URL:

https://trace.mediago.io/ju/ic?tn=9220dd482c2a49631b4e66cca9f5f0ee&trackingid=8d0bdf6639b0c1fe239163528c2d5203&acid=25618&data=sGcqtl4Lwm5RBRJdPwlcTraX3GMOSViV1JftKFO3tCs2tjiLaPnMID9fjEQM8LDBiYzC_tDMw9o7LhTpcuuvGtq6WdI9HvQf7pzoiEPr1lKO5YMyWj7fSDrmilViYnH0k-ljMvvl0imuw676Kaukb7jZyCYnSAkgeWXWdL0U6VuuzRUKVQ-cmqiv7Jw7pI8vkUuWTb29VHoVguy3VbIERwpeR4I55fw2JULDXakYuR_Zds5HLrSCxuZ8v2R7vuj93pMaJK9Kd332u-a1dBMXVYO9tHe92Da-2O1blkOKuiUjcY40EHSDT80eZKxeVUjIvSVRDX_UNHP4E9eeSGNIeVsVtlL5dLLoNkdLI-ilIxwhxIZAoqyGm7XUGpIz1bcJUJpVq2_86e-pGiikANgWDYi5ANwjkUFu1Sgg8NFoerH4F0wAfSEcFjdsL6GVb9iV9Jp7Blm63otEINvQQFvc43jXi2EYxCu4n2fI31iyqvkwkaZQJgonK4v_SkSMXVIc2wL5XcU8pbTTewTmGIoS4uYZNeeWTkYDZlgoIw9t-LtyBDK3m6U_p8W58pgSB17AXrJQjDKgy8zJTGOk1uWjmCfDlTIFWF-21yGpNf1v9ltH3HAyrXTk-yNmrJjodqFtnlNWk91q_q30p0Pe1zxOrKGYD6C1QDoGVi5vqjSRYWooui_3ZzOqMqU2lxGTleF-j79VUc27fAMzKmqUYR5lyL58_zh2i7iwpHhhtihsrllv-UUFd5XajGZNLQhzBRJolzYvzO3k3nm1ys--YQDsdGfWTNxq3jYwNPafuwaXB5eCqixOPWIdKv8ESAIWLS3dD3FtAMl7ittFkA-lteBie77XmSeM0zW7-c8IsIM4i6oYA7VbFrtpnIs6EwhGseDATQ9T2ea5O1oTODaF9TIkoBbC71158U-_waIo6QodWxxhVsvscmp06VzIdxbTh7k6Dl5XHBa_0bSBCdXdEB2CFAfxXuBhG68Xy90lbaYQpOjayEmTBFpxjkVlzRxB5raSyH5mVtAhfoX_FUIU5z6wFd6KkAYnQpMx8ewBSODfeCQcvwX_ZE9OklTYp1FqdpLzhuMgKMalT5u97NXs6Zy_jCIQVfH49z5nHysVKWsj740AAFcDxw6BcWS-REE4zE-UaeNFuhL7__7_m8EZv9ip0y5PFsySImu5v48WzXJIifIaiZbabCMhV0jzVHehEVoAwu1QVfDlNd_BpGkoV4AOOSgw3QD61ePbS0gMF_wEv9RiFHNb3JPJdhZbyzVuJxp4Rq4aEVJcSaOgH686piPfU9XTrbYVY3SarS_DlPdof0JV5Mk-3ECiRq8B6WLgTgDERmKGp84LIQfvt9_l9yEnyT4lRlBoLcdNcNBXNlDHxyFc3wC7PUQqKNh1RrLgaubf7SJW0wFpySRVODurgwKiYw0DoOaWcvJG2zbEYVw8FUg6Y-SZSU1CjokrZ4iRBgc1HatEVT7UsM2pOICELyxDnZrwlAeqXAfMRiqK2smnbVXzQVW5yBOVGGu4Jo_YjgzBjbcbpBbes4_WkGzVD6E8LZ27krHrOEk6hcjJmwaqeVeIlSCC92YNLgrYxOrSE5_hj2R09I3D74cumGEHWGQRfkhcN9gwtQfYKtrBNQ9DLWI0wsVBoO2UQQnJ0i-ZATob8S6fcnt4TbiPWshXycFloZ9CRG2WpjT9TFB8H-QoKtEd2NyEyWgzM4YIXr8AJMmZt1eE9u8Fh20b_LJbyoJnEkLociI-sXos-oiIumyiaJzUPwxuS0vf44e1DXwZ4m7l&uid=13171FBEFD5265E00D040E11FCC064C0&mguid=&ap={AUCTION_PRICE}&tid={tid}&gprice=172oJKHMDXH2tkqRYQQVV7zY7GUhamTjNi_czrEDIbA&campaignid=2057207

Full analysis: https://app.any.run/tasks/693d8ea5-3e15-4b92-bdc2-118a8a4b1d39
Verdict: Malicious activity
Analysis date: October 30, 2023, 18:38:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
SHA1:

9BECD69DEFAC84B44C80609938CC6D2C62348E85

SHA256:

D7E3D75D46EBF8937CB44D4313E3D0793E5BD942CF8EF3E447A7272E5722D242

SSDEEP:

48:ctcNn6veZTijQNhIzCfOX9/M/GBNu8k91yD+zia3Av2aHTJe:AcNnV2HzCmN/MGXS1yD+zia30LJe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1884)
      • chrome.exe (PID: 2812)
    • Manual execution by a user

      • chrome.exe (PID: 2812)
    • The process uses the downloaded file

      • chrome.exe (PID: 460)
      • chrome.exe (PID: 3644)
      • chrome.exe (PID: 3160)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
151
Monitored processes
115
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
148"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=45 --mojo-platform-channel-handle=6432 --field-trial-handle=1188,i,13056511863896548505,4803973141867828592,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
396"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=30 --mojo-platform-channel-handle=5124 --field-trial-handle=1188,i,13056511863896548505,4803973141867828592,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
460"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4148 --field-trial-handle=1188,i,13056511863896548505,4803973141867828592,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shell32.dll
668"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2116 --field-trial-handle=1188,i,13056511863896548505,4803973141867828592,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\sechost.dll
916"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=38 --mojo-platform-channel-handle=5956 --field-trial-handle=1188,i,13056511863896548505,4803973141867828592,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1280"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=2288 --field-trial-handle=1188,i,13056511863896548505,4803973141867828592,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\chrome.exe
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cryptbase.dll
