download: | index.html |
Full analysis: | https://app.any.run/tasks/d1a25cb0-150f-4246-8cc8-f5ff3aab6dc5 |
Verdict: | Malicious activity |
Analysis date: | January 10, 2019, 19:08:04 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/html |
File info: | HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators |
MD5: | 4AECFFA9C95838CF15694958C724A2C9 |
SHA1: | A9F3D32B73E7E48E6DFF4E3F2A1DA236C8407A4E |
SHA256: | BBC8A0B05BA3CD29C1B087DFCDB145E9C75AFFB995DD000E3C4A175A8F171DC1 |
SSDEEP: | 3072:4npKOkstQRWq5I8paoFia3+d9wwfLyREp+G5JMnghnVbYcd7b8UOk84:mQbP+dKwfLWEl5JMngV |
.htm/html | | | HyperText Markup Language with DOCTYPE (80.6) |
---|---|---|
.html | | | HyperText Markup Language (19.3) |
Generator: | Powered by Slider Revolution 5.1.6 - responsive, Mobile-Friendly Slider Plugin for WordPress with comfortable drag and drop interface. |
---|---|
twitterCreator: | @TRCA_TRIECA |
twitterImage: | https://trieca.com/app/uploads/2018/10/DdfIlwDU8AEEVSo.png |
twitterSite: | @TRCA_TRIECA |
twitterTitle: | TRIECA - Canada's Premier Stormwater & Erosion and Sediment Control Conference |
twitterDescription: | TRIECA is Canada’s premier stormwater and erosion and sediment control conference bringing together leading experts, influential leaders & research partners |
twitterCard: | summary |
Description: | TRIECA is Canada’s premier stormwater and erosion and sediment control conference bringing together leading experts, influential leaders & research partners |
viewport: | width=device-width, initial-scale=1.0 |
Title: | Canada's Premiere Stormwater & Erosion and Sediment Control Conference |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2700 | "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\index.html.htm | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3388 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2700 CREDAT:79873 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3012 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2700 CREDAT:137473 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
2296 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2700 CREDAT:203009 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
2448 | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe | — | svchost.exe |
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe® Flash® Player Installer/Uninstaller 26.0 r0 Version: 26,0,0,131 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2700 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
2700 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
3388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\style[1].css | html | |
MD5:04F207A3E371F4DC0112748B76E078FC | SHA256:5BA32A859EB8A79E41F34B56395BB7C21AE84EC370B972BEB2B2A8A17071E1CB | |||
3388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\swift-slider[1].css | text | |
MD5:BB1943765247DC92B0D3806ECB18939A | SHA256:5586578D0738B3841074FEA6F9AB54537ECD63A075A11DA34DC1FC8A54BFDD30 | |||
3388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\responsive[1].css | text | |
MD5:13FB5D566D1FB922D981A33A8E892000 | SHA256:581A6DDAAFEC388EC6304B1F2C874B75D13B9B3A55CFBA6B0EA1A45BC02707EB | |||
3388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\ss-gizmo[1].css | html | |
MD5:7CBC06EC83E98CAA96E18463C00FBF1E | SHA256:BCC6B81A519AD4DB0B130ADE5EB1ACA6EA91E46BB8F682BCEDE26333911CF9EC | |||
3388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\css[1].txt | text | |
MD5:5DA3E602E6ABCB086292D3B3E5039BD5 | SHA256:78E9FC94EC8733F4B5B04C655D310999DDB444798DA88D2993E198367B926C93 | |||
3388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\spb-styles[1].css | text | |
MD5:2D64AC508A46F496A1EBBE488AFC7BAB | SHA256:7A8319AB413A626C17B986D6102D38EC43BD1008E8CA7AE095CE041B487FB8B6 | |||
3388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\S6uyw4BMUTPHjx4wWg[1].eot | eot | |
MD5:6A6D715087A68AC5AD790B4F7BBB1766 | SHA256:5C795BD6B63ED3EC2FB053216FE4A8E89C2C2A90BEB7AEE8456DEB3EFF347BA5 | |||
3388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\jquery-migrate.min[1].js | text | |
MD5:7121994EEC5320FBE6586463BF9651C2 | SHA256:48EB8B500AE6A38617B5738D2B3FAEC481922A7782246E31D2755C034A45CD5D |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3388 | iexplore.exe | OPTIONS | 400 | 216.58.205.232:80 | http://www.googletagmanager.com/ | US | html | 1.52 Kb | whitelisted |
3388 | iexplore.exe | OPTIONS | 400 | 216.58.205.232:80 | http://www.googletagmanager.com/ | US | html | 1.52 Kb | whitelisted |
3388 | iexplore.exe | OPTIONS | 400 | 216.58.205.232:80 | http://www.googletagmanager.com/ | US | html | 1.52 Kb | whitelisted |
3388 | iexplore.exe | OPTIONS | 400 | 216.58.205.232:80 | http://www.googletagmanager.com/ | US | html | 1.52 Kb | whitelisted |
3388 | iexplore.exe | OPTIONS | 400 | 216.58.205.232:80 | http://www.googletagmanager.com/ | US | html | 1.52 Kb | whitelisted |
2700 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
3388 | iexplore.exe | OPTIONS | 400 | 216.58.205.232:80 | http://www.googletagmanager.com/ | US | html | 1.52 Kb | whitelisted |
3388 | iexplore.exe | OPTIONS | 400 | 216.58.205.232:80 | http://www.googletagmanager.com/ | US | html | 1.52 Kb | whitelisted |
3388 | iexplore.exe | OPTIONS | 400 | 216.58.205.232:80 | http://www.googletagmanager.com/ | US | html | 1.52 Kb | whitelisted |
3388 | iexplore.exe | OPTIONS | 400 | 216.58.205.232:80 | http://www.googletagmanager.com/ | US | html | 1.52 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3388 | iexplore.exe | 216.58.207.67:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
3388 | iexplore.exe | 172.217.22.106:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
2700 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3388 | iexplore.exe | 167.99.180.216:443 | trieca.com | — | US | unknown |
4 | System | 216.58.205.232:445 | www.googletagmanager.com | Google Inc. | US | whitelisted |
3388 | iexplore.exe | 216.58.205.232:80 | www.googletagmanager.com | Google Inc. | US | whitelisted |
4 | System | 216.58.205.232:139 | www.googletagmanager.com | Google Inc. | US | whitelisted |
2296 | iexplore.exe | 172.217.22.106:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
2296 | iexplore.exe | 216.58.207.67:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
4 | System | 216.58.210.14:445 | maps.google.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
trieca.com |
| unknown |
fonts.googleapis.com |
| whitelisted |
www.bing.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
maps.google.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
connect.facebook.net |
| whitelisted |
stats.g.doubleclick.net |
| whitelisted |
www.google.com |
| whitelisted |