URL: | https://skidrowcpygames.com/password01 |
Full analysis: | https://app.any.run/tasks/0e0f8ca0-8a72-46bb-b9d1-706f7bc4b187 |
Verdict: | Malicious activity |
Analysis date: | February 12, 2023, 11:46:51 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | 7034E3340260C6DEF14778B12292C80D |
SHA1: | 73023C00AF6F36B9A59130E23287B8EBF8F09515 |
SHA256: | 01C1C91B583AEE7E574B08C1BA56A91EC4C8711FBA77FC1AB968ED3CA3EBF146 |
SSDEEP: | 3:N8DyKfcCtzEWWSKXB+n:2lxoR5Xo |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3520 | "C:\Program Files\Internet Explorer\iexplore.exe" "https://skidrowcpygames.com/password01" | C:\Program Files\Internet Explorer\iexplore.exe | Explorer.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
3936 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3520 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
2836 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2448 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3520 CREDAT:464144 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
|
(PID) Process: | (3520) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
(PID) Process: | (3520) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
(PID) Process: | (3520) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31014615 | |||
(PID) Process: | (3520) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: | |||
(PID) Process: | (3520) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31014615 | |||
(PID) Process: | (3520) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (3520) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (3520) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (3520) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
(PID) Process: | (3520) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3936 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:A288DF66573A233EB1CCDEE1423E10BB | SHA256:B6FD87DB4F82137828BFE3C5CF9E352697293F7BFBCEB7EB7B08CABBBF268D06 | |||
3936 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27 | binary | |
MD5:54B13AC020FE099A27C7441E3DBB0CA6 | SHA256:759C2CA1412060CC79F96CCAABCAC41C1094986DD28D263E2875BAD0DE4FB299 | |||
3936 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9FF67FB3141440EED32363089565AE60_83B8F093B5BC55D4DCF5048DC8795FA3 | der | |
MD5:4C425B8F3D1FF46DB10CED54F69B6643 | SHA256:D3AA51589FACDD43071BD15BF90CD78D813B170260ECA2713C69FC659B97E348 | |||
3936 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9FF67FB3141440EED32363089565AE60_CE2F0A1E5DF40B788EA08C89F604EB34 | binary | |
MD5:FC7924C3CC8A1CAEAB368AA909631FBA | SHA256:8AF5E70D8081414D57F537DCE00BF32E6190BD7818BB97D318D3478E76F27403 | |||
3520 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\82CB34DD3343FE727DF8890D352E0D8F | der | |
MD5:60B9EEE18F0318BA56E33C41A80E4620 | SHA256:B3897ABDC308EB2F09AF2F1146576875F8592116ABE59B487ECA11BE14A147A3 | |||
3520 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\82CB34DD3343FE727DF8890D352E0D8F | binary | |
MD5:30DD44A3B8984AC0CCD6BBFB924E8F92 | SHA256:A64074812DEC5F3B1E621BE957842FAFBBD568C6082FD0DD00A9E8878EA58933 | |||
3936 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9FF67FB3141440EED32363089565AE60_83B8F093B5BC55D4DCF5048DC8795FA3 | binary | |
MD5:1BB7E2CD864F93AD89DED06209DD595A | SHA256:0BA11B713577A65F8CA48624183A318AA23A549407DBD002241EB646DAF26F23 | |||
3936 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27 | der | |
MD5:396A9E17CEA30BEE646E770C19C03A6C | SHA256:99DD10454F762B8A8DF7578D00678E29B942D5FE0C85D97960CC9366A9E54B60 | |||
3936 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9FF67FB3141440EED32363089565AE60_CE2F0A1E5DF40B788EA08C89F604EB34 | der | |
MD5:25B2EB0267F3CB7D7B93A093EA646E1A | SHA256:216D7E2DF5E0DEF7ECF6B7B4CEFD813CCDD9FFA97FDCFBCCF99F57500883F885 | |||
3936 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\passwordtxt01[1].htm | html | |
MD5:96858D7F3820EE2C8B195C90AB79EBBE | SHA256:7247B7082EF235C1E33ACF370CB9C49EB561E3B255C4ACADF01965DD947716DA |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3936 | iexplore.exe | GET | 200 | 142.251.208.131:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQC%2ByQ3HCGjSjxK2rAEAFE8%2F | US | der | 472 b | whitelisted |
3936 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQS14tALDViBvqCf47YkiQRtKz1BAQUpc436uuwdQ6UZ4i0RfrZJBCHlh8CEAcxaF%2FM%2FAqMiL%2FRlq0mxBg%3D | US | der | 279 b | whitelisted |
3520 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://crl3.digicert.com/Omniroot2025.crl | US | der | 7.78 Kb | whitelisted |
3936 | iexplore.exe | GET | 200 | 178.79.242.0:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?f94802e48d820499 | DE | compressed | 61.4 Kb | whitelisted |
3936 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQS14tALDViBvqCf47YkiQRtKz1BAQUpc436uuwdQ6UZ4i0RfrZJBCHlh8CEAzja4vAreEppugpYALm3lE%3D | US | der | 280 b | whitelisted |
3936 | iexplore.exe | GET | 200 | 178.79.242.0:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e52a9ded24e1e7d8 | DE | compressed | 4.70 Kb | whitelisted |
2448 | iexplore.exe | GET | 200 | 104.18.32.68:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | US | der | 2.18 Kb | whitelisted |
2448 | iexplore.exe | GET | 200 | 172.64.155.188:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEEhcp0ACfnKpNNh1%2FZUtu4o%3D | US | der | 471 b | whitelisted |
3936 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D | US | der | 1.47 Kb | whitelisted |
3936 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3936 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | EDGECAST | GB | whitelisted |
3520 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | EDGECAST | GB | whitelisted |
3520 | iexplore.exe | 204.79.197.200:443 | www.bing.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3936 | iexplore.exe | 178.79.242.0:80 | ctldl.windowsupdate.com | LLNW | DE | whitelisted |
3936 | iexplore.exe | 142.251.39.74:443 | fonts.googleapis.com | GOOGLE | US | suspicious |
— | — | 104.21.32.36:443 | trkfiles.com | CLOUDFLARENET | — | unknown |
— | — | 104.18.10.207:443 | netdna.bootstrapcdn.com | CLOUDFLARENET | — | suspicious |
3936 | iexplore.exe | 104.21.28.119:443 | — | CLOUDFLARENET | — | unknown |
3936 | iexplore.exe | 104.21.32.36:443 | trkfiles.com | CLOUDFLARENET | — | unknown |
3936 | iexplore.exe | 104.18.10.207:443 | netdna.bootstrapcdn.com | CLOUDFLARENET | — | suspicious |
Domain | IP | Reputation |
---|---|---|
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
trkfiles.com |
| unknown |
crl3.digicert.com |
| whitelisted |
ajax.googleapis.com |
| whitelisted |
netdna.bootstrapcdn.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
i.ibb.co |
| shared |