1536"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1884 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1864"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=80 --mojo-platform-channel-handle=7600 --field-trial-handle=1188,i,13056511863896548505,4803973141867828592,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1880"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --mojo-platform-channel-handle=2796 --field-trial-handle=1188,i,13056511863896548505,4803973141867828592,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1884"C:\Program Files\Internet Explorer\iexplore.exe" "https://trace.mediago.io/ju/ic?tn=9220dd482c2a49631b4e66cca9f5f0ee&trackingid=8d0bdf6639b0c1fe239163528c2d5203&acid=25618&data=sGcqtl4Lwm5RBRJdPwlcTraX3GMOSViV1JftKFO3tCs2tjiLaPnMID9fjEQM8LDBiYzC_tDMw9o7LhTpcuuvGtq6WdI9HvQf7pzoiEPr1lKO5YMyWj7fSDrmilViYnH0k-ljMvvl0imuw676Kaukb7jZyCYnSAkgeWXWdL0U6VuuzRUKVQ-cmqiv7Jw7pI8vkUuWTb29VHoVguy3VbIERwpeR4I55fw2JULDXakYuR_Zds5HLrSCxuZ8v2R7vuj93pMaJK9Kd332u-a1dBMXVYO9tHe92Da-2O1blkOKuiUjcY40EHSDT80eZKxeVUjIvSVRDX_UNHP4E9eeSGNIeVsVtlL5dLLoNkdLI-ilIxwhxIZAoqyGm7XUGpIz1bcJUJpVq2_86e-pGiikANgWDYi5ANwjkUFu1Sgg8NFoerH4F0wAfSEcFjdsL6GVb9iV9Jp7Blm63otEINvQQFvc43jXi2EYxCu4n2fI31iyqvkwkaZQJgonK4v_SkSMXVIc2wL5XcU8pbTTewTmGIoS4uYZNeeWTkYDZlgoIw9t-LtyBDK3m6U_p8W58pgSB17AXrJQjDKgy8zJTGOk1uWjmCfDlTIFWF-21yGpNf1v9ltH3HAyrXTk-yNmrJjodqFtnlNWk91q_q30p0Pe1zxOrKGYD6C1QDoGVi5vqjSRYWooui_3ZzOqMqU2lxGTleF-j79VUc27fAMzKmqUYR5lyL58_zh2i7iwpHhhtihsrllv-UUFd5XajGZNLQhzBRJolzYvzO3k3nm1ys--YQDsdGfWTNxq3jYwNPafuwaXB5eCqixOPWIdKv8ESAIWLS3dD3FtAMl7ittFkA-lteBie77XmSeM0zW7-c8IsIM4i6oYA7VbFrtpnIs6EwhGseDATQ9T2ea5O1oTODaF9TIkoBbC71158U-_waIo6QodWxxhVsvscmp06VzIdxbTh7k6Dl5XHBa_0bSBCdXdEB2CFAfxXuBhG68Xy90lbaYQpOjayEmTBFpxjkVlzRxB5raSyH5mVtAhfoX_FUIU5z6wFd6KkAYnQpMx8ewBSODfeCQcvwX_ZE9OklTYp1FqdpLzhuMgKMalT5u97NXs6Zy_jCIQVfH49z5nHysVKWsj740AAFcDxw6BcWS-REE4zE-UaeNFuhL7__7_m8EZv9ip0y5PFsySImu5v48WzXJIifIaiZbabCMhV0jzVHehEVoAwu1QVfDlNd_BpGkoV4AOOSgw3QD61ePbS0gMF_wEv9RiFHNb3JPJdhZbyzVuJxp4Rq4aEVJcSaOgH686piPfU9XTrbYVY3SarS_DlPdof0JV5Mk-3ECiRq8B6WLgTgDERmKGp84LIQfvt9_l9yEnyT4lRlBoLcdNcNBXNlDHxyFc3wC7PUQqKNh1RrLgaubf7SJW0wFpySRVODurgwKiYw0DoOaWcvJG2zbEYVw8FUg6Y-SZSU1CjokrZ4iRBgc1HatEVT7UsM2pOICELyxDnZrwlAeqXAfMRiqK2smnbVXzQVW5yBOVGGu4Jo_YjgzBjbcbpBbes4_WkGzVD6E8LZ27krHrOEk6hcjJmwaqeVeIlSCC92YNLgrYxOrSE5_hj2R09I3D74cumGEHWGQRfkhcN9gwtQfYKtrBNQ9DLWI0wsVBoO2UQQnJ0i-ZATob8S6fcnt4TbiPWshXycFloZ9CRG2WpjT9TFB8H-QoKtEd2NyEyWgzM4YIXr8AJMmZt1eE9u8Fh20b_LJbyoJnEkLociI-sXos-oiIumyiaJzUPwxuS0vf44e1DXwZ4m7l&uid=13171FBEFD5265E00D040E11FCC064C0&mguid=&ap={AUCTION_PRICE}&tid={tid}&gprice=172oJKHMDXH2tkqRYQQVV7zY7GUhamTjNi_czrEDIbA&campaignid=2057207"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
17 159
Read events
16 892
Write events
263
Delete events
4

Modification events

(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
12
Suspicious files
759
Text files
58
Unknown types
5

Dropped files

PID
Process
Filename
Type
1884iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:C2C4DE4B0E810BD4606CEEE2555FE249
SHA256:
1536iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_005284E085E122BD76B51F33745F7753binary
MD5:0FF58E5B43C61599F7DE3ACD5394239B
SHA256:DC2822D30094A2402C000241D9A5E73BDCF535541CE25B7C20665AB5FC9899D7
1884iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
1884iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
2812chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF1ed9c4.TMP
MD5:
SHA256:
2812chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
1884iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
1884iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118Abinary
MD5:568E6BE9C6D190D09598014AD2E7EFDF
SHA256:B0C3A8BCED0E747F17C7A7EE53A1B4C9D79EB82E554EC508BE2793BBA359AAC9
1884iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
1536iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DD76941B08ECB69B450D4C1AE579DB94_16201E6A9A0A0A0384E81CD3F1BB9F68der
MD5:E4B050283C11E5BC6CF9CAAFF34149B7
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
696
DNS requests
791
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
864
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3
unknown
1884
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d4c74188198c1b4a
unknown
compressed
4.66 Kb
1536
iexplore.exe
GET
200
151.101.2.133:80
http://ocsp2.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHe9DgdC1dnp0EnXdNAqb5o%3D
unknown
der
1.40 Kb
1536
iexplore.exe
GET
200
151.101.2.133:80
http://ocsp.globalsign.com/gsgccr3dvtlsca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQoKOHJRQbCE%2B3DXqwFiztBxLYdhwQUDZjAc3%2Brvb3ZR0tJrQpKDKw%2Bx3wCDH%2BK%2FPaAF%2BBmlRfKiw%3D%3D
unknown
der
1.38 Kb
1884
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
der
313 b
1884
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5e95d261bb46542b
unknown
compressed
4.66 Kb
864
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/AJqZYiqGvCtix64S2N84g-M_2020.11.2.164946/EWvH2e-LS80S29cxzuTfRA
unknown
binary
10.6 Kb
864
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/AJqZYiqGvCtix64S2N84g-M_2020.11.2.164946/EWvH2e-LS80S29cxzuTfRA
unknown
binary
17.6 Kb
864
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3
unknown
binary
8.24 Kb
864
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3
unknown
binary
5.74 Kb
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
239.255.255.250:1900
unknown
1884
iexplore.exe
104.126.37.186:443
www.bing.com
Akamai International B.V.
DE
unknown
1884
iexplore.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
unknown
1884
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
1536
iexplore.exe
151.101.2.133:80
ocsp2.globalsign.com
FASTLY
US
unknown
2812
chrome.exe
239.255.255.250:1900
unknown
4032
chrome.exe
142.250.186.99:443
clientservices.googleapis.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
api.bing.com
  • 13.107.5.80
unknown
www.bing.com
  • 104.126.37.186
  • 104.126.37.163
  • 104.126.37.170
  • 104.126.37.161
  • 104.126.37.154
  • 104.126.37.178
  • 104.126.37.155
  • 104.126.37.171
  • 104.126.37.130
unknown
ctldl.windowsupdate.com
  • 209.197.3.8
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
ocsp2.globalsign.com
  • 151.101.2.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.194.133
unknown
ocsp.globalsign.com
  • 151.101.2.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.194.133
unknown
clientservices.googleapis.com
  • 142.250.186.99
unknown
accounts.google.com
  • 216.58.212.173
unknown
www.google.com
  • 142.250.184.228
  • 142.250.185.164
  • 172.217.169.132
unknown
update.googleapis.com
  • 142.250.181.227
  • 142.250.187.131
unknown

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
Potential Corporate Privacy Violation
AV POLICY Observed TikTok Domain in TLS SNI (tiktok.com)
No debug info