Loading content, please wait...
This report is generated from a file or URL submitted to this webservice on March 5th 2020 11:03:34 (UTC) and action script Default browser analysis
Guest System: Windows 7 64 bit, Professional, 6.1 (build 7601), Service Pack 1
Report generated by
Falcon Sandbox v8.30 © Hybrid Analysis
Not all malicious and suspicious indicators are displayed. Get your own cloud service or the full version to view all details.
No relevant data available.
Loading content, please wait...
Tip: Click an analysed process below to view more details.
Analysed 3 processes in total.
| Domain | Address | Registrar | Country |
|---|---|---|---|
|
ajax.googleapis.com
OSINT |
216.58.193.138
TTL: 299 |
MarkMonitor, Inc. |
United States |
|
fonts.googleapis.com
OSINT |
172.217.12.74
TTL: 188 |
MarkMonitor, Inc. |
United States |
|
goldesel.to
OSINT |
104.27.190.171
TTL: 231 |
- |
United States |
|
isrg.trustid.ocsp.identrust.com
OSINT |
23.46.48.225
TTL: 16 |
- |
United States |
|
ns-dnstest.spyoff.com
OSINT |
159.89.109.89
TTL: 299 |
PSI-USA, Inc. dba Domain Robot |
United States |
|
ocsp.int-x3.letsencrypt.org
OSINT |
23.46.48.202
TTL: 2634 |
eNom, Inc.
Organization: Internet Security Research Group Name Server: A9-67.AKAM.NET Creation Date: Mon, 07 Jul 2014 19:54:04 GMT |
United States |
|
ocsp.pki.goog
OSINT |
172.217.4.67
TTL: 224 |
- |
United States |
|
www.popads.media
OSINT |
104.28.31.4
TTL: 299 |
GoDaddy.com, LLC
Organization: Domains By Proxy, LLC Name Server: betty.ns.cloudflare.com Creation Date: Sun, 25 Jun 2017 11:42:42 GMT |
United States |
| IP Address | Port/Protocol | Associated Process | Details |
|---|---|---|---|
|
104.27.190.171 |
80
TCP |
iexplore.exe PID: 3832 |
United States |
|
104.27.190.171 |
443
TCP |
iexplore.exe PID: 3832 |
United States |
|
216.58.192.234 |
443
TCP |
iexplore.exe PID: 3832 |
United States |
|
172.217.9.74 |
443
TCP |
iexplore.exe PID: 3832 |
United States |
|
104.28.30.4 |
443
TCP |
iexplore.exe PID: 3832 |
United States |
|
172.217.4.67 |
80
TCP |
iexplore.exe PID: 3832 |
United States |
|
159.89.109.89 |
443
TCP |
iexplore.exe PID: 3832 |
United States |
|
23.46.48.225 |
80
TCP |
iexplore.exe PID: 3832 |
United States |
|
184.84.68.43 |
443
TCP |
iexplore.exe PID: 1488 |
United States |
| Endpoint | Request | URL | |
|---|---|---|---|
| 104.27.190.171:80 (goldesel.to) | GET | goldesel.to/ | GET / HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
Accept-Encoding: gzip, deflate
Host: goldesel.to
DNT: 1
Connection: Keep-Alive More Details |
| 172.217.4.67:80 (ocsp.pki.goog) | GET | ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | GET /gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.pki.goog More Details |
| 172.217.4.67:80 (ocsp.pki.goog) | GET | ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQCSaJP2bCz9oAgAAAAALnFI | GET /gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQCSaJP2bCz9oAgAAAAALnFI HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.pki.goog More Details |
| 23.46.48.225:80 (isrg.trustid.ocsp.identrust.com) | GET | isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNq... | GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: isrg.trustid.ocsp.identrust.com More Details |
| Event | Category | Description | SID |
|---|---|---|---|
| local -> 8.8.8.8:53 (UDP) | Potentially Bad Traffic | ET DNS Query for .to TLD | 2027757 %} |
Displaying 50 extracted file(s). The remaining 17 file(s) are available in the full version and XML/JSON reports.