File name: | Detected_File_48B0E20407A7A183DE95801C7DB101EF898B8CDD_20200221133348-0800 |
Full analysis: | https://app.any.run/tasks/5bf35fad-3792-4d21-a825-d0fc41200240 |
Verdict: | Malicious activity |
Analysis date: | February 22, 2020, 06:16:44 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/html |
File info: | HTML document, ASCII text |
MD5: | 36D43C7CB26AFC9E30CB50660396370F |
SHA1: | 48B0E20407A7A183DE95801C7DB101EF898B8CDD |
SHA256: | EAEFDC5E77B9FE6D904049B80B5367C7CA92CE2D97C5F28336D3C3585653B887 |
SSDEEP: | 6:pn0+Dy9xwhmEr6VjTMu9nPjLCKLeUx+lN68SVDFEl/7jx7zNU+KqD:J0+oxkmRNTMWPyQe3N68SVDFW/7jx7zx |
.htm/html | | | HyperText Markup Language with DOCTYPE (80.6) |
---|---|---|
.html | | | HyperText Markup Language (19.3) |
Title: | 302 Found |
---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3172 | "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\Detected_File_48B0E20407A7A183DE95801C7DB101EF898B8CDD_20200221133348-0800.htm | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
1832 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3172 CREDAT:144385 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
2400 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3172 CREDAT:333057 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
3824 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3172 CREDAT:726292 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
3172 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
2400 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Cab812E.tmp | — | |
MD5:— | SHA256:— | |||
2400 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\Tar812F.tmp | — | |
MD5:— | SHA256:— | |||
2400 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F51E5B12F35C173ECCBCAA3F54031F67 | binary | |
MD5:B42B753364466121303701DBFAA4890D | SHA256:48D1BD476C7069DB86F5AC3CD372E147B9CE6E9DC064648F4C78753933DC945A | |||
2400 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\main-menu[1].css | text | |
MD5:BD090CE9C5CE3B4C5A0CDA2DBB8639E2 | SHA256:26303FAE8B1571E30B3D5A0FB8A436C48FAF7228A7390A632CF1D9311DDD4C14 | |||
2400 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\responsive-tabs[1].css | text | |
MD5:D9F754027196A010F82549F694905C10 | SHA256:9797C72C813DBD49D6096045D1DB31D50607C2B61AC17DEB0BBEEB315425B43A | |||
2400 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E49827401028F7A0F97B5576C77A26CB_7CE95D8DCA26FE957E7BD7D76F353B08 | binary | |
MD5:C6CB61068AE7FF0C08FB20EB75C97318 | SHA256:7F826B9AF334F15B285C9AD0E0AD6B7752DDC378B2ACB536390613F3F2895436 | |||
2400 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F51E5B12F35C173ECCBCAA3F54031F67 | der | |
MD5:CB1316F1D787B755D5793FFEED508A91 | SHA256:6D24C0A9B68717698008CCE7FD80430D2DEE309C662462C09F14A3CA8C51DFD9 | |||
2400 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BE8B021F9E811DFC8C8A28572A17C05A_375B7F179C25C4C237293A604A6DE85C | binary | |
MD5:66B35343EA51B5C35FC84A1853BBCDEE | SHA256:A662B5D2598F14F06CF310EC84420EE42DB88B03D9D4C316CAE28DA313A51DEA | |||
2400 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CFE86DBBE02D859DC92F1E17E0574EE8_46766FC45507C0B9E264E4C18BC7288B | der | |
MD5:E550DA03AEE5B546B436CD553D3233B9 | SHA256:9ABFD4E29B96CCA442502B1DE6071FE0293455DF22B4EFF19FA3E6DF060947E7 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2400 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | US | der | 468 b | whitelisted |
2400 | iexplore.exe | GET | 200 | 2.21.242.204:80 | http://ocsp.int-x3.letsencrypt.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBR%2B5mrncpqz%2FPiiIGRsFqEtYHEIXQQUqEpqYwR93brm0Tm3pkVl7%2FOo7KECEgPeQgwgTiS7PGSsWLttKvS5gg%3D%3D | NL | der | 527 b | whitelisted |
2400 | iexplore.exe | GET | 200 | 2.21.242.197:80 | http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D | NL | der | 1.37 Kb | whitelisted |
2400 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | US | der | 468 b | whitelisted |
2400 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQCgdZM8AVzzKAgAAAAALnDU | US | der | 472 b | whitelisted |
2400 | iexplore.exe | GET | 200 | 2.21.242.197:80 | http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D | NL | der | 1.37 Kb | whitelisted |
2400 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDu3mVgzTXArwIAAAAAWXG3 | US | der | 472 b | whitelisted |
2400 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDu3mVgzTXArwIAAAAAWXG3 | US | der | 472 b | whitelisted |
2400 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDvdxhhS3x8DggAAAAALnGY | US | der | 472 b | whitelisted |
2400 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | US | der | 468 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3172 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2400 | iexplore.exe | 67.157.38.176:443 | www.hcd.ca.gov | California Technology Agency | US | unknown |
2400 | iexplore.exe | 216.58.207.36:443 | www.google.com | Google Inc. | US | whitelisted |
2400 | iexplore.exe | 2.21.242.197:80 | isrg.trustid.ocsp.identrust.com | Akamai International B.V. | NL | whitelisted |
2400 | iexplore.exe | 216.58.206.14:443 | translate.google.com | Google Inc. | US | whitelisted |
2400 | iexplore.exe | 2.21.242.204:80 | ocsp.int-x3.letsencrypt.org | Akamai International B.V. | NL | whitelisted |
2400 | iexplore.exe | 172.217.16.131:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
2400 | iexplore.exe | 172.217.22.40:443 | www.googletagmanager.com | Google Inc. | US | whitelisted |
2400 | iexplore.exe | 74.125.140.157:443 | stats.g.doubleclick.net | Google Inc. | US | whitelisted |
2400 | iexplore.exe | 172.217.23.104:443 | ssl.google-analytics.com | Google Inc. | US | suspicious |
Domain | IP | Reputation |
---|---|---|
www.hcd.ca.gov |
| unknown |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
isrg.trustid.ocsp.identrust.com |
| whitelisted |
ocsp.int-x3.letsencrypt.org |
| whitelisted |
translate.google.com |
| whitelisted |
www.google.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
ssl.google-analytics.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |