URL:

emailmarketing.locaweb.com.br/accounts/54473/messages/662/clicks/17858/265?envelope_id\=553

Full analysis: https://app.any.run/tasks/2dab2e74-84b3-485d-8a70-5693e693a098
Verdict: Malicious activity
Analysis date: February 29, 2024, 11:03:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

B213428C46E9B84F8983C63F54831381

SHA1:

EF517D2215875A01AC46CA3CE4B8F6F3EB949AFD

SHA256:

F40CAB6868E4545195A6F6F5B02153083C72E32CA4A8B0F7ACC340FBD5651A1F

SSDEEP:

3:tEMT4C9FArYGKQtaaNCZNUSFXTQLAEqwW:rDAcRQtn0N5cLAjwW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MicrosoftEdgeSetup.exe (PID: 2064)
      • MicrosoftEdgeUpdateSetup.exe (PID: 1860)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MicrosoftEdgeSetup.exe (PID: 2064)
      • MicrosoftEdgeUpdateSetup.exe (PID: 1860)
    • Process drops legitimate windows executable

      • MicrosoftEdgeSetup.exe (PID: 2064)
      • MicrosoftEdgeUpdateSetup.exe (PID: 1860)
      • MicrosoftEdgeUpdate.exe (PID: 1572)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 3164)
      • MicrosoftEdgeUpdateSetup.exe (PID: 1860)
      • MicrosoftEdgeUpdate.exe (PID: 1572)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 1572)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 1572)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 3324)
    • Creates a software uninstall entry

      • MicrosoftEdgeUpdate.exe (PID: 1572)
    • Reads the Internet Settings

      • MicrosoftEdgeUpdate.exe (PID: 1340)
    • Executes as Windows Service

      • MicrosoftEdgeUpdate.exe (PID: 2804)
    • Reads settings of System Certificates

      • MicrosoftEdgeUpdate.exe (PID: 1340)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 1340)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 1340)
  • INFO

    • Checks supported languages

      • MicrosoftEdgeSetup.exe (PID: 2064)
      • MicrosoftEdgeUpdate.exe (PID: 3164)
      • MicrosoftEdgeUpdateSetup.exe (PID: 1860)
      • MicrosoftEdgeUpdate.exe (PID: 1572)
      • MicrosoftEdgeUpdate.exe (PID: 2564)
      • MicrosoftEdgeUpdate.exe (PID: 3324)
      • MicrosoftEdgeUpdate.exe (PID: 1340)
      • MicrosoftEdgeUpdate.exe (PID: 2240)
      • MicrosoftEdgeUpdate.exe (PID: 2804)
    • Application launched itself

      • iexplore.exe (PID: 3668)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 3668)
    • The process uses the downloaded file

      • MicrosoftEdgeSetup.exe (PID: 2064)
      • iexplore.exe (PID: 3668)
    • Reads the computer name

      • MicrosoftEdgeUpdate.exe (PID: 3164)
      • MicrosoftEdgeUpdate.exe (PID: 1572)
      • MicrosoftEdgeUpdate.exe (PID: 3324)
      • MicrosoftEdgeUpdate.exe (PID: 2564)
      • MicrosoftEdgeUpdate.exe (PID: 1340)
      • MicrosoftEdgeUpdate.exe (PID: 2240)
      • MicrosoftEdgeUpdate.exe (PID: 2804)
    • Create files in a temporary directory

      • MicrosoftEdgeSetup.exe (PID: 2064)
      • MicrosoftEdgeUpdate.exe (PID: 3164)
      • MicrosoftEdgeUpdate.exe (PID: 1340)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 3164)
    • Creates files in the program directory

