Windows Analysis Report
http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUBbnirb_9br0X5shiNiwX4VUZDcx4TYOb3sM2wpz2yfKg1MgxZ1YJL-O2Cgk4bYCNefiWCiFF6AWzX5TW-0MLSz0G_WzeGmbrF2OdN

Overview

General Information

Sample URL: http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUB
Analysis ID: 1431856
Infos:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.6:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.6:49708 version: TLS 1.2
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic DNS traffic detected: DNS query: google.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: unknown Network traffic detected: HTTP traffic on port 49674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49698 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49698
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49718
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 49718 -> 443
Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.6:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.6:49708 version: TLS 1.2
Source: classification engine Classification label: clean0.win@20/0@4/3
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1692,i,17621815830497467087,13166226885346699693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUBbnirb_9br0X5shiNiwX4VUZDcx4TYOb3sM2wpz2yfKg1MgxZ1YJL-O2Cgk4bYCNefiWCiFF6AWzX5TW-0MLSz0G_WzeGmbrF2OdN0t4ZaqmVPDCNASJelVCumDRTBmHv8sIc2WmxIRpA8qkLj06C6cWMpqHsEj6IYHXdzG6zw8bE0uRgAFYaztmMGMfBs5Ou90QtGia25xnEYig2RimxQAVmP4oxXMlmRiYxndT0-RDxmvx3k_BuoWxzTrt35UuefUC2PNrEt7DqDzvymqQE8az3WUFcrdKVEpRTdUH4zq-nCBg0JhgBMYtqLppPzNE5vLHgHwvB5J4iGlrnsWA2iGo-KimvthNAA96Mjj0vhzXJq6aZZWcezookCdv6cRGm76TFE-eBVXjDcNWZ7pTeVhlZVBE-nWHFXCW5epYz-roVt5e_k5gOZmbC1Bv1z1RMTAkxNK3N4YKGvvwCV3dmuNIncEfrV6CcQrEh_k5sZC-9S7Jgk7ifHL0ufBo6awzBPiJsKSokti992kEAPGlVwMxbWJNcjKuJs48fsvKjXzK1lPPLeIx_w3cfpg11UXMUN4_WTXdDqXSCHVDy0gQmAlEOodYXzVL27FKnQEDckRfNx_GFF1zc1PYklLH3ygh_zwV5b1zh_JD4Q2xICJySXrTX45B_ZAjPhU2FM8IsVbeHGqNNdLqW7xePm48sx8ni2LO4ZfADTbQfDhPASjRLJ5-RvfeQZIj2SYlR&state=18471666-cc8e-484a-a9f8-e361977136bc&session_state=3961325a-3a84-4a62-86ce-1defb25719b4#"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1692,i,17621815830497467087,13166226885346699693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs