URL:

http://mailgun.internationalsos.com/c/eJxUkLGOnDAQQL_GdD557AHjwoWNTbJSVjqJJL0XDxwSCytMivx9xKW67mn0RjN63-7DnUpJM92ClQgAQkFbDctJ437Q7aTnLVimPWrdR2gVV844jrH2vO2g4zJ6FY1peqEi0-HL5o-0zX_STJa2L_PfdJRl3yxUw99yXci2qbJFgnGqyIIWqBTWUlUfthWUEShPdasMAtR5SnrExmAtUE65WqwTfWeECTzKTnMUveZeg-deSR_q0EjoDEPxa4gwfHfvw_3n-yCwWu3Heb4KU47Jnsn-PNJW1nQu-_a2bCcd2yentezlbdyf_6200nFeqPo1bTNTIRMPkclmyUwF1Hqiz0zJJI5UP3g7wsglPRQZ00xCEZPNRJRvl8-09y6Ac1JybGPL0ZmG-x6Qm9o5AKmVQ32VPeyjpOeLDmIoCj1fR5rX_ZHW67l_AQAA__9tm4Qt__;!!D1sDotPi8BGI9gw!m4hxtMiiTgzHOMKORCzZMdsQ3LshV4JR1jtS5BDKgCkhnVq-m2V1-BUN9u7zB3XyvOAc_DjKcuzsW1q_leHHlSVMXfM3Xw6hig$

Full analysis: https://app.any.run/tasks/4b6738e8-f899-42bf-b45d-0af2fca54ec0
Verdict: Malicious activity
Analysis date: January 16, 2024, 03:27:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

96845C3BEA6ADE5E2DB6C21257E9CED6

SHA1:

2A0ABCEF095CFC51C55834495AD44D0A838E6C38

SHA256:

DBF3D905EEB0FE2EE1D988432E287F1AF7FCAB8ED0B97068901ED4785F3C806A

SSDEEP:

12:PIPIZIz2nSkpJLufJmoACSwGOMMBD4sFilbqS/IUdrQXSkZO1OZmzCtcd:APICKnS9RmoH2OXBD40iluOrCROzr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ChromeSetup.exe (PID: 3540)
      • GoogleUpdateSetup.exe (PID: 2092)
      • GoogleUpdate.exe (PID: 3868)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ChromeSetup.exe (PID: 3540)
      • GoogleUpdateSetup.exe (PID: 2092)
      • GoogleUpdate.exe (PID: 3868)
    • Disables SEHOP

      • GoogleUpdate.exe (PID: 3868)
    • Creates/Modifies COM task schedule object

      • GoogleUpdate.exe (PID: 3912)
    • Reads the Internet Settings

      • GoogleUpdate.exe (PID: 3812)
      • GoogleUpdate.exe (PID: 1492)
    • Executes as Windows Service

      • GoogleUpdate.exe (PID: 4076)
    • Reads settings of System Certificates

      • GoogleUpdate.exe (PID: 3812)
      • GoogleUpdate.exe (PID: 1492)
    • Reads security settings of Internet Explorer

      • GoogleUpdate.exe (PID: 1492)
    • Checks Windows Trust Settings

      • GoogleUpdate.exe (PID: 1492)
  • INFO

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 1644)
      • iexplore.exe (PID: 124)
    • Application launched itself

      • iexplore.exe (PID: 124)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 1644)
      • iexplore.exe (PID: 124)
    • The process uses the downloaded file

      • iexplore.exe (PID: 124)
      • ChromeSetup.exe (PID: 3540)
    • Checks supported languages

      • ChromeSetup.exe (PID: 3540)
      • GoogleUpdate.exe (PID: 3532)
      • GoogleUpdateSetup.exe (PID: 2092)
      • GoogleUpdate.exe (PID: 3868)
      • GoogleUpdate.exe (PID: 3848)
      • GoogleUpdate.exe (PID: 3912)
      • GoogleUpdate.exe (PID: 3812)
      • GoogleUpdate.exe (PID: 1492)
      • GoogleUpdate.exe (PID: 4076)
    • Create files in a temporary directory

      • ChromeSetup.exe (PID: 3540)
      • GoogleUpdate.exe (PID: 1492)
    • Reads the computer name

      • GoogleUpdate.exe (PID: 3532)
      • GoogleUpdate.exe (PID: 3868)
      • GoogleUpdate.exe (PID: 3848)
      • GoogleUpdate.exe (PID: 3912)
      • GoogleUpdate.exe (PID: 3812)
      • GoogleUpdate.exe (PID: 1492)
      • GoogleUpdate.exe (PID: 4076)
    • Reads the machine GUID from the registry

      • GoogleUpdate.exe (PID: 3532)
      • GoogleUpdate.exe (PID: 3868)
      • GoogleUpdate.exe (PID: 1492)
      • GoogleUpdate.exe (PID: 4076)
      • GoogleUpdate.exe (PID: 3812)
    • Creates files in the program directory

      • GoogleUpdateSetup.exe (PID: 2092)
      • GoogleUpdate.exe (PID: 3868)
      • GoogleUpdate.exe (PID: 1492)
      • GoogleUpdate.exe (PID: 3848)
      • GoogleUpdate.exe (PID: 3912)
      • GoogleUpdate.exe (PID: 3812)
      • GoogleUpdate.exe (PID: 4076)
    • Checks proxy server information

      • GoogleUpdate.exe (PID: 1492)
    • Creates files or folders in the user directory

      • GoogleUpdate.exe (PID: 1492)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
16
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe chromesetup.exe googleupdate.exe no specs googleupdatesetup.exe googleupdate.exe googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe googleupdate.exe googleupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Program Files\Internet Explorer\iexplore.exe" "http://mailgun.internationalsos.com/c/eJxUkLGOnDAQQL_GdD557AHjwoWNTbJSVjqJJL0XDxwSCytMivx9xKW67mn0RjN63-7DnUpJM92ClQgAQkFbDctJ437Q7aTnLVimPWrdR2gVV844jrH2vO2g4zJ6FY1peqEi0-HL5o-0zX_STJa2L_PfdJRl3yxUw99yXci2qbJFgnGqyIIWqBTWUlUfthWUEShPdasMAtR5SnrExmAtUE65WqwTfWeECTzKTnMUveZeg-deSR_q0EjoDEPxa4gwfHfvw_3n-yCwWu3Heb4KU47Jnsn-PNJW1nQu-_a2bCcd2yentezlbdyf_6200nFeqPo1bTNTIRMPkclmyUwF1Hqiz0zJJI5UP3g7wsglPRQZ00xCEZPNRJRvl8-09y6Ac1JybGPL0ZmG-x6Qm9o5AKmVQ32VPeyjpOeLDmIoCj1fR5rX_ZHW67l_AQAA__9tm4Qt__;!!D1sDotPi8BGI9gw!m4hxtMiiTgzHOMKORCzZMdsQ3LshV4JR1jtS5BDKgCkhnVq-m2V1-BUN9u7zB3XyvOAc_DjKcuzsW1q_leHHlSVMXfM3Xw6higf7f81a39-5f63-5b42-9efd-1f13b5431005quot;C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
968"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:2430239 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1268"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:3675414 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1492"C:\Program Files\Google\Update\GoogleUpdate.exe" /handoff "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={2C8A60A5-25CA-81E5-BEE7-D9CF5FB2491E}&lang=en&browser=2&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=stable-arch_x86-statsdef_1&installdataindex=defaultbrowser" /installsource taggedmi /sessionid "{C727A2B3-55DD-4343-89F7-B6E0093D12FE}"C:\Program Files\Google\Update\GoogleUpdate.exe
GoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1644"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:660823 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2092"C:\Users\admin\AppData\Local\Temp\GUM9695.tmp\GoogleUpdateSetup.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={2C8A60A5-25CA-81E5-BEE7-D9CF5FB2491E}&lang=en&browser=2&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=stable-arch_x86-statsdef_1&installdataindex=defaultbrowser" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\GUM9695.tmp\GoogleUpdateSetup.exe
GoogleUpdate.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Update Setup
Exit code:
0
Version:
1.3.36.352
Modules
Images
c:\users\admin\appdata\local\temp\gum9695.tmp\googleupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2204"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2336"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:3806473 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2488"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:3675435 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3532C:\Users\admin\AppData\Local\Temp\GUM9695.tmp\GoogleUpdate.exe /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={2C8A60A5-25CA-81E5-BEE7-D9CF5FB2491E}&lang=en&browser=2&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=stable-arch_x86-statsdef_1&installdataindex=defaultbrowser"C:\Users\admin\AppData\Local\Temp\GUM9695.tmp\GoogleUpdate.exeChromeSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Installer
Exit code:
0
Version:
1.3.36.351
Modules
Images
c:\users\admin\appdata\local\temp\gum9695.tmp\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
70 879
Read events
67 648
Write events
3 139
Delete events
92

Modification events

(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
206
Suspicious files
113
Text files
287
Unknown types
0

Dropped files

PID
Process
Filename
Type
2204iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2204iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:551AB98CE86E92B516DBB166B4C02627
SHA256:A028C23E775D79D7A47B4EA12D89DA4BE7AF1E65ADB67FF36BF377BDF02E9349
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery.validate.unobtrusive[1].jstext
MD5:AF4745B35504641C942123F163F4E09D
SHA256:03197246BDFD70D6D4CD13802619C322AD80B735DA05EAEB97AC7CB50BF71275
2204iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A37B8BA80004D3266CB4D93B2052DC10_9930CFFA1A8DC7DD2E91B8BAFFAF726Dbinary
MD5:11F7204165E9D50F0DA70F065FCDC70B
SHA256:28F74A426D93D2C031C426A3D5072E7D18E1A6BD51774CD0ED7081A96224961D
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\site.validation[1].jstext
MD5:3FD1B8BB71D13E0CCD9BE7680BABAB16
SHA256:0C508249AA662D30F109FB71667FCD202C4A5235B3FC552B7ECB50C72D81887A
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\alert[1].htmhtml
MD5:03BA0257C05A8C7CD3DB812828B75D29
SHA256:F55750EEBACCB641294ED6AF7C6B8897DFB434FD86CF3295870B2BF177FDC5DE
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery.requestAnimationFrame.min[1].jstext
MD5:8D1A0888D9E506238A63E92D3F82EFB8
SHA256:37D998F3A728A3248A8330951AA99B7F403F6A7CD25A0C58E9B29A865FD978AB
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery.unobtrusive-ajax[1].jstext
MD5:76C0AF7FEECC460402EE4FBC98DD36BC
SHA256:343BE4324C7C60FDC6F4BE2254C4913E188CF3CDBAB45A1B2A0F44FA656D6FFD
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery-3.3.1[1].jstext
MD5:239323BF77AB54A1338268FB545E6E78
SHA256:8C814712CCAF55E4F93469DAF010BA277E8569D60781237C3A2AC6EAF81359E1
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery-3.5.1[1].jstext
MD5:1AD1EE488A3D394708CA7241AAA459C2
SHA256:5DCA20C7AF8324DA4B122B6CF2F9634BC367E77F4A23A42D9BE8E20742B84B3B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
234
DNS requests
54
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2204
iexplore.exe
GET
302
34.110.180.34:80
http://mailgun.internationalsos.com/c/eJxUkLGOnDAQQL_GdD557AHjwoWNTbJSVjqJJL0XDxwSCytMivx9xKW67mn0RjN63-7DnUpJM92ClQgAQkFbDctJ437Q7aTnLVimPWrdR2gVV844jrH2vO2g4zJ6FY1peqEi0-HL5o-0zX_STJa2L_PfdJRl3yxUw99yXci2qbJFgnGqyIIWqBTWUlUfthWUEShPdasMAtR5SnrExmAtUE65WqwTfWeECTzKTnMUveZeg-deSR_q0EjoDEPxa4gwfHfvw_3n-yCwWu3Heb4KU47Jnsn-PNJW1nQu-_a2bCcd2yentezlbdyf_6200nFeqPo1bTNTIRMPkclmyUwF1Hqiz0zJJI5UP3g7wsglPRQZ00xCEZPNRJRvl8-09y6Ac1JybGPL0ZmG-x6Qm9o5AKmVQ32VPeyjpOeLDmIoCj1fR5rX_ZHW67l_AQAA__9tm4Qt__;!!D1sDotPi8BGI9gw!m4hxtMiiTgzHOMKORCzZMdsQ3LshV4JR1jtS5BDKgCkhnVq-m2V1-BUN9u7zB3XyvOAc_DjKcuzsW1q_leHHlSVMXfM3Xw6hig$
unknown
html
664 b
unknown
2204
iexplore.exe
GET
200
23.32.238.227:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f6bf34dbb61e71d7
unknown
compressed
4.66 Kb
unknown
2204
iexplore.exe
GET
200
23.32.238.227:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?608cb4ab6d3f68d3
unknown
compressed
4.66 Kb
unknown
2204
iexplore.exe
GET
200
2.18.162.189:80
http://ocsp.entrust.net/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanImetAe733nO2lR1GyNn5ASZqsCDA7pTMMAAAAAUdN3hQ%3D%3D
unknown
binary
1.55 Kb
unknown
124
iexplore.exe
GET
304
23.32.238.227:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ce83dcf70518f919
unknown
unknown
124
iexplore.exe
GET
304
23.32.238.227:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1a6e676fbb64f2cc
unknown
unknown
124
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
313 b
unknown
2204
iexplore.exe
GET
200
2.18.162.189:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTMbSIc9rRVLC%2BHkV9a%2FvDh7s6DzAQUgqJwdN28Uz%2FPe9T3zX%2BnYMYKTL8CEAc8TQcVWotza8I0Swa%2FwEg%3D
unknown
binary
1.55 Kb
unknown
2204
iexplore.exe
GET
200
142.250.185.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2204
iexplore.exe
GET
200
142.250.185.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2204
iexplore.exe
34.110.180.34:80
mailgun.internationalsos.com
GOOGLE
US
unknown
2204
iexplore.exe
45.60.13.197:443
translation.internationalsos.com
INCAPSULA
US
unknown
2204
iexplore.exe
23.32.238.227:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2204
iexplore.exe
2.18.162.189:80
ocsp.entrust.net
AKAMAI-AS
DE
unknown
124
iexplore.exe
23.53.43.121:443
www.bing.com
Akamai International B.V.
DE
unknown
2204
iexplore.exe
45.60.80.68:443
www.internationalsos.com
INCAPSULA
US
unknown
2204
iexplore.exe
18.165.183.120:443
cdn1.internationalsos.com
US
unknown

DNS requests

Domain
IP
Reputation
mailgun.internationalsos.com
  • 34.110.180.34
unknown
translation.internationalsos.com
  • 45.60.13.197
unknown
ctldl.windowsupdate.com
  • 23.32.238.227
  • 23.32.238.203
  • 23.32.238.200
  • 23.32.238.201
  • 23.32.238.168
  • 23.32.238.194
  • 23.32.238.217
  • 23.32.238.240
  • 23.32.238.193
  • 93.184.221.240
whitelisted
ocsp.entrust.net
  • 2.18.162.189
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 23.53.43.121
  • 23.53.43.115
whitelisted
www.internationalsos.com
  • 45.60.80.68
unknown
cdn1.internationalsos.com
  • 18.165.183.120
  • 18.165.183.19
  • 18.165.183.73
  • 18.165.183.8
  • 18.245.31.75
  • 18.245.31.11
  • 18.245.31.17
  • 18.245.31.98
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.googletagmanager.com
  • 142.250.184.232
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
856
svchost.exe
Misc activity
ET INFO EXE - Served Attached HTTP
856
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info