URL:

spankbang.com

Full analysis: https://app.any.run/tasks/6c1c98d5-d7cd-40ff-858d-e5f1abc6e106
Verdict: Malicious activity
Analysis date: February 19, 2024, 19:15:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

1C14732DA7025587F05151B3ADE7D962

SHA1:

37465874DA949FA0C18F28D4D1725E211EBF65B9

SHA256:

0EECAB1C8A4BEE409DAA265178B82F9670CB3F9FF1F501514E5A4428AEC082F7

SSDEEP:

3:cinn:cin

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3164"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3672 CREDAT:3740945 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3348"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3672 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3672"C:\Program Files\Internet Explorer\iexplore.exe" "spankbang.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
34 922
Read events
34 785
Write events
101
Delete events
36

Modification events

(PID) Process:(3672) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3672) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
342070448
(PID) Process:(3672) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31089512
(PID) Process:(3672) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
642227948
(PID) Process:(3672) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31089512
(PID) Process:(3672) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3672) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3672) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3672) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3672) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
30
Text files
78
Unknown types
9

Dropped files

PID
Process
Filename
Type
3348iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:5779CBF1808387FFC28B2E11A3D21C52
SHA256:385E55FFD7F794F85489ED9DACD3939E36F95D0DBAE32062F7ED1A1135CB846B
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\060EYAQYtext
MD5:FDA44910DEB1A460BE4AC5D56D61D837
SHA256:933B971C6388D594A23FA1559825DB5BEC8ADE2DB1240AA8FC9D0C684949E8C9
3348iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\5WBLIOGU.txttext
MD5:16A6B6B7247B26CBDDD4B7A7DFC2FC7A
SHA256:3024F804DE066A489BC9F1270051CBEAD314DFA517BE7DBE51C7CC401EBF08D7
3348iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27der
MD5:254A92E7965EEDD8A25EFBBAC0C4F2D7
SHA256:8A8C6BA62EC0CADCFA6B38DCD019707DA37A9B0E5E7262A91C00BC1B9CD3E5BE
3348iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\SY9LYX2R.txttext
MD5:C954451A03A51C2E6C35BB32C95A0531
SHA256:935B6E29FACF97FDDEE95B4C9EE8EBAC38171CB3A005D457137B130136EF3457
3348iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\7JONOM7H.txttext
MD5:003ECFD1326F53DF19B6C5BA97082FAD
SHA256:7C8E5F3A2EB75CE84F39B2835EDA64CD7A9CD9CB939C2201B8EF13879842FD3D
3348iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\NY0CYG1G.txttext
MD5:DF304BE3D2F5E11DCA5FF38B1482B07E
SHA256:BFCF84581BBD123899743522374489964FFB0B0035BC99852CD1F3179901931A
3348iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\OY2KE1LF.txttext
MD5:D2D6B1322768D7C6F6BAE727EC01F3B5
SHA256:5AA88C9EF6D43CD0ACB55476CDE3C33B849FBE44CBF7B7B7C04D3EDC770EDC5E
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\universal.master.6.1.packed.sync.44b4ae0d[1].jstext
MD5:44B4AE0D61EF13C11E8FE23FD69ED08A
SHA256:7BD88C2FD16BA7BD0EDB808B7863B827ADDF8956D544024240CE9E8D8D24C2ED
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\video-js-cdn.min[1].csstext
MD5:AC81FF99F34ECDE50A5BEE2605A6C2D7
SHA256:EF19D3570DEA1C5A973FB7F6FC98C525CD8CE6D01DB1937F8459975979648BDC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
85
DNS requests
36
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3348
iexplore.exe
GET
301
104.19.137.100:80
http://spankbang.com/
unknown
unknown
3348
iexplore.exe
GET
304
173.222.108.195:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?64db15c300a7b163
unknown
unknown
3348
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
3348
iexplore.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
3348
iexplore.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
3348
iexplore.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCG5mYmc5exBwr3zurLpXnC
unknown
binary
472 b
unknown
3672
iexplore.exe
GET
304
173.222.108.195:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?70b4a85d87201c80
unknown
unknown
3672
iexplore.exe
GET
304
173.222.108.195:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?96c8eb5dfc595a04
unknown
unknown
3348
iexplore.exe
GET
200
173.222.108.195:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ab3478d39268ae3e
unknown
compressed
65.2 Kb
unknown
3348
iexplore.exe
GET
200
173.222.108.195:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6369203200c0cfcd
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3348
iexplore.exe
104.19.137.100:80
spankbang.com
CLOUDFLARENET
unknown
3348
iexplore.exe
104.19.137.100:443
spankbang.com
CLOUDFLARENET
unknown
3348
iexplore.exe
173.222.108.195:80
ctldl.windowsupdate.com
Akamai International B.V.
CH
unknown
3348
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3348
iexplore.exe
172.64.154.90:443
deliver.ptgncdn.com
CLOUDFLARENET
US
unknown
3348
iexplore.exe
104.17.24.14:443
cdnjs.cloudflare.com
CLOUDFLARENET
unknown
3348
iexplore.exe
104.18.218.46:443
tb.sb-cd.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
spankbang.com
  • 104.19.137.100
  • 104.19.136.100
whitelisted
ctldl.windowsupdate.com
  • 173.222.108.195
  • 173.222.108.226
  • 173.222.108.210
  • 173.222.108.201
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
tb.sb-cd.com
  • 104.18.218.46
  • 104.18.200.68
unknown
hls-uranus.sb-cd.com
  • 104.18.200.68
  • 104.18.218.46
unknown
deliver.ptgncdn.com
  • 172.64.154.90
  • 104.18.33.166
unknown
cdnjs.cloudflare.com
  • 104.17.24.14
  • 104.17.25.14
whitelisted
c.ptgncdn.com
  • 212.102.56.179
  • 156.146.33.137
  • 195.181.170.18
  • 212.102.56.181
  • 195.181.175.15
  • 156.146.33.140
  • 195.181.175.41
  • 212.102.56.178
  • 195.181.170.19
  • 195.181.175.16
unknown
assets.sb-cd.com
  • 104.18.218.46
  • 104.18.200.68
unknown
static.cloudflareinsights.com
  • 104.16.56.101
  • 104.16.57.101
whitelisted

Threats

No threats detected
No debug info