URL:

https://ninoglostoay.com/?b=19366673&ba=1&campid=7573047&did=933&dm=1&ep=0&g=SA&l=tV3hvx756DdxZVl&oaid=917ff1b55e0b40daa847a648622a0d5e&s=768588858303459328&ssk=fac99fb9800e57d2bfef8a46020d40c6&svar=1704809381&vi=1&vo=1&z=6163280&tr=default&stest=aaea725258ed0bde480ef635fdda9658

Full analysis: https://app.any.run/tasks/5a520564-0b75-47af-a144-34e020c1d9db
Verdict: Malicious activity
Analysis date: January 09, 2024, 14:34:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

13CB8BAC73723FB62F687EC068BCFC0F

SHA1:

336B9B02DE5495857FBCBD0F7FDD678F367BCECF

SHA256:

08690A067049B1DB3EA0116D9538E7903BA2BBB89FE9953E81E9A5F57F61F421

SSDEEP:

6:2FWlvLIK0uvUabJAtr0R2uTkVzSQdN3uFAQMmEV8KAyHt8AfIA6eI:2FWlDZ090gXddN3u6QuV8KHt8AQheI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 120)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Program Files\Internet Explorer\iexplore.exe" "https://ninoglostoay.com/?b=19366673&ba=1&campid=7573047&did=933&dm=1&ep=0&g=SA&l=tV3hvx756DdxZVl&oaid=917ff1b55e0b40daa847a648622a0d5e&s=768588858303459328&ssk=fac99fb9800e57d2bfef8a46020d40c6&svar=1704809381&vi=1&vo=1&z=6163280&tr=default&stest=aaea725258ed0bde480ef635fdda9658"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1056"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:120 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
19 761
Read events
19 680
Write events
77
Delete events
4

Modification events

(PID) Process:(120) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(120) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(120) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(120) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(120) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(120) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(120) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(120) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(120) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(120) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
82
Text files
64
Unknown types
0

Dropped files

PID
Process
Filename
Type
1056iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\CabFE75.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
1056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:419A691E4628BD0DEA8933217014B7AA
SHA256:162C2DC25CD50FCE38D38794324BE5936836D8C32DCACF7877CDB8A6E2D9B8B9
1056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
1056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
1056iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\NMO1EF4Y.txttext
MD5:456A4EC8784CCBEC20DD78535BD00710
SHA256:63C6F3EE51F0FF7156C783A6FD88739347A723C749008390966628C502CFD432
1056iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\2LMTBDRH.txttext
MD5:2F3BF8DC993551B47D855D155A82BF51
SHA256:C6B53A714F77BF96910FA75F824A2446866720CF3587BF7B432110178B1C42AE
1056iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\TarFE78.tmpcat
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
1056iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\icons[1].jpgimage
MD5:023F4E546359D8D934FECA7280734CA9
SHA256:7D5E6AB47F0350A75BFE0B5B431320F5D4C9B83FB242DE7E1014E3097EC4ECFE
1056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:A8F58D3C59E4FABE095F61E88C2C1E0F
SHA256:63A49371E99668F1B0D9A216A87721372D832EEEB3AD7E9EA5159C774CB7F13C
1056iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\TarFE76.tmpcat
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
67
DNS requests
31
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1056
iexplore.exe
GET
200
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?16e53a13f7f2d96f
unknown
compressed
4.66 Kb
unknown
1056
iexplore.exe
GET
200
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b2fd21f5b9689499
unknown
compressed
4.66 Kb
unknown
1056
iexplore.exe
GET
200
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?7a9d8baceff24343
unknown
compressed
65.2 Kb
unknown
1056
iexplore.exe
GET
200
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?b25bf5dc542a1974
unknown
compressed
65.2 Kb
unknown
1056
iexplore.exe
GET
200
2.19.105.18:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
1056
iexplore.exe
GET
200
95.101.54.106:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgT7GIaD65gX3NQdEX7YsorfYQ%3D%3D
unknown
binary
503 b
unknown
1056
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
1056
iexplore.exe
GET
200
95.101.54.106:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOF6TT0ySAsLovNvz1KBN75Pg%3D%3D
unknown
binary
503 b
unknown
120
iexplore.exe
GET
304
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?111b88f027149bc7
unknown
unknown
120
iexplore.exe
GET
304
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?973bc8aa769c2f5e
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1056
iexplore.exe
139.45.197.153:443
ninoglostoay.com
RETN Limited
GB
malicious
1080
svchost.exe
224.0.0.252:5355
unknown
1056
iexplore.exe
173.222.108.226:80
ctldl.windowsupdate.com
Akamai International B.V.
CH
unknown
1056
iexplore.exe
2.19.105.18:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown
1056
iexplore.exe
95.101.54.106:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
1056
iexplore.exe
104.22.24.116:443
littlecdn.com
CLOUDFLARENET
unknown
1056
iexplore.exe
139.45.197.250:443
stoomawy.net
RETN Limited
GB
unknown
1056
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
ninoglostoay.com
  • 139.45.197.152
  • 139.45.197.153
  • 139.45.197.154
  • 139.45.197.151
  • 139.45.197.155
unknown
ctldl.windowsupdate.com
  • 173.222.108.226
  • 173.222.108.210
whitelisted
x1.c.lencr.org
  • 2.19.105.18
whitelisted
r3.o.lencr.org
  • 95.101.54.106
  • 95.101.54.208
  • 95.101.54.107
  • 95.101.54.137
  • 95.101.54.139
shared
stoomawy.net
  • 139.45.197.250
unknown
littlecdn.com
  • 104.22.24.116
  • 104.22.25.116
  • 172.67.10.98
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 2.20.142.178
  • 2.20.142.181
  • 2.20.142.182
  • 2.20.142.180
  • 2.20.142.187
  • 2.20.142.179
  • 2.20.142.185
  • 2.20.142.186
  • 2.20.142.184
whitelisted
aikravoapu.com
  • 139.45.197.154
  • 139.45.197.153
  • 139.45.197.155
  • 139.45.197.152
  • 139.45.197.151
unknown

Threats

No threats detected
No debug info