| URL: | https://doxbin.org/upload/hazetomika |
| Full analysis: | https://app.any.run/tasks/32e0e98a-932a-4243-84f6-60e3e57f10ef |
| Verdict: | Malicious activity |
| Analysis date: | July 24, 2024, 06:53:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 2E0CF77488BC5B21046E0343B4184070 |
| SHA1: | 7812D3888FC135BD9B0B88F5ECF2D5B2F9E3850E |
| SHA256: | 019A6165F2B85C169A4E72D4CB3F2533325C91D6BF7512C06080F45CD661F672 |
| SSDEEP: | 3:N8SxXCKKI8n:2SRJK5n |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2980 | "C:\Program Files\Internet Explorer\iexplore.exe" "https://doxbin.org/upload/hazetomika" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3676 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2980 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (2980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (2980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: 571016160 | |||
| (PID) Process: | (2980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31120790 | |||
| (PID) Process: | (2980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 871174910 | |||
| (PID) Process: | (2980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31120790 | |||
| (PID) Process: | (2980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3676 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:822467B728B7A66B081C91795373789A | SHA256:AF2343382B88335EEA72251AD84949E244FF54B6995063E24459A7216E9576B9 | |||
| 3676 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:3A34778F7A19798653A34DC3EB9000FD | SHA256:25BD6685A075592F504753E04959545AF8A54AF8654D8312149C5414949CFF35 | |||
| 3676 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0924CDE532BA7BBE11F890289679EF70 | binary | |
MD5:56E03C4DC8C68059D922B32181D91CA0 | SHA256:690929B32585E485D648EBE5462CA616679985AEDE57A197C54A5F95974A53AA | |||
| 3676 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\GYG9S7DM.txt | text | |
MD5:8867D31C3DA11D1DC7C88CD4A0CA3435 | SHA256:83512589E4265F779699C13B18447D45D7FA503C2CC440399A9A486DA9400DB8 | |||
| 3676 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\show[1].css | binary | |
MD5:1998DB9955902842A530598937AD7A54 | SHA256:36321B47B6FA3F5723ECEDA17D3FC1ADA6D39A7FE2BC989D18B9637AC4ACC8F4 | |||
| 3676 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\5AR33JCB.txt | text | |
MD5:47B70C29447FDF2736F6657D9A29A784 | SHA256:A06A6CB17B0DF985BF3BF1438D527351EF4EC8A84AE9896B227B610355ED5396 | |||
| 3676 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\hazetomika[1].htm | html | |
MD5:2ABB26261830183E5D7EDB8A4B6D6B17 | SHA256:D5BFF4FDC3899189752A10EDD24C14C22B805063DFF9BA650C2FA7139BE8D7D4 | |||
| 3676 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\doxbin[1].css | binary | |
MD5:692E3F5286736533CD50B56E9A1BD02A | SHA256:65544122DFB0C08EF3067BF94EE2C50B9856CDDC5066CF000A2D1AA3541A0630 | |||
| 3676 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:922429FA9144F5B86E3268056776C151 | SHA256:B271382F87B8B650F0D2FF39C6A9A84E887B578D866987256DC47C39813B64F3 | |||
| 3676 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\app[1].css | binary | |
MD5:F29FA1DF1F0AE27CF286B41A5346DEAE | SHA256:87FFBCD9B460F64AA0C4FFFF82E85A3D1C498E70A33E9036961A15313A744D3E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3676 | iexplore.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b006811c9d87512f | unknown | — | — | whitelisted |
3676 | iexplore.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?94d4aa867f589435 | unknown | — | — | whitelisted |
3676 | iexplore.exe | GET | 200 | 72.246.169.163:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
3676 | iexplore.exe | GET | 200 | 172.217.23.99:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
3676 | iexplore.exe | GET | 200 | 172.217.23.99:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
3676 | iexplore.exe | GET | 200 | 184.24.77.54:80 | http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgPxPu7FPlV8%2F%2BMPTNqYsn%2FH%2Fg%3D%3D | unknown | — | — | whitelisted |
2980 | iexplore.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2badae3db65008eb | unknown | — | — | whitelisted |
2980 | iexplore.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?447a8cb464fbbb54 | unknown | — | — | whitelisted |
2980 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
3676 | iexplore.exe | 91.215.42.4:443 | doxbin.org | Ddos-guard Ltd | RU | unknown |
1372 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3676 | iexplore.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
3676 | iexplore.exe | 72.246.169.163:80 | x1.c.lencr.org | AKAMAI-AS | DE | unknown |
3676 | iexplore.exe | 184.24.77.54:80 | r11.o.lencr.org | Akamai International B.V. | DE | unknown |
3676 | iexplore.exe | 104.18.11.207:443 | netdna.bootstrapcdn.com | CLOUDFLARENET | — | unknown |
3676 | iexplore.exe | 104.19.229.21:443 | js.hcaptcha.com | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
doxbin.org |
| malicious |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r11.o.lencr.org |
| whitelisted |
netdna.bootstrapcdn.com |
| whitelisted |
js.hcaptcha.com |
| whitelisted |
c.pki.goog |
| whitelisted |
newassets.hcaptcha.com |
| whitelisted |
api.hcaptcha.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1060 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |