URL:

http://mailgun.internationalsos.com/c/eJxUkLGOnDAQQL_GdD557AHjwoWNTbJSVjqJJL0XDxwSCytMivx9xKW67mn0RjN63-7DnUpJM92ClQgAQkFbDctJ437Q7aTnLVimPWrdR2gVV844jrH2vO2g4zJ6FY1peqEi0-HL5o-0zX_STJa2L_PfdJRl3yxUw99yXci2qbJFgnGqyIIWqBTWUlUfthWUEShPdasMAtR5SnrExmAtUE65WqwTfWeECTzKTnMUveZeg-deSR_q0EjoDEPxa4gwfHfvw_3n-yCwWu3Heb4KU47Jnsn-PNJW1nQu-_a2bCcd2yentezlbdyf_6200nFeqPo1bTNTIRMPkclmyUwF1Hqiz0zJJI5UP3g7wsglPRQZ00xCEZPNRJRvl8-09y6Ac1JybGPL0ZmG-x6Qm9o5AKmVQ32VPeyjpOeLDmIoCj1fR5rX_ZHW67l_AQAA__9tm4Qt__;!!D1sDotPi8BGI9gw!m4hxtMiiTgzHOMKORCzZMdsQ3LshV4JR1jtS5BDKgCkhnVq-m2V1-BUN9u7zB3XyvOAc_DjKcuzsW1q_leHHlSVMXfM3Xw6hig$

Full analysis: https://app.any.run/tasks/4b6738e8-f899-42bf-b45d-0af2fca54ec0
Verdict: Malicious activity
Analysis date: January 16, 2024, 03:27:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

96845C3BEA6ADE5E2DB6C21257E9CED6

SHA1:

2A0ABCEF095CFC51C55834495AD44D0A838E6C38

SHA256:

DBF3D905EEB0FE2EE1D988432E287F1AF7FCAB8ED0B97068901ED4785F3C806A

SSDEEP:

12:PIPIZIz2nSkpJLufJmoACSwGOMMBD4sFilbqS/IUdrQXSkZO1OZmzCtcd:APICKnS9RmoH2OXBD40iluOrCROzr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ChromeSetup.exe (PID: 3540)
      • GoogleUpdateSetup.exe (PID: 2092)
      • GoogleUpdate.exe (PID: 3868)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ChromeSetup.exe (PID: 3540)
      • GoogleUpdateSetup.exe (PID: 2092)
      • GoogleUpdate.exe (PID: 3868)
    • Disables SEHOP

      • GoogleUpdate.exe (PID: 3868)
    • Creates/Modifies COM task schedule object

      • GoogleUpdate.exe (PID: 3912)
    • Reads the Internet Settings

      • GoogleUpdate.exe (PID: 3812)
      • GoogleUpdate.exe (PID: 1492)
    • Executes as Windows Service

      • GoogleUpdate.exe (PID: 4076)
    • Reads settings of System Certificates

      • GoogleUpdate.exe (PID: 1492)
      • GoogleUpdate.exe (PID: 3812)
    • Checks Windows Trust Settings

      • GoogleUpdate.exe (PID: 1492)
    • Reads security settings of Internet Explorer

      • GoogleUpdate.exe (PID: 1492)
  • INFO

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 1644)
      • iexplore.exe (PID: 124)
    • Checks supported languages

      • ChromeSetup.exe (PID: 3540)
      • GoogleUpdate.exe (PID: 3532)
      • GoogleUpdateSetup.exe (PID: 2092)
      • GoogleUpdate.exe (PID: 3868)
      • GoogleUpdate.exe (PID: 3848)
      • GoogleUpdate.exe (PID: 3912)
      • GoogleUpdate.exe (PID: 3812)
      • GoogleUpdate.exe (PID: 1492)
      • GoogleUpdate.exe (PID: 4076)
    • Create files in a temporary directory

      • ChromeSetup.exe (PID: 3540)
      • GoogleUpdate.exe (PID: 1492)
    • The process uses the downloaded file

      • iexplore.exe (PID: 124)
      • ChromeSetup.exe (PID: 3540)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 1644)
      • iexplore.exe (PID: 124)
    • Application launched itself

      • iexplore.exe (PID: 124)
    • Reads the computer name

      • GoogleUpdate.exe (PID: 3532)
      • GoogleUpdate.exe (PID: 3868)
      • GoogleUpdate.exe (PID: 3848)
      • GoogleUpdate.exe (PID: 3912)
      • GoogleUpdate.exe (PID: 3812)
      • GoogleUpdate.exe (PID: 1492)
      • GoogleUpdate.exe (PID: 4076)
    • Reads the machine GUID from the registry

      • GoogleUpdate.exe (PID: 3532)
      • GoogleUpdate.exe (PID: 3868)
      • GoogleUpdate.exe (PID: 1492)
      • GoogleUpdate.exe (PID: 4076)
      • GoogleUpdate.exe (PID: 3812)
    • Creates files in the program directory

      • GoogleUpdateSetup.exe (PID: 2092)
      • GoogleUpdate.exe (PID: 3868)
      • GoogleUpdate.exe (PID: 3848)
      • GoogleUpdate.exe (PID: 3912)
      • GoogleUpdate.exe (PID: 3812)
      • GoogleUpdate.exe (PID: 1492)
      • GoogleUpdate.exe (PID: 4076)
    • Checks proxy server information

      • GoogleUpdate.exe (PID: 1492)
    • Creates files or folders in the user directory

      • GoogleUpdate.exe (PID: 1492)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
16
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe chromesetup.exe googleupdate.exe no specs googleupdatesetup.exe googleupdate.exe googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe googleupdate.exe googleupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Program Files\Internet Explorer\iexplore.exe" "http://mailgun.internationalsos.com/c/eJxUkLGOnDAQQL_GdD557AHjwoWNTbJSVjqJJL0XDxwSCytMivx9xKW67mn0RjN63-7DnUpJM92ClQgAQkFbDctJ437Q7aTnLVimPWrdR2gVV844jrH2vO2g4zJ6FY1peqEi0-HL5o-0zX_STJa2L_PfdJRl3yxUw99yXci2qbJFgnGqyIIWqBTWUlUfthWUEShPdasMAtR5SnrExmAtUE65WqwTfWeECTzKTnMUveZeg-deSR_q0EjoDEPxa4gwfHfvw_3n-yCwWu3Heb4KU47Jnsn-PNJW1nQu-_a2bCcd2yentezlbdyf_6200nFeqPo1bTNTIRMPkclmyUwF1Hqiz0zJJI5UP3g7wsglPRQZ00xCEZPNRJRvl8-09y6Ac1JybGPL0ZmG-x6Qm9o5AKmVQ32VPeyjpOeLDmIoCj1fR5rX_ZHW67l_AQAA__9tm4Qt__;!!D1sDotPi8BGI9gw!m4hxtMiiTgzHOMKORCzZMdsQ3LshV4JR1jtS5BDKgCkhnVq-m2V1-BUN9u7zB3XyvOAc_DjKcuzsW1q_leHHlSVMXfM3Xw6higf7f81a39-5f63-5b42-9efd-1f13b5431005quot;C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
968"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:2430239 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1268"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:3675414 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1492"C:\Program Files\Google\Update\GoogleUpdate.exe" /handoff "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={2C8A60A5-25CA-81E5-BEE7-D9CF5FB2491E}&lang=en&browser=2&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=stable-arch_x86-statsdef_1&installdataindex=defaultbrowser" /installsource taggedmi /sessionid "{C727A2B3-55DD-4343-89F7-B6E0093D12FE}"C:\Program Files\Google\Update\GoogleUpdate.exe
GoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1644"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:660823 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2092"C:\Users\admin\AppData\Local\Temp\GUM9695.tmp\GoogleUpdateSetup.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={2C8A60A5-25CA-81E5-BEE7-D9CF5FB2491E}&lang=en&browser=2&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=stable-arch_x86-statsdef_1&installdataindex=defaultbrowser" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\GUM9695.tmp\GoogleUpdateSetup.exe
GoogleUpdate.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Update Setup
Exit code:
0
Version:
1.3.36.352
Modules
Images
c:\users\admin\appdata\local\temp\gum9695.tmp\googleupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2204"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2336"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:3806473 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2488"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:3675435 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3532C:\Users\admin\AppData\Local\Temp\GUM9695.tmp\GoogleUpdate.exe /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={2C8A60A5-25CA-81E5-BEE7-D9CF5FB2491E}&lang=en&browser=2&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=stable-arch_x86-statsdef_1&installdataindex=defaultbrowser"C:\Users\admin\AppData\Local\Temp\GUM9695.tmp\GoogleUpdate.exeChromeSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Installer
Exit code:
0
Version:
1.3.36.351
Modules
Images
c:\users\admin\appdata\local\temp\gum9695.tmp\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
70 879
Read events
67 648
Write events
3 139
Delete events
92

Modification events

(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
206
Suspicious files
113
Text files
287
Unknown types
0

Dropped files

PID
Process
Filename
Type
2204iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2204iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:551AB98CE86E92B516DBB166B4C02627
SHA256:A028C23E775D79D7A47B4EA12D89DA4BE7AF1E65ADB67FF36BF377BDF02E9349
2204iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A37B8BA80004D3266CB4D93B2052DC10_9930CFFA1A8DC7DD2E91B8BAFFAF726Dbinary
MD5:D1C4649E7AE522AF2456B64A881B74F8
SHA256:9859498577D3E6DF2F946017DDA0B43805540F0A7810FFDB04BEA656F49DC7F7
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\alert[1].htmhtml
MD5:03BA0257C05A8C7CD3DB812828B75D29
SHA256:F55750EEBACCB641294ED6AF7C6B8897DFB434FD86CF3295870B2BF177FDC5DE
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery-3.3.1[1].jstext
MD5:239323BF77AB54A1338268FB545E6E78
SHA256:8C814712CCAF55E4F93469DAF010BA277E8569D60781237C3A2AC6EAF81359E1
2204iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A37B8BA80004D3266CB4D93B2052DC10_9930CFFA1A8DC7DD2E91B8BAFFAF726Dbinary
MD5:11F7204165E9D50F0DA70F065FCDC70B
SHA256:28F74A426D93D2C031C426A3D5072E7D18E1A6BD51774CD0ED7081A96224961D
2204iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\QQDHICYI.txttext
MD5:0AE6796698FE25EE5845E0044856261E
SHA256:5067D077DF142D68A582A5E1DCA4AC188FB202CA45164ECE7B6A3AE7A36E7A5E
2204iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\HSW3ANKI.txttext
MD5:929B817A5C2A5D36275439758A937532
SHA256:FDE9ED35ADCC0132191B8A56AD4E2E2B3E3A53602A5F28ACE29DC9C5EC306E86
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery.validate[1].jstext
MD5:A11E557FFC45069BF28E267645DA1E4E
SHA256:27E4D8E3C7D7859D58E43F24C94EABD156219487BD7C095DCCBCA1BD3DB93274
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery.validate.unobtrusive[1].jstext
MD5:AF4745B35504641C942123F163F4E09D
SHA256:03197246BDFD70D6D4CD13802619C322AD80B735DA05EAEB97AC7CB50BF71275
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
234
DNS requests
54
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2204
iexplore.exe
GET
302
34.110.180.34:80
http://mailgun.internationalsos.com/c/eJxUkLGOnDAQQL_GdD557AHjwoWNTbJSVjqJJL0XDxwSCytMivx9xKW67mn0RjN63-7DnUpJM92ClQgAQkFbDctJ437Q7aTnLVimPWrdR2gVV844jrH2vO2g4zJ6FY1peqEi0-HL5o-0zX_STJa2L_PfdJRl3yxUw99yXci2qbJFgnGqyIIWqBTWUlUfthWUEShPdasMAtR5SnrExmAtUE65WqwTfWeECTzKTnMUveZeg-deSR_q0EjoDEPxa4gwfHfvw_3n-yCwWu3Heb4KU47Jnsn-PNJW1nQu-_a2bCcd2yentezlbdyf_6200nFeqPo1bTNTIRMPkclmyUwF1Hqiz0zJJI5UP3g7wsglPRQZ00xCEZPNRJRvl8-09y6Ac1JybGPL0ZmG-x6Qm9o5AKmVQ32VPeyjpOeLDmIoCj1fR5rX_ZHW67l_AQAA__9tm4Qt__;!!D1sDotPi8BGI9gw!m4hxtMiiTgzHOMKORCzZMdsQ3LshV4JR1jtS5BDKgCkhnVq-m2V1-BUN9u7zB3XyvOAc_DjKcuzsW1q_leHHlSVMXfM3Xw6hig$
US
html
664 b
unknown
2204
iexplore.exe
GET
200
23.32.238.227:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f6bf34dbb61e71d7
DE
compressed
4.66 Kb
unknown
2204
iexplore.exe
GET
200
2.18.162.189:80
http://ocsp.entrust.net/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanImetAe733nO2lR1GyNn5ASZqsCDA7pTMMAAAAAUdN3hQ%3D%3D
DE
binary
1.55 Kb
unknown
124
iexplore.exe
GET
304
23.32.238.227:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ce83dcf70518f919
DE
unknown
2204
iexplore.exe
GET
200
142.250.185.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
binary
1.41 Kb
unknown
124
iexplore.exe
GET
304
23.32.238.227:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1a6e676fbb64f2cc
DE
unknown
124
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
US
binary
313 b
unknown
2204
iexplore.exe
GET
200
142.250.185.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
binary
724 b
unknown
2204
iexplore.exe
GET
200
2.18.162.189:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTMbSIc9rRVLC%2BHkV9a%2FvDh7s6DzAQUgqJwdN28Uz%2FPe9T3zX%2BnYMYKTL8CEAc8TQcVWotza8I0Swa%2FwEg%3D
DE
binary
1.55 Kb
unknown
2204
iexplore.exe
GET
200
142.250.185.195:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQD7vSzSbK8Z0QnHSrEZ7mPf
US
binary
472 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2204
iexplore.exe
34.110.180.34:80
mailgun.internationalsos.com
GOOGLE
US
unknown
2204
iexplore.exe
45.60.13.197:443
translation.internationalsos.com
INCAPSULA
US
unknown
2204
iexplore.exe
23.32.238.227:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2204
iexplore.exe
2.18.162.189:80
ocsp.entrust.net
AKAMAI-AS
DE
unknown
124
iexplore.exe
23.53.43.121:443
www.bing.com
Akamai International B.V.
DE
unknown
2204
iexplore.exe
45.60.80.68:443
www.internationalsos.com
INCAPSULA
US
unknown
2204
iexplore.exe
18.165.183.120:443
cdn1.internationalsos.com
US
unknown

DNS requests

Domain
IP
Reputation
mailgun.internationalsos.com
  • 34.110.180.34
unknown
translation.internationalsos.com
  • 45.60.13.197
unknown
ctldl.windowsupdate.com
  • 23.32.238.227
  • 23.32.238.203
  • 23.32.238.200
  • 23.32.238.201
  • 23.32.238.168
  • 23.32.238.194
  • 23.32.238.217
  • 23.32.238.240
  • 23.32.238.193
  • 93.184.221.240
whitelisted
ocsp.entrust.net
  • 2.18.162.189
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 23.53.43.121
  • 23.53.43.115
whitelisted
www.internationalsos.com
  • 45.60.80.68
unknown
cdn1.internationalsos.com
  • 18.165.183.120
  • 18.165.183.19
  • 18.165.183.73
  • 18.165.183.8
  • 18.245.31.75
  • 18.245.31.11
  • 18.245.31.17
  • 18.245.31.98
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.googletagmanager.com
  • 142.250.184.232
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
856
svchost.exe
Misc activity
ET INFO EXE - Served Attached HTTP
856
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info