      • MicrosoftEdgeUpdateSetup.exe (PID: 1860)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 1340)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 1340)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 1340)
      • MicrosoftEdgeUpdate.exe (PID: 2804)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
11
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe microsoftedgesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdatesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
1340"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xODUuMTciIHNoZWxsX3ZlcnNpb249IjEuMy4xODUuMTciIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7Q0U5NUUxRUEtQjgxNi00OTJGLUJGMTYtQjU3RDdBQUQ2N0VBfSIgaW5zdGFsbHNvdXJjZT0idGFnZ2VkbWkiIHJlcXVlc3RpZD0iezVENDQ0QzVBLTkyQzItNDEzNC1CRDA0LTg3OUJFMzkzODYzNn0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgbG9naWNhbF9jcHVzPSI0IiBwaHlzbWVtb3J5PSIzIiBkaXNrX3R5cGU9IjAiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjI0NTQ2IiBzcD0iU2VydmljZSBQYWNrIDEiIGFyY2g9Ing4NiIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSImcXVvdDtyNDUydDErazJUZ3EvSFh6anZGTkJSaG9wQldSOXNialh4cWVVREg5dVgwPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGM0M0RkUwMC1FRkQ1LTQwM0ItOTU2OS0zOThBMjBGMUJBNEF9IiB2ZXJzaW9uPSIxLjMuMTc1LjI5IiBuZXh0dmVyc2lvbj0iMS4zLjE4NS4xNyIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTU5ODM2NTIzNDMiIGluc3RhbGxfdGltZV9tcz0iNzY1Ii8-PC9hcHA-PC9yZXF1ZXN0PgC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.17
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1572"C:\Program Files\Microsoft\Temp\EU6164.tmp\MicrosoftEdgeUpdate.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installelevatedC:\Program Files\Microsoft\Temp\EU6164.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.17
Modules
Images
c:\program files\microsoft\temp\eu6164.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1860"C:\Users\admin\AppData\Local\Temp\EU5CE0.tmp\MicrosoftEdgeUpdateSetup.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\EU5CE0.tmp\MicrosoftEdgeUpdateSetup.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.185.17
Modules
Images
c:\users\admin\appdata\local\temp\eu5ce0.tmp\microsoftedgeupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2064"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\MicrosoftEdgeSetup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\MicrosoftEdgeSetup.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.185.17
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\microsoftedgesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2240"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0" /installsource taggedmi /sessionid "{CE95E1EA-B816-492F-BF16-B57D7AAD67EA}"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.17
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2564"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvcC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.17
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2804"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svcC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.17
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3164C:\Users\admin\AppData\Local\Temp\EU5CE0.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&usagestats=0"C:\Users\admin\AppData\Local\Temp\EU5CE0.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.17
Modules
Images
c:\users\admin\appdata\local\temp\eu5ce0.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3324"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.185.17
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3348"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3668 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
35 774
Read events
31 243
Write events
4 373
Delete events
158

Modification events

(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31091454
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31091454
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3668) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
33
Suspicious files
5
Text files
5
Unknown types
4

Dropped files

PID
Process
Filename
Type
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\265[1].htmhtml
MD5:CD2E0E43980A00FB6A2742D3AFD803B8
SHA256:BD9DF047D51943ACC4BC6CF55D88EDB5B6785A53337EE2A0F74DD521AEDDE87D
3348iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_96EEC010953ED454BBCDFA69FC071E7Cbinary
MD5:6ABA88AD45191700553E77E0586A76FA
SHA256:874A94098354A7D15086D73651002292A8156B2C784D28CF073A9A2DCBE983BE
3348iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_96EEC010953ED454BBCDFA69FC071E7Cder
MD5:AC7B53012893FEC7C41AA829E64FE508
SHA256:D7276A92B90698CAE92EA7220BB31972B94A650D24CB94CFE63D81185FCB2642
3348iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:E84AE45F852974A26D5594186DF7BEE8
SHA256:DEB6DA8CA5A71B6424AF466F14A7B6A4CE8224FA180CC545443648FE65BBF4E6
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\error[1].csstext
MD5:C37F174036CF5C3CE4D986465CB42E83
SHA256:32036BAD26E8E22A5EAE0FB079C0271F3BDFE83E420E65DCAB5CA4AD6AAC0969
3348iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E573CDF4C6D731D56A665145182FD759_1D978D5EA8275AA72D1BFCD66AF4A751der
MD5:005332AD6DE8AEB10071BD21DBBA54ED
SHA256:B722616C594A9C659A87D2C72AC3B6F335573BFBF015B425DD0F0D1857FA98FC
3348iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E573CDF4C6D731D56A665145182FD759_1D978D5EA8275AA72D1BFCD66AF4A751binary
MD5:DA97C5DDCC88B6CB94A8FBCBFAFD8AA4
SHA256:9DDB35D03B6ACD819A191A83D03A98AD92A89BB70F167BF599CAB3C88E230451
3348iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\3NXC1F88.txttext
MD5:91DD7668F4D979FC9941983F622009EB
SHA256:07FA72CDF75296C073CBCBC950C322D4EEF2E306E2A004EE01AE45BA87AC7CBC
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery-3.6.4.min[1].jstext
MD5:641DD14370106E992D352166F5A07E99
SHA256:A0FE8723DCF55DA64D06B25446D0A8513E52527C45AFCB37073465F9C6F352AF
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\OpenSans-Bold-webfont[1].ttfttf
MD5:B0DBBE03FA8B4030610973E2FEA5D232
SHA256:B6CE56EE32C81DDFF0F724F95BF0347F9E7A886496BEDDBCC8F3CD2FA7042971
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
54
DNS requests
27
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3348
iexplore.exe
GET
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
unknown
3348
iexplore.exe
GET
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAHWlVhJ1rvbwVVZSZDShpE%3D
unknown
unknown
3668
iexplore.exe
GET
304
23.32.238.227:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?70b4a85d87201c80
unknown
unknown
3668
iexplore.exe
GET
304
23.32.238.227:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?18014fff35250a83
unknown
unknown
3668
iexplore.exe
GET
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
unknown
3348
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
binary
471 b
unknown
3348
iexplore.exe
GET
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
3348
iexplore.exe
GET
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
unknown
3348
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
unknown
856
svchost.exe
GET
23.48.23.56:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/d87a3bbd-7fe5-4ec3-b806-293cca78b363?P1=1709809420&P2=404&P3=2&P4=FYr0QuE6cNOGU3unn%2faUQykUeN4k%2fcD2UhVs%2bco3OqfsOi3OJB2HTCHj6bhyMvnkT%2bzPZ%2fiIkeU2EvqEh10wng%3d%3d
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3348
iexplore.exe
186.202.135.207:80
emailmarketing.locaweb.com.br
Locaweb Servicos de Internet SA
BR
unknown
3348
iexplore.exe
186.202.135.207:443
emailmarketing.locaweb.com.br
Locaweb Servicos de Internet SA
BR
unknown
3348
iexplore.exe
23.32.238.227:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3348
iexplore.exe
104.18.21.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
3348
iexplore.exe
162.125.72.18:443
www.dropbox.com
DROPBOX
US
unknown
3348
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3348
iexplore.exe
18.239.18.27:443
assets.dropbox.com
US
unknown

DNS requests

Domain
IP
Reputation
emailmarketing.locaweb.com.br
  • 186.202.135.207
malicious
ctldl.windowsupdate.com
  • 23.32.238.227
  • 23.32.238.168
  • 23.32.238.241
  • 23.32.238.242
  • 23.32.238.243
  • 23.32.238.240
  • 23.32.238.233
  • 23.32.238.232
  • 23.32.238.235
  • 178.79.238.128
whitelisted
ocsp.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
www.dropbox.com
  • 162.125.72.18
shared
ocsp.digicert.com
  • 192.229.221.95
whitelisted
cfl.dropboxstatic.com
  • 104.16.100.29
  • 104.16.99.29
shared
assets.dropbox.com
  • 18.239.18.27
  • 18.239.18.75
  • 18.239.18.102
  • 18.239.18.9
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 92.123.104.38
  • 92.123.104.45
  • 92.123.104.49
  • 92.123.104.37
  • 92.123.104.46
  • 92.123.104.39
  • 92.123.104.50
  • 92.123.104.35
  • 92.123.104.41
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted

Threats

PID
Process
Class
Message
3348
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY Dropbox.com Offsite File Backup in Use
856
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info