| URL: | https://d2punpeg7vtjci.cloudfront.net/public/dynamo/lockerClick.php?offer=53283670&offer_position=1&it=3549396&m=0&visitor_id=Vdb0d0edbe9dd3&cpguid=dcmobrn6p&hash=fc14e13a40fe9b52e06b8834aa22d1f6 |
| Full analysis: | https://app.any.run/tasks/3c07b18a-65b7-438b-94dc-a80333ec6165 |
| Verdict: | Malicious activity |
| Analysis date: | April 12, 2023, 09:28:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 8BC738F16586C32E633F2248A350ED14 |
| SHA1: | D2F903DFD9B2BBD396020DE5450069FD7C90D06B |
| SHA256: | BF36FF86E2AC1DA508AB18BD9DE736375D97538F5D5DEC473DF2BFE982C998D0 |
| SSDEEP: | 3:N8PVe5U+MVl/0/HJ7rvXzFNUvDGxWEc3UY9MlKX6AeuAcAQAnVDCDm2t5HfWlGn:2tfzM/HRXGqriUY9vBu/VrAWlG |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 908 | "C:\Program Files\Internet Explorer\iexplore.exe" "https://d2punpeg7vtjci.cloudfront.net/public/dynamo/lockerClick.php?offer=53283670&offer_position=1&it=3549396&m=0&visitor_id=Vdb0d0edbe9dd3&cpguid=dcmobrn6p&hash=fc14e13a40fe9b52e06b8834aa22d1f6" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 1188 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=97.0.4719.63 --initial-client-data=0x16c,0x170,0x174,0x140,0x178,0x6a5933e0,0x6a5933f0,0x6a5933fc | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe | OperaSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Installer Exit code: 0 Version: 97.0.4719.63 Modules
| |||||||||||||||
| 1804 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe" --backend --initial-pid=3740 --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --launchopera=0 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20230412103012" --session-guid=86d23dbc-4629-4cb5-ad90-1f24d3137c6b --server-tracking-blob=NTFjYzQ2Njc2ODhlNzIwMzI0Mjg3NzY2MzlkZDFmMzIyMmM4OTA3NjFjNTlhZGIyNzkzYThmZWY3MzYxZDdjNjp7ImNvdW50cnkiOiJHQiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vbGVnYWN5LXRoYW5rcz9uaT1zdGFibGUmb3M9d2luZG93cyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cz91dG1fdHJ5YWdhaW49eWVzIiwic3lzdGVtIjp7InBsYXRmb3JtIjp7ImFyY2giOiJ4ODYiLCJvcHN5cyI6IldpbmRvd3MiLCJvcHN5cy12ZXJzaW9uIjoiNyIsInBhY2thZ2UiOiJFWEUifX0sInRpbWVzdGFtcCI6IjE2ODEyOTE4MDkuMTM2MiIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDYuMTsgVHJpZGVudC83LjA7IHJ2OjExLjApIGxpa2UgR2Vja28iLCJ1dG0iOnsidHJ5YWdhaW4iOiJ5ZXMifSwidXVpZCI6IjFkY2NjMGYwLWM0ZTgtNDc4OC05Nzg1LTg3NzAyMmM3YzkzMSJ9 --desktopshortcut=1 --parent-pid=3156 --wait-for-package --run-elevated | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe | OperaSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: HIGH Description: Opera Installer Exit code: 0 Version: 97.0.4719.63 Modules
| |||||||||||||||
| 1908 | "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\OperaSetup.exe" --version | C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\OperaSetup.exe | OperaSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Installer Exit code: 0 Version: 97.0.4719.63 Modules
| |||||||||||||||
| 2072 | "C:\Program Files\Opera\95.0.4635.80\installer.exe" --backend --initial-pid=3740 --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --launchopera=0 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --package-dir="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202304121030121" --session-guid=86d23dbc-4629-4cb5-ad90-1f24d3137c6b --server-tracking-blob=NTFjYzQ2Njc2ODhlNzIwMzI0Mjg3NzY2MzlkZDFmMzIyMmM4OTA3NjFjNTlhZGIyNzkzYThmZWY3MzYxZDdjNjp7ImNvdW50cnkiOiJHQiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vbGVnYWN5LXRoYW5rcz9uaT1zdGFibGUmb3M9d2luZG93cyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cz91dG1fdHJ5YWdhaW49eWVzIiwic3lzdGVtIjp7InBsYXRmb3JtIjp7ImFyY2giOiJ4ODYiLCJvcHN5cyI6IldpbmRvd3MiLCJvcHN5cy12ZXJzaW9uIjoiNyIsInBhY2thZ2UiOiJFWEUifX0sInRpbWVzdGFtcCI6IjE2ODEyOTE4MDkuMTM2MiIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDYuMTsgVHJpZGVudC83LjA7IHJ2OjExLjApIGxpa2UgR2Vja28iLCJ1dG0iOnsidHJ5YWdhaW4iOiJ5ZXMifSwidXVpZCI6IjFkY2NjMGYwLWM0ZTgtNDc4OC05Nzg1LTg3NzAyMmM3YzkzMSJ9 --desktopshortcut=1 --install-subfolder=95.0.4635.80 --parent-pid=3156 | C:\Program Files\Opera\95.0.4635.80\installer.exe | OperaSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: HIGH Description: Opera Installer Exit code: 0 Version: 95.0.4635.80 Modules
| |||||||||||||||
| 2520 | "C:\Program Files\Opera\launcher.exe" --new-tab | C:\Program Files\Opera\launcher.exe | — | installer.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Exit code: 0 Version: 95.0.4635.80 Modules
| |||||||||||||||
| 2580 | "C:\Program Files\Opera\95.0.4635.80\installer.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=95.0.4635.80 --initial-client-data=0x16c,0x170,0x174,0x140,0x178,0x679fe428,0x679fe438,0x679fe444 | C:\Program Files\Opera\95.0.4635.80\installer.exe | installer.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: HIGH Description: Opera Installer Exit code: 0 Version: 95.0.4635.80 Modules
| |||||||||||||||
| 2784 | "C:\Program Files\Opera\opera.exe" | C:\Program Files\Opera\opera.exe | explorer.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Exit code: 0 Version: 1748 Modules
| |||||||||||||||
| 2960 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=97.0.4719.63 --initial-client-data=0x16c,0x170,0x174,0x140,0x178,0x692d33e0,0x692d33f0,0x692d33fc | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe | OperaSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: HIGH Description: Opera Installer Exit code: 0 Version: 97.0.4719.63 Modules
| |||||||||||||||
| 3156 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --launchopera=1 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --initial-pid=3740 --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20230412103012" --session-guid=86d23dbc-4629-4cb5-ad90-1f24d3137c6b --server-tracking-blob=NTFjYzQ2Njc2ODhlNzIwMzI0Mjg3NzY2MzlkZDFmMzIyMmM4OTA3NjFjNTlhZGIyNzkzYThmZWY3MzYxZDdjNjp7ImNvdW50cnkiOiJHQiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vbGVnYWN5LXRoYW5rcz9uaT1zdGFibGUmb3M9d2luZG93cyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cz91dG1fdHJ5YWdhaW49eWVzIiwic3lzdGVtIjp7InBsYXRmb3JtIjp7ImFyY2giOiJ4ODYiLCJvcHN5cyI6IldpbmRvd3MiLCJvcHN5cy12ZXJzaW9uIjoiNyIsInBhY2thZ2UiOiJFWEUifX0sInRpbWVzdGFtcCI6IjE2ODEyOTE4MDkuMTM2MiIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDYuMTsgVHJpZGVudC83LjA7IHJ2OjExLjApIGxpa2UgR2Vja28iLCJ1dG0iOnsidHJ5YWdhaW4iOiJ5ZXMifSwidXVpZCI6IjFkY2NjMGYwLWM0ZTgtNDc4OC05Nzg1LTg3NzAyMmM3YzkzMSJ9 --desktopshortcut=1 --wait-for-package --initial-proc-handle=5406000000000000 | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe | OperaSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Installer Exit code: 0 Version: 97.0.4719.63 Modules
| |||||||||||||||
| (PID) Process: | (908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (908) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3284 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:— | SHA256:— | |||
| 3284 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62 | binary | |
MD5:— | SHA256:— | |||
| 3284 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\lockerClick[1].htm | html | |
MD5:— | SHA256:— | |||
| 3284 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\IL7IQBWQ.txt | text | |
MD5:— | SHA256:— | |||
| 3284 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 | binary | |
MD5:— | SHA256:— | |||
| 3284 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8 | binary | |
MD5:— | SHA256:— | |||
| 3284 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\30D802E0E248FEE17AAF4A62594CC75A | binary | |
MD5:— | SHA256:— | |||
| 3284 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850D | binary | |
MD5:— | SHA256:— | |||
| 3284 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 | der | |
MD5:7CECA430A42A7B562296E777850D9A59 | SHA256:69136A40F067B783DE49C6E27E1C30C12CA37A5F28D23495812934884605723A | |||
| 3284 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8 | der | |
MD5:D5125FF59BB40D49F4DEC8F736ECE33D | SHA256:B87741F7C1B28BB0225727D1E5E3FEC012BA22D4F659F6127E8A12CCA67A5963 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3284 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQrHR6YzPN2BNbByL0VoiTIBBMAOAQUCrwIKReMpTlteg7OM8cus%2B37w3oCEA0WcKqJz0qvV5nHApP7qas%3D | US | der | 314 b | whitelisted |
3284 | iexplore.exe | GET | 200 | 172.64.155.188:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEA9uAUFDljLnD1CR8PbHMzc%3D | US | der | 471 b | whitelisted |
3284 | iexplore.exe | GET | 200 | 13.32.47.54:80 | http://crl.r2m01.amazontrust.com/r2m01.crl | US | binary | 154 Kb | suspicious |
3284 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | US | der | 471 b | whitelisted |
3284 | iexplore.exe | GET | 200 | 104.18.32.68:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | US | der | 2.18 Kb | whitelisted |
3284 | iexplore.exe | GET | 200 | 108.138.2.173:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | US | der | 1.70 Kb | whitelisted |
3284 | iexplore.exe | GET | 200 | 52.222.250.42:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
3284 | iexplore.exe | GET | 200 | 8.248.131.254:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8cb10c1ba2d5906b | US | compressed | 4.70 Kb | whitelisted |
908 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D | US | der | 1.47 Kb | whitelisted |
3284 | iexplore.exe | GET | 200 | 91.199.212.52:80 | http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt | GB | der | 1.52 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
908 | iexplore.exe | 108.138.24.197:443 | d2punpeg7vtjci.cloudfront.net | AMAZON-02 | US | unknown |
3284 | iexplore.exe | 34.91.234.242:443 | blue.redredirector.com | GOOGLE-CLOUD-PLATFORM | NL | unknown |
3284 | iexplore.exe | 91.199.212.52:80 | crt.sectigo.com | Sectigo Limited | GB | suspicious |
3284 | iexplore.exe | 104.18.32.68:80 | ocsp.usertrust.com | CLOUDFLARENET | — | suspicious |
3284 | iexplore.exe | 172.64.155.188:80 | ocsp.usertrust.com | CLOUDFLARENET | US | suspicious |
3284 | iexplore.exe | 52.70.250.63:443 | www.getgx.net | AMAZON-AES | US | unknown |
908 | iexplore.exe | 34.91.234.242:443 | blue.redredirector.com | GOOGLE-CLOUD-PLATFORM | NL | unknown |
3284 | iexplore.exe | 52.222.226.205:80 | ocsp.r2m01.amazontrust.com | AMAZON-02 | US | unknown |
908 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
908 | iexplore.exe | 2.23.209.185:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
Domain | IP | Reputation |
|---|---|---|
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
blue.redredirector.com |
| unknown |
crt.sectigo.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2784 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2784 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2784 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2784 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2784 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2784 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2784 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2784 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2784 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2784 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
Process | Message |
|---|---|
assistant_installer.exe | [0412/103204.217:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202304121030121\assistant\assistant_installer.exe" --version
|
assistant_installer.exe | [0412/103204.217:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202304121030121\assistant\assistant_installer.exe" --version
|