
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown

DNS requests

Domain
IP
Reputation
winscp.net
  • 88.198.21.111
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
winscp-static-746341.c.cdn77.org
  • 156.146.33.138
  • 195.181.175.15
  • 156.146.33.141
  • 195.181.175.40
  • 195.181.170.18
  • 195.181.170.19
  • 156.146.33.137
suspicious
www.googletagmanager.com
  • 172.217.16.136
whitelisted
platform.twitter.com
  • 146.75.116.157
whitelisted
pagead2.googlesyndication.com
  • 142.250.184.194
whitelisted
www.gravatar.com
  • 192.0.73.2
whitelisted
ocsp.comodoca.com
  • 104.18.32.68
  • 172.64.155.188
whitelisted
ocsp.pki.goog
  • 142.250.185.67
whitelisted

Threats

PID
Process
Class
Message
3480
WinSCP-5.21.8-Setup.tmp
Potentially Bad Traffic
ET INFO TLS Handshake Failure
No debug info