URL:

https://bimvision.eu/?smd_process_download=1&download_id=10083

Full analysis: https://app.any.run/tasks/29c7940a-f0ef-4430-bb2d-73c11b9e7de9
Verdict: Malicious activity
Analysis date: March 13, 2024, 07:26:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

F9423BF53D6C0CD1F0B2F03B50E8E6D0

SHA1:

22C9B8D3681316557855D3C13BC5A200154AE14D

SHA256:

F1141CDF50E67044E39B9CD85D9CA22D7C56487FE1D75648728F5E285083FEFE

SSDEEP:

3:N8HMTQNMVXgUDZUAi:2sTQ2VXRF+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BIMvision 2.27.7 Setup.exe (PID: 1928)
      • BIMvision 2.27.7 Setup.exe (PID: 1768)
      • BIMvision 2.27.7 Setup.tmp (PID: 2900)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • BIMvision 2.27.7 Setup.tmp (PID: 2900)
    • Executable content was dropped or overwritten

      • BIMvision 2.27.7 Setup.exe (PID: 1928)
      • BIMvision 2.27.7 Setup.exe (PID: 1768)
      • BIMvision 2.27.7 Setup.tmp (PID: 2900)
    • Non-standard symbols in registry

      • BIMvision 2.27.7 Setup.tmp (PID: 2900)
    • Reads the Internet Settings

      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
    • Reads security settings of Internet Explorer

      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
    • Reads Microsoft Outlook installation path

      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
    • Reads settings of System Certificates

      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
    • Checks Windows Trust Settings

      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
    • Reads Internet Explorer settings

      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
  • INFO

    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 3972)
    • Application launched itself

      • iexplore.exe (PID: 3668)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3972)
    • Create files in a temporary directory

      • BIMvision 2.27.7 Setup.exe (PID: 1768)
      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
      • BIMvision 2.27.7 Setup.exe (PID: 1928)
    • Checks supported languages

      • BIMvision 2.27.7 Setup.tmp (PID: 3516)
      • BIMvision 2.27.7 Setup.exe (PID: 1768)
      • BIMvision 2.27.7 Setup.tmp (PID: 2900)
      • BIM_Vision.exe (PID: 2248)
      • update .NET plugin dependencies.exe (PID: 568)
      • BIM_Vision.exe (PID: 2308)
      • wmpnscfg.exe (PID: 3808)
      • BIMvision 2.27.7 Setup.exe (PID: 1928)
    • Reads the computer name

      • BIMvision 2.27.7 Setup.tmp (PID: 3516)
      • BIMvision 2.27.7 Setup.tmp (PID: 2900)
      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
      • wmpnscfg.exe (PID: 3808)
    • Creates files in the program directory

      • BIMvision 2.27.7 Setup.tmp (PID: 2900)
      • update .NET plugin dependencies.exe (PID: 568)
      • BIM_Vision.exe (PID: 2248)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 3668)
    • Reads the machine GUID from the registry

      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
    • Checks proxy server information

      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
    • Reads the software policy settings

      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
    • Creates a software uninstall entry

      • BIMvision 2.27.7 Setup.tmp (PID: 2900)
    • Manual execution by a user

      • BIM_Vision.exe (PID: 2308)
      • wmpnscfg.exe (PID: 3808)
    • Creates files or folders in the user directory

