| URL: | http://example.com |
| Full analysis: | https://app.any.run/tasks/13eba0f9-3add-4f79-a1c4-4beffbac1189 |
| Verdict: | Suspicious activity |
| Analysis date: | July 05, 2019, 13:35:42 |
| OS: | Windows 10 Professional (build: 16299, 64 bit) |
| Indicators: | |
| MD5: | A9B9F04336CE0181A08E774E01113B31 |
| SHA1: | 89DCE6A446A69D6B9BDC01AC75251E4C322BCDFF |
| SHA256: | F0E6A6A97042A4F1F1C87F5F7D44315B2D852C2DF5C7991CC66241BF7072D1C4 |
| SSDEEP: | 3:N1KbGINT:CB |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 760 | "C:\Program Files\internet explorer\iexplore.exe" SCODEF:1760 CREDAT:75020 /prefetch:2 | C:\Program Files\internet explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.16299.15 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1760 | "C:\Program Files\internet explorer\iexplore.exe" http://example.com | C:\Program Files\internet explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.16299.15 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3572 | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1760 CREDAT:9474 /prefetch:2 | C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.16299.15 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3744 | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1760 CREDAT:9476 /prefetch:2 | C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.16299.15 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4888 | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1760 CREDAT:4068624 /prefetch:2 | C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.16299.15 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5064 | C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft (R) Diagnostics Hub Standard Collector Exit code: 0 Version: 11.00.16299.431 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6140 | "C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe" -Embedding | C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe | — | svchost.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe® Flash® Player Utility Exit code: 0 Version: 29,0,0,171 Modules
| |||||||||||||||
| (PID) Process: | (1760) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlock |
| Operation: | write | Name: | L1WatermarkLowPart |
Value: 2774191708 | |||
| (PID) Process: | (1760) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlock |
| Operation: | write | Name: | L1WatermarkHighPart |
Value: 148288328 | |||
| (PID) Process: | (1760) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlock |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 2846349740 | |||
| (PID) Process: | (1760) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlock |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30749494 | |||
| (PID) Process: | (1760) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (1760) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1760) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1760) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (1760) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1760) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3572 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\LD57I5PR\X4WQQ2WI.htm | html | |
MD5:— | SHA256:— | |||
| 1760 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFFA4D91B75DB2A8DD.TMP | — | |
MD5:— | SHA256:— | |||
| 3744 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\FZ4P8RAN\meversion[1].js | text | |
MD5:— | SHA256:— | |||
| 3744 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\5UIG5DSE\1e-fd610f[1].js | text | |
MD5:— | SHA256:— | |||
| 3744 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\2I6MPL32\cartcount[1].htm | html | |
MD5:— | SHA256:— | |||
| 3744 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\FZ4P8RAN\meBoot.min[1].js | text | |
MD5:— | SHA256:— | |||
| 3744 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\FZ4P8RAN\e3-082b89[1].js | text | |
MD5:— | SHA256:— | |||
| 3744 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\LD57I5PR\welcomeie11[1].htm | html | |
MD5:— | SHA256:— | |||
| 3744 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\FZ4P8RAN\typographicintro[1].css | text | |
MD5:— | SHA256:— | |||
| 3744 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\2I6MPL32\meCore.min[1].js | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3744 | IEXPLORE.EXE | GET | 302 | 2.19.38.59:443 | https://go.microsoft.com/fwlink/?LinkId=838604 | unknown | — | — | whitelisted |
3744 | IEXPLORE.EXE | GET | 302 | 2.19.38.59:443 | https://go.microsoft.com/fwlink/?LinkId=517287 | unknown | — | — | whitelisted |
3744 | IEXPLORE.EXE | GET | 301 | 2.18.233.62:443 | https://www.microsoft.com/en-us/welcomeie11/ | unknown | — | — | whitelisted |
3744 | IEXPLORE.EXE | GET | 204 | 2.18.232.244:443 | https://uhf.microsoft.com/_log?o=mscc&s=Microsoft.OneRenderFramework.Core&m=show&nv=aspnet-3.1.3&sv=0.1.2 | unknown | — | — | whitelisted |
3572 | IEXPLORE.EXE | GET | 200 | 93.184.216.34:80 | http://example.com/ | US | html | 606 b | whitelisted |
3744 | IEXPLORE.EXE | GET | 200 | 104.111.216.162:443 | https://mem.gfx.ms/meversion?partner=RetailStore2&market=en-us&uhf=1 | NL | text | 24.8 Kb | whitelisted |
3744 | IEXPLORE.EXE | GET | 200 | 2.18.233.62:443 | https://www.microsoft.com/onerfstatics/marketingsites-neu-prod/welcomeie11/_scrf/js/themes=default/2f-63ce8f/2d-7a9063/dc-7e9864/4f-5115f8/7d-266f10/4a-abd94b/78-4c7d22/7e-fb0d6a/e4-8302f6/cd-23d3b0/6d-1e7ed0/b7-cadaa7/ca-40b7b0/4e-ee3a55/3e-f5c39b/c3-6454d7/f9-7592d3/92-10345d/f8-73a5f2/79-499886/7e-cda2d3/32-6dafa3/93-283c2d/91-97a04f/1f-100dea/33-abe4df/18-d72213/e3-082b89?ver=2.0 | unknown | text | 102 Kb | whitelisted |
1760 | iexplore.exe | GET | 404 | 93.184.216.34:80 | http://example.com/favicon.ico | US | html | 606 b | whitelisted |
3744 | IEXPLORE.EXE | GET | 200 | 2.18.233.62:443 | https://www.microsoft.com/onerfstatics/marketingsites-neu-prod/west-european/welcomeie11/_scrf/css/themes=default.device=uplevel_web_pc_ie/2b-19f120/bb-57b92e/90-cdc061?ver=2.0 | unknown | text | 76.6 Kb | whitelisted |
3744 | IEXPLORE.EXE | GET | 200 | 2.18.233.62:443 | https://www.microsoft.com/onerfstatics/marketingsites-neu-prod/welcomeie11/_scrf/js/themes=default/78-6f121b/1e-fd610f?ver=2.0 | unknown | text | 64.8 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3572 | IEXPLORE.EXE | 93.184.216.34:80 | example.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3572 | IEXPLORE.EXE | 52.136.230.174:443 | urs.microsoft.com | Microsoft Corporation | NL | unknown |
1760 | iexplore.exe | 93.184.216.34:80 | example.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3744 | IEXPLORE.EXE | 2.19.38.59:443 | go.microsoft.com | Akamai International B.V. | — | whitelisted |
3744 | IEXPLORE.EXE | 2.18.233.62:443 | www.microsoft.com | Akamai International B.V. | — | whitelisted |
— | — | 2.18.232.244:443 | uhf.microsoft.com | Akamai International B.V. | — | whitelisted |
3744 | IEXPLORE.EXE | 2.16.186.27:443 | img-prod-cms-rt-microsoft-com.akamaized.net | Akamai International B.V. | — | whitelisted |
1760 | iexplore.exe | 2.18.233.62:443 | www.microsoft.com | Akamai International B.V. | — | whitelisted |
3744 | IEXPLORE.EXE | 64.4.54.254:443 | web.vortex.data.microsoft.com | Microsoft Corporation | US | whitelisted |
1760 | iexplore.exe | 137.117.142.136:443 | c.urs.microsoft.com | Microsoft Corporation | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
example.com |
| whitelisted |
urs.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
c.s-microsoft.com |
| whitelisted |
mem.gfx.ms |
| whitelisted |
img-prod-cms-rt-microsoft-com.akamaized.net |
| whitelisted |
uhf.microsoft.com |
| whitelisted |
web.vortex.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |