| URL: | https://hitfile.net/s1GtDj6?short_domain=hitf.cc |
| Full analysis: | https://app.any.run/tasks/b901adcb-7f43-4827-b442-fa40a33db545 |
| Verdict: | No threats detected |
| Analysis date: | November 22, 2020, 19:14:35 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MD5: | 91E195C02711792BA56084ADC8C8093A |
| SHA1: | 834F7E04FE4540AAAA0094FACC397E257C6FFDB5 |
| SHA256: | C8F4694C4A2596A53188F5985FC05BB424F56686797AB7A7DD4DD3B56FB7C4D6 |
| SSDEEP: | 3:N8wlabPWqZljB:2wlaXZ5B |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 2468 | "C:\Program Files\Internet Explorer\iexplore.exe" https://hitfile.net/s1GtDj6?short_domain=hitf.cc | C:\Program Files\Internet Explorer\iexplore.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) | ||||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 172.217.18.3:80 | http://ocsp.pki.goog/gts1o1core/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEFcLuT0XSrlKAgAAAACAVZE%3D | US | der | 471 b | whitelisted |
— | — | GET | 200 | 23.55.163.68:80 | http://ocsp.int-x3.letsencrypt.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBR%2B5mrncpqz%2FPiiIGRsFqEtYHEIXQQUqEpqYwR93brm0Tm3pkVl7%2FOo7KECEgOJzmp6N6FX0VfdvAWdRy38Dg%3D%3D | US | der | 527 b | whitelisted |
— | — | GET | 200 | 23.55.163.61:80 | http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D | US | der | 1.37 Kb | whitelisted |
— | — | GET | 200 | 23.55.163.77:80 | http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D | US | der | 1.37 Kb | whitelisted |
— | — | GET | 200 | 172.217.18.3:80 | http://ocsp.pki.goog/gts1o1core/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDgM%2F2Oalb9SggAAAAAYth0 | US | der | 472 b | whitelisted |
— | — | GET | 200 | 23.55.163.68:80 | http://ocsp.int-x3.letsencrypt.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBR%2B5mrncpqz%2FPiiIGRsFqEtYHEIXQQUqEpqYwR93brm0Tm3pkVl7%2FOo7KECEgOJzmp6N6FX0VfdvAWdRy38Dg%3D%3D | US | der | 527 b | whitelisted |
— | — | GET | 200 | 2.16.186.163:80 | http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso | unknown | der | 1.58 Kb | whitelisted |
— | — | GET | 200 | 2.16.186.145:80 | http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso | unknown | der | 1.58 Kb | whitelisted |
— | — | GET | 200 | 2.16.186.163:80 | http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEQDkBUeDDgxkUpdvejVJwN1I | unknown | der | 1.63 Kb | whitelisted |
— | — | GET | 200 | 5.45.205.241:80 | http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CEDa8vXdAngh37rPnjRFyHyk%3D | RU | der | 1.48 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 91.235.142.225:443 | hitfile.net | FOP Smirnov V'yacheslav Valentunovuch | UA | unknown |
— | — | 23.55.163.61:80 | isrg.trustid.ocsp.identrust.com | Akamai International B.V. | US | unknown |
— | — | 23.55.163.68:80 | ocsp.int-x3.letsencrypt.org | Akamai International B.V. | US | suspicious |
— | — | 23.55.163.77:80 | isrg.trustid.ocsp.identrust.com | Akamai International B.V. | US | unknown |
— | — | 172.217.16.196:443 | www.google.com | Google Inc. | US | whitelisted |
— | — | 172.217.23.170:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
— | — | 172.217.18.3:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
— | — | 172.217.22.46:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
— | — | 172.217.23.131:443 | www.gstatic.com | Google Inc. | US | whitelisted |
— | — | 77.88.21.119:443 | mc.yandex.ru | YANDEX LLC | RU | whitelisted |
Domain | IP | Reputation |
|---|---|---|
hitfile.net |
| whitelisted |
isrg.trustid.ocsp.identrust.com |
| whitelisted |
ocsp.int-x3.letsencrypt.org |
| whitelisted |
www.google.com |
| malicious |
fonts.googleapis.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
www.google-analytics.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
mc.yandex.ru |
| whitelisted |
counter.yadro.ru |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET DNS Query for .to TLD |