Analysis Report https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten/formulieren/2021/01/21/formulier-eigen-verklaring-avondklok

Overview

General Information

Sample URL: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten/formulieren/2021/01/21/formulier-eigen-verklaring-avondklok
Analysis ID: 343643

Most interesting Screenshot:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Compliance:

barindex
Uses new MSVCR Dlls
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior
Uses secure TLS version for HTTPS connections
Source: unknown HTTPS traffic detected: 178.22.85.6:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.6:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.94.196.189:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.94.196.189:443 -> 192.168.2.4:49737 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.6:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.97:443 -> 192.168.2.4:49767 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.97:443 -> 192.168.2.4:49768 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.97:443 -> 192.168.2.4:49770 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.97:443 -> 192.168.2.4:49771 version: TLS 1.2
Source: ministerie-van-justitie-en-veiligheid[1].htm.2.dr String found in binary or memory: <a href="https://www.facebook.com/MinisterievanJustitieenVeiligheid/" class="facebook"> equals www.facebook.com (Facebook)
Source: ministerie-van-justitie-en-veiligheid[1].htm.2.dr String found in binary or memory: <a href="https://www.linkedin.com/company/ministerie-van-justitie-en-veiligheid-/" class="linkedin"> equals www.linkedin.com (Linkedin)
Source: ministerie-van-justitie-en-veiligheid[1].htm.2.dr String found in binary or memory: <a href="https://www.youtube.com/user/MinisterieJustitie" class="youtube"> equals www.youtube.com (Youtube)
Source: onderwerpen[1].htm.2.dr String found in binary or memory: <meta property="og:image" content="https://www.rijksoverheid.nl/binaries/small/content/gallery/rijksoverheid/channel-afbeeldingen/logos/facebook.png"/> equals www.facebook.com (Facebook)
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: <meta property="og:image" content="https://www.rijksoverheid.nl/binaries/small/content/gallery/rijksoverheid/channel-afbeeldingen/logos/facebook.png"/> equals www.facebook.com (Facebook)
Source: unknown DNS traffic detected: queries for: www.rijksoverheid.nl
Source: piwik[1].js.2.dr String found in binary or memory: http://bestiejs.github.io/json3
Source: ankiebroekersknol_1.jpg_1920[1].jpg.2.dr, sander-dekker-2020-1[1].jpg.2.dr String found in binary or memory: http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/
Source: piwik[1].js.2.dr String found in binary or memory: http://kit.mit-license.org
Source: ankiebroekersknol_1.jpg_1920[1].jpg.2.dr, sander-dekker-2020-1[1].jpg.2.dr String found in binary or memory: http://ns.useplus.org/ldf/xmp/1.0/
Source: contact[1].htm.2.dr String found in binary or memory: http://wetten.overheid.nl/BWBR0019219
Source: contact[1].htm.2.dr String found in binary or memory: https://autoriteitpersoonsgegevens.nl/nl/contact-met-de-autoriteit-persoonsgegevens/tip-ons
Source: ministerie-van-justitie-en-veiligheid[1].htm.2.dr String found in binary or memory: https://crisis.nl/nl-alert
Source: ministerie-van-justitie-en-veiligheid[1].htm.2.dr String found in binary or memory: https://feeds.rijksoverheid.nl/ministeries/ministerie-van-justitie-en-veiligheid/nieuws.rss
Source: documenten[1].htm.2.dr String found in binary or memory: https://feeds.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten.rss
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: https://feeds.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/nieuws.rss
Source: piwik[1].js.2.dr String found in binary or memory: https://github.com/piwik/piwik/blob/master/js/piwik.js
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: https://ind.nl/Paginas/Coronavirus.aspx
Source: ministerie-van-justitie-en-veiligheid[1].htm.2.dr String found in binary or memory: https://magazines.rijksoverheid.nl/jenv/jenvmagazine
Source: rop-survey-bar-and-ergo.min[1].js.2.dr String found in binary or memory: https://onderzoek.platformrijksoverheid.nl/CnTMVC/pub/108108108pre/cnt108108108pre.js
Source: piwik[1].js.2.dr String found in binary or memory: https://opensource.org/licenses/BSD-3-Clause
Source: ministerie-van-justitie-en-veiligheid[1].htm.2.dr String found in binary or memory: https://twitter.com/ministerieJenV
Source: avondklok[1].htm.2.dr String found in binary or memory: https://we.tl/t-1RCY6GmWbX
Source: contact[1].htm.2.dr String found in binary or memory: https://wetten.overheid.nl/BWBR0007376/2020-01-01
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: https://www.aandachtvoorelkaar.nl/
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: https://www.ecdc.europa.eu/en/coronavirus
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: https://www.gobiernodireino.nl/
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: https://www.gobiernudireino.nl/
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: https://www.government.nl
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: https://www.government.nl/topics/c/coronavirus-covid-19
Source: ministerie-van-justitie-en-veiligheid[1].htm.2.dr String found in binary or memory: https://www.instagram.com/ministeriejenv/
Source: contact[1].htm.2.dr String found in binary or memory: https://www.kpnteletolk.nl/
Source: contact[1].htm.2.dr String found in binary or memory: https://www.kvk.nl/coronaloket/
Source: ministerie-van-justitie-en-veiligheid[1].htm.2.dr String found in binary or memory: https://www.linkedin.com/company/ministerie-van-justitie-en-veiligheid-/
Source: contact[1].htm.2.dr String found in binary or memory: https://www.overheid.nl/contact/e-mailgedragslijn-voor-overheden
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.Root
Source: KEKSHZAX.htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/
Source: abonneren[1].htm.2.dr, ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/abonneren
Source: ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/abonneren/ministerie-van-justitie-en-veiligheidd.nl/
Source: ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/abonneren8Abonneren
Source: KEKSHZAX.htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/actueel/nieuwsbrieven/regeringsnieuws
Source: imagestore.dat.2.dr String found in binary or memory: https://www.rijksoverheid.nl/binaries/content/assets/rijksoverheid/iconen/touch-icon.png
Source: coronavirus-covid-19[1].htm.2.dr, onderwerpen[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/binaries/small/content/gallery/rijksoverheid/channel-afbeeldingen/logos
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.nl/contact
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.nl/contact4Contact
Source: ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/contactes/ministerie-van-justitie-en-veiligheid
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.nl/dInformatie
Source: abonneren[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/documenten
Source: formulier-eigen-verklaring-avondklok[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/documenten/formulieren/2021/01/21/formulier-eigen-verklaring-avondklok
Source: formulier-voor-de-avondklok-downloaden-en-meenemen[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/documenten/formulieren/2021/01/21/formulier-voor-de-avondklok-downloade
Source: formulier-werkgeversverklaring-avondklok[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/documenten/formulieren/2021/01/21/formulier-werkgeversverklaring-avondk
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/documenten?trefwoord=coronavirus&startdatum=&einddatum=&onderdeel=Alle
Source: contact[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/ministeries
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.nl/ministeries/minister2
Source: ministerie-van-justitie-en-veiligheid[1].htm.2.dr, ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/ministeries/ministerie-van-justitie-en-veiligheid
Source: ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/ministeries/ministerie-van-justitie-en-veiligheideren/2021/01/21/formul
Source: ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/ministeries/ministerie-van-justitie-en-veiligheidpMinisterie
Source: ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/nderwerpen/coronavirus-covid-19/documenten/formulieren/2021/01/21/formu
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr, ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-c
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-cRoot
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-coverheid.nl/contact4Contact
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr, ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/avondklok
Source: ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/avondklok/formulieren/2021/01/21/formu
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/avondklokfAvondklok
Source: documenten[1].htm.2.dr, ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten
Source: ~DFA9C3FD9DAD52A256.TMP.1.dr, formulier-werkgeversverklaring-avondklok[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten/formulieren/2021/01/21/form
Source: documenten[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten?pagina=2
Source: documenten[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten?pagina=3
Source: documenten[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten?pagina=4
Source: documenten[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten?pagina=5
Source: documenten[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten?pagina=6
Source: documenten[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten?sorteren%2Dop=relevantie
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documentenjOnderwerpen
Source: {6701F4C6-5EE8-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19NCoronavirus
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/overheidscommunicatie/nederlandse-gebarentaal
Source: contact[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpen/privacy-en-persoonsgegevens/burgerservicenummer-bsn
Source: ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpenoronavirus-covid-19/documenten/formulieren/2021/01/21/formul
Source: ~DFA9C3FD9DAD52A256.TMP.1.dr String found in binary or memory: https://www.rijksoverheid.nl/onderwerpenr
Source: contact[1].htm.2.dr String found in binary or memory: https://www.rijksoverheid.nl/over-rijksoverheid-nl
Source: coronavirus-covid-19[1].htm.2.dr String found in binary or memory: https://www.who.int/emergencies/diseases/novel-coronavirus-2019
Source: ministerie-van-justitie-en-veiligheid[1].htm.2.dr String found in binary or memory: https://www.youtube.com/user/MinisterieJustitie
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49762 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49773 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49766
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49762
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49761
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49761 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown HTTPS traffic detected: 178.22.85.6:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.6:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.94.196.189:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.94.196.189:443 -> 192.168.2.4:49737 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.6:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.97:443 -> 192.168.2.4:49767 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.97:443 -> 192.168.2.4:49768 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.97:443 -> 192.168.2.4:49770 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.22.85.97:443 -> 192.168.2.4:49771 version: TLS 1.2
Source: classification engine Classification label: clean0.win@3/98@5/4
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{6701F4C4-5EE8-11EB-90EB-ECF4BBEA1588}.dat Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Temp\~DFF63FF4DD2D95D176.TMP Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File read: C:\Users\desktop.ini Jump to behavior
Source: unknown Process created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
Source: unknown Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6864 CREDAT:17410 /prefetch:2
Source: C:\Program Files\internet explorer\iexplore.exe Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6864 CREDAT:17410 /prefetch:2 Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe Automated click: Ok
Source: C:\Program Files\internet explorer\iexplore.exe Automated click: Ok
Source: C:\Program Files\internet explorer\iexplore.exe Automated click: Ok
Source: C:\Program Files\internet explorer\iexplore.exe Automated click: Ok
Source: C:\Program Files\internet explorer\iexplore.exe Automated click: Ok
Source: C:\Program Files\internet explorer\iexplore.exe Automated click: Ok
Source: C:\Program Files\internet explorer\iexplore.exe Automated click: Ok
Source: C:\Program Files\internet explorer\iexplore.exe Automated click: Ok
Source: C:\Program Files\internet explorer\iexplore.exe Automated click: Ok
Source: C:\Program Files\internet explorer\iexplore.exe Automated click: Ok
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 343643 URL: https://www.rijksoverheid.n... Startdate: 25/01/2021 Architecture: WINDOWS Score: 0 11 www.rijksoverheid.nl 2->11 13 rijksoverheid.nl 2->13 6 iexplore.exe 1 58 2->6         started        process3 process4 8 iexplore.exe 3 134 6->8         started        dnsIp5 15 rijksoverheid.nl 178.22.85.6, 443, 49733, 49734 PROLOCATIONTransitpolicypref100NL Netherlands 8->15 17 www.rovid.nl 178.22.85.97, 443, 49767, 49768 PROLOCATIONTransitpolicypref100NL Netherlands 8->17 19 3 other IPs or domains 8->19
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Contacted Public IPs

IP Domain Country Flag ASN ASN Name Malicious
13.94.196.189
unknown United States
8075 MICROSOFT-CORP-MSN-AS-BLOCKUS false
78.31.116.148
unknown Netherlands
12859 NL-BITBITBVNL false
178.22.85.97
unknown Netherlands
41887 PROLOCATIONTransitpolicypref100NL false
178.22.85.6
unknown Netherlands
41887 PROLOCATIONTransitpolicypref100NL false

Contacted Domains

Name IP Active
onderzoek.platformrijksoverheid.nl 78.31.116.148 true
www.rovid.nl 178.22.85.97 true
statistiek.rijksoverheid.nl 13.94.196.189 true
rijksoverheid.nl 178.22.85.6 true
www.rijksoverheid.nl unknown unknown

Contacted URLs

Name Malicious Antivirus Detection Reputation
https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten false
    high
    https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten/formulieren/2021/01/21/formulier-voor-de-avondklok-downloaden-en-meenemen false
      high
      https://www.rijksoverheid.nl/onderwerpen false
        high
        https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten/formulieren/2021/01/21/formulier-werkgeversverklaring-avondklok false
          high
          https://www.rijksoverheid.nl/ministeries/ministerie-van-justitie-en-veiligheid false
            high
            https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten/formulieren/2021/01/21/formulier-eigen-verklaring-avondklok#content-wrapper false
              high
              https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/avondklok false
                high
                https://www.rijksoverheid.nl/contact false
                  high
                  https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19 false
                    high
                    https://www.rijksoverheid.nl/ false
                      high
                      https://www.rijksoverheid.nl/onderwerpen/coronavirus-covid-19/documenten/formulieren/2021/01/21/formulier-eigen-verklaring-avondklok false
                        high
                        https://www.rijksoverheid.nl/abonneren false
                          high