URL:

http://web.archive.org/web/20200705013449/http://demo.zeeroq.com/

Full analysis: https://app.any.run/tasks/37abc7a6-198a-48e9-997f-8d1765beca54
Verdict: Malicious activity
Analysis date: February 06, 2024, 11:28:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

98E3940F00ED30B2C37B8F48A29B6FD0

SHA1:

108135E97560E6BFB50E0C68432CD599E5C2663E

SHA256:

008653090F28903F7472763D41E918E83551E2C43643165B06A0DB9AD7481BF2

SSDEEP:

3:N1KJAQXxXJetV4+znAIKUmIK:COQhX84UntKUmIK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1392"C:\Program Files\Internet Explorer\iexplore.exe" "http://web.archive.org/web/20200705013449/http://demo.zeeroq.com/"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2736"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1392 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
20 697
Read events
20 618
Write events
73
Delete events
6

Modification events

(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
12
Text files
22
Unknown types
1

Dropped files

PID
Process
Filename
Type
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\polyfill-support[1].jstext
MD5:7FABD4610BA5D18D67BE167E2AAA5479
SHA256:403C031A5E9ADDC1081C77F0BF123456C905D116A9E814E753A4A3E8B8C19B03
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\analytics[1].jstext
MD5:CBC1B007EB7DE0B65EDA9EF00E069EBE
SHA256:A1F3D3BE0AF279C2DA371163D037A3D46569453A855CF91ACECA0F3695C57017
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\archive.min[1].csstext
MD5:09615BAFC8504B2D1BAC4D62E95D7D9F
SHA256:DA065D3CFFC8398261FF7D2F9CFED26501AEA0447586AF6154416E1CD7789824
2736iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EB2C4AB8B68FFA4B7733A9139239A396_D76DB901EE986B889F30D8CC06229E2Dbinary
MD5:040A44C000EB598968D7E553491EA17D
SHA256:6EA0DBF078E7CECD62202ECEF6FE7C4BA6F256B0CE57F814797DC43832EC88FF
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\ia-topnav.min[1].jstext
MD5:577545DEBC0E4B0EC44F7AA5ED62CF3F
SHA256:65C9B0F909C6238799BBB9033CB993E9F0EB48FEF88B763C1356C3F59EB67799
2736iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:2043428A49C3CCB7AA2B7125B374CD35
SHA256:B8277CD2EE96B55763131F82E51099C36C5E746BDA18B275FE6481E2B5BF9DB1
2736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\archive.min[1].jstext
MD5:D52341692B1AB6A7332743F52FC41B98
SHA256:25F349DD14D877EA596A1D3171C7C300514B39989C6EF4EF511904A77F6D34CA
2736iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771binary
MD5:D4631B4724B80ECCC5792DDCFD886A55
SHA256:A26A4210D5F424445F1318CFF2DD5C5F4DD937AAB03824469E8EA1971CC45D1C
2736iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EB2C4AB8B68FFA4B7733A9139239A396_D76DB901EE986B889F30D8CC06229E2Dbinary
MD5:B8DF255D3EB5601AAC3797B45E0E5D84
SHA256:B006090D2372DF86CC6FAF373688B4A7EC3B84476E9453C80E66646D467AF723
2736iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771der
MD5:F67437658C15B3FA18C128E00779DF37
SHA256:AC17B9BAA0C3B7714391719A7307893399A0AFEBBE69C61BC4A5807DBC449B2F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
23
TCP/UDP connections
39
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2736
iexplore.exe
GET
403
207.241.237.3:80
http://web.archive.org/web/20200705013449/http://demo.zeeroq.com/
unknown
html
31.8 Kb
unknown
2736
iexplore.exe
GET
200
207.241.224.2:80
http://archive.org/components/npm/@webcomponents/webcomponentsjs/webcomponents-bundle.js?v=759dc97d
unknown
text
40.3 Kb
unknown
2736
iexplore.exe
GET
200
207.241.224.2:80
http://archive.org/includes/analytics.js?v=759dc97d
unknown
text
5.01 Kb
unknown
2736
iexplore.exe
GET
200
207.241.224.2:80
http://archive.org/components/npm/lit/polyfill-support.js?v=759dc97d
unknown
text
1.49 Kb
unknown
2736
iexplore.exe
GET
200
207.241.224.2:80
http://archive.org/includes/build/css/archive.min.css?v=759dc97d
unknown
text
67.4 Kb
unknown
2736
iexplore.exe
GET
200
207.241.224.2:80
http://archive.org/includes/build/js/archive.min.js?v=759dc97d
unknown
text
260 Kb
unknown
2736
iexplore.exe
GET
200
207.241.224.2:80
http://archive.org/includes/build/js/ia-topnav.min.js?v=759dc97d
unknown
text
11.7 Kb
unknown
2736
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?dd957a9af52c2916
unknown
unknown
2736
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?673c0ed9526ed36f
unknown
unknown
2736
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4dc155ab4f870581
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2736
iexplore.exe
207.241.237.3:80
web.archive.org
INTERNET-ARCHIVE
US
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2736
iexplore.exe
207.241.224.2:80
archive.org
INTERNET-ARCHIVE
US
malicious
2736
iexplore.exe
207.241.239.242:443
polyfill.archive.org
INTERNET-ARCHIVE
US
unknown
2736
iexplore.exe
207.241.237.2:443
web-static.archive.org
INTERNET-ARCHIVE
US
unknown
2736
iexplore.exe
207.241.224.2:443
archive.org
INTERNET-ARCHIVE
US
malicious
2736
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2736
iexplore.exe
192.124.249.41:80
ocsp.godaddy.com
SUCURI-SEC
US
unknown

DNS requests

Domain
IP
Reputation
web.archive.org
  • 207.241.237.3
whitelisted
polyfill.archive.org
  • 207.241.239.242
unknown
archive.org
  • 207.241.224.2
whitelisted
web-static.archive.org
  • 207.241.237.2
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.godaddy.com
  • 192.124.249.41
  • 192.124.249.36
  • 192.124.249.23
  • 192.124.249.24
  • 192.124.249.22
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 23.37.226.97
  • 23.37.226.90
  • 23.37.226.106
  • 23.37.226.105
  • 23.53.43.153
  • 23.37.226.88
  • 23.53.43.121
whitelisted
analytics.archive.org
  • 207.241.225.195
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info