      • BIM_Vision.exe (PID: 2248)
      • BIM_Vision.exe (PID: 2308)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
10
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe bimvision 2.27.7 setup.exe bimvision 2.27.7 setup.tmp no specs bimvision 2.27.7 setup.exe bimvision 2.27.7 setup.tmp update .net plugin dependencies.exe no specs bim_vision.exe bim_vision.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
568"C:\Program Files\Datacomp\BIM Vision\update .NET plugin dependencies.exe"C:\Program Files\Datacomp\BIM Vision\update .NET plugin dependencies.exeBIMvision 2.27.7 Setup.tmp
User:
admin
Company:
Datacomp Sp. z o.o.
Integrity Level:
HIGH
Description:
Update .NET plugin dependencies
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\datacomp\bim vision\update .net plugin dependencies.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
1768"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\BIMvision 2.27.7 Setup.exe" /SPAWNWND=$110196 /NOTIFYWND=$D025A C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\BIMvision 2.27.7 Setup.exe
BIMvision 2.27.7 Setup.tmp
User:
admin
Company:
Datacomp IT Sp. z o.o.
Integrity Level:
HIGH
Description:
BIMvision installer
Exit code:
0
Version:
{code:get_AppVersion
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\bimvision 2.27.7 setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1928"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\BIMvision 2.27.7 Setup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\BIMvision 2.27.7 Setup.exe
iexplore.exe
User:
admin
Company:
Datacomp IT Sp. z o.o.
Integrity Level:
MEDIUM
Description:
BIMvision installer
Exit code:
0
Version:
{code:get_AppVersion
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\bimvision 2.27.7 setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2248"C:\Program Files\Datacomp\BIM Vision\bim_vision.exe"C:\Program Files\Datacomp\BIM Vision\BIM_Vision.exe
BIMvision 2.27.7 Setup.tmp
User:
admin
Company:
Datacomp IT Sp. z o.o.
Integrity Level:
MEDIUM
Description:
BIMvision - freeware IFC viewer
Exit code:
0
Version:
2.27.7.33305
Modules
Images
c:\program files\datacomp\bim vision\bim_vision.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
2308"C:\Program Files\Datacomp\BIM Vision\BIM_Vision.exe" C:\Program Files\Datacomp\BIM Vision\BIM_Vision.exe
explorer.exe
User:
admin
Company:
Datacomp IT Sp. z o.o.
Integrity Level:
MEDIUM
Description:
BIMvision - freeware IFC viewer
Exit code:
0
Version:
2.27.7.33305
Modules
Images
c:\program files\datacomp\bim vision\bim_vision.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
2900"C:\Users\admin\AppData\Local\Temp\is-NQ39D.tmp\BIMvision 2.27.7 Setup.tmp" /SL5="$180138,41089574,780800,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\BIMvision 2.27.7 Setup.exe" /SPAWNWND=$110196 /NOTIFYWND=$D025A C:\Users\admin\AppData\Local\Temp\is-NQ39D.tmp\BIMvision 2.27.7 Setup.tmp
BIMvision 2.27.7 Setup.exe
User:
admin
Company:
Datacomp IT Sp. z o.o.
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-nq39d.tmp\bimvision 2.27.7 setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3516"C:\Users\admin\AppData\Local\Temp\is-0N87G.tmp\BIMvision 2.27.7 Setup.tmp" /SL5="$D025A,41089574,780800,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\BIMvision 2.27.7 Setup.exe" C:\Users\admin\AppData\Local\Temp\is-0N87G.tmp\BIMvision 2.27.7 Setup.tmpBIMvision 2.27.7 Setup.exe
User:
admin
Company:
Datacomp IT Sp. z o.o.
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-0n87g.tmp\bimvision 2.27.7 setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3668"C:\Program Files\Internet Explorer\iexplore.exe" "https://bimvision.eu/?smd_process_download=1&download_id=10083"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3808"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3972"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3668 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
29 528
Read events
29 199
Write events
243
Delete events
86

Modification events

(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31094039
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31094039
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
11
Suspicious files
84
Text files
89
Unknown types
17

Dropped files

PID
Process
Filename
Type
3972iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\64697A0293662D543FD74BE71E66034Bbinary
MD5:A2D794E83BAFDA0E1E245E1EEB3739F6
SHA256:D0CD13DA3EF6C47FD5A10C8D7AA2FB00DA880481001DF658D9DB2E2900C923D9
3972iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:D3B6CBEC346BF1819E241908CB932BC1
SHA256:E4485220DEC1267FD96715B5004544F14E2DE4AA313A3BFFAFCC8514968475E9
3972iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\BIMvision%202.27.7%20Setup[1].exeexecutable
MD5:64C9B3EC63AABBC25F7664C17D4B02D2
SHA256:C77C385B746EC87A6D3D00E4419AD6F44DD4F2069F7A8B3D9C7D525E6289719F
3972iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\68FAF71AF355126BCA00CE2E73CC7374_A88E46230AD93776AD6952BFE1EC0FFFbinary
MD5:815391FDBB62232D368D878913D6B5D5
SHA256:C0A4058D54EDA04FE9FF0F7FBF8D36D61776649F8F79BCDC8CEAA587BD39CCA4
3972iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C70BFA2D9DC40914ACED8BBED973B1E3_0AAC2086786434F6533EB54D1FBF050Cbinary
MD5:2CDAD32F4A8AA584DC87589BC8B0E9C5
SHA256:53FC9F38ED8DDA448F1E1BE42B64A637EEEE61B71CEB946388A1F8E922DB5AF5
3972iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\04FC23A773A43B5EED263BBAF545D686_F4C70626E6C3D591CD167C9B95203B65binary
MD5:D91F2A10BAAB90A30501C2CEF6658464
SHA256:72C76E7C0862B8A080F9CF1756D19753E7E9A9332C20B165070C08DCE2A2C14A
3972iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\68FAF71AF355126BCA00CE2E73CC7374_A88E46230AD93776AD6952BFE1EC0FFFbinary
MD5:9E01DC08C0BA0E9DFC269C56C527A9C8
SHA256:02F0B3AE645C27A26BC61CA1ECB124DFAFF0E7BEF22494CA5EE770A179A46B86
3972iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\64697A0293662D543FD74BE71E66034Bder
MD5:409A45E68351453138A0107B3ABCDF1E
SHA256:09772D19E2917C077B6F56B2A98043A074EA31D8C872420A8120803B4CB631B4
3972iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C70BFA2D9DC40914ACED8BBED973B1E3_0AAC2086786434F6533EB54D1FBF050Cbinary
MD5:B72D78FBB622C51866D1125D6B2734E5
SHA256:0714D70B7DBFFF5D210407C3F51746F894CD7CEC9BCD648502BC0AADA35B4694
3668iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{05FD41FC-E10B-11EE-AE0A-12A9866C77DE}.datbinary
MD5:50A4E0CFD8A81945940933D467744B28
SHA256:52B4B4B4B5142B26F5A922A7BB53D0F3C516B913BFBDF64ADEC61B9BCE8F7BD2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
23
TCP/UDP connections
51
DNS requests
32
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3972
iexplore.exe
GET
304
2.19.126.137:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5b0325f31ae0f9b6
unknown
unknown
3972
iexplore.exe
GET
200
95.101.54.139:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgMZM2g3fdrtRjGH%2BadZB64xxg%3D%3D
unknown
binary
503 b
unknown
3972
iexplore.exe
GET
304
2.19.126.137:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1c38e09e3428bf6c
unknown
unknown
3972
iexplore.exe
GET
200
2.17.22.194:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEQDQS2%2Fl3VvSIefHTPZGizFG
unknown
binary
1.54 Kb
unknown
3972
iexplore.exe
GET
200
2.17.22.194:80
http://subca.ocsp-certum.com/MFAwTjBMMEowSDAJBgUrDgMCGgUABBQcn6glOULIBQemtTWi1FD7IEbk4gQUVJndm%2F%2Fopw6jGZ1bvkJX3zD8jzICDzEdft3kkgIIu9he9yYrug%3D%3D
unknown
binary
1.55 Kb
unknown
3972
iexplore.exe
GET
200
2.17.22.154:80
http://h.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRLAbuY6AMy2ME5AnM9MlyLM4YhywQUPZG2zBF76%2BRmEazS0gfLqaSAczECEGmU4fHI1hR0%2BPBKiWYMVi8%3D
unknown
binary
1.46 Kb
unknown
3668
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
313 b
unknown
3668
iexplore.exe
GET
304
2.22.242.113:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a973ebecfe8ccbeb
unknown
unknown
3668
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
3668
iexplore.exe
GET
304
2.22.242.113:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b0be6f4ad90be2e5
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
3972
iexplore.exe
188.210.221.85:443
bimvision.eu
Data Space Sp. z o.o.
PL
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3668
iexplore.exe
2.19.96.49:443
www.bing.com
Akamai International B.V.
DE
unknown
3972
iexplore.exe
2.19.126.137:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3972
iexplore.exe
92.123.17.153:80
x1.c.lencr.org
AKAMAI-AS
AT
unknown
3668
iexplore.exe
2.19.96.58:443
www.bing.com
Akamai International B.V.
DE
unknown
3668
iexplore.exe
2.22.242.107:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
bimvision.eu
  • 188.210.221.85
unknown
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 2.19.96.49
  • 2.19.96.58
  • 2.19.96.72
  • 2.19.96.35
  • 2.19.96.42
  • 2.19.96.41
  • 2.19.96.66
  • 2.19.96.67
  • 2.19.96.56
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
ctldl.windowsupdate.com
  • 2.19.126.137
  • 2.19.126.163
  • 2.22.242.107
  • 2.22.242.113
  • 2.22.242.130
  • 2.22.242.112
  • 2.22.242.123
  • 2.22.242.105
  • 2.22.242.115
  • 2.22.242.114
  • 2.22.242.131
  • 2.16.100.177
  • 88.221.110.66
  • 2.16.100.155
  • 2.16.100.138
  • 2.16.100.169
  • 2.16.100.152
  • 23.32.238.219
  • 23.32.238.203
  • 23.32.238.200
  • 23.32.238.201
  • 23.32.238.210
  • 23.32.238.217
  • 23.32.238.208
  • 23.32.238.216
  • 23.32.238.218
whitelisted
x1.c.lencr.org
  • 92.123.17.153
  • 104.76.201.34
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
store.bimvision.eu
  • 87.98.242.170
unknown
r3.o.lencr.org
  • 95.101.54.139
  • 95.101.54.216
  • 2.16.202.115
  • 95.101.54.121
  • 95.101.54.122
  • 95.101.54.137
  • 95.101.54.210
  • 95.101.54.145
shared

Threats

No threats detected
No debug info