URL: | http://georeg.mywire.org/KtimaLoc509/ |
Full analysis: | https://app.any.run/tasks/2b508e40-6f47-4b7c-ab7a-2a9446afa218 |
Verdict: | Malicious activity |
Analysis date: | December 14, 2023, 09:14:57 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | 2B175313C90D6B3EC51E39240055C5E0 |
SHA1: | 7309E4DC1A6AC3FE717962F6416C11C209C88BC4 |
SHA256: | 17C980248C7AFE763DCE641499A57230425BA1A71361AB88B288AE2EE6609BB9 |
SSDEEP: | 3:N1KZAKbho+SmdQV7:C+K9ofmSV7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1696 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2620 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3048 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
3048 | "C:\Program Files\Internet Explorer\iexplore.exe" "http://georeg.mywire.org/KtimaLoc509/" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
|
(PID) Process: | (3048) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
(PID) Process: | (3048) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
(PID) Process: | (3048) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
(PID) Process: | (3048) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (3048) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (3048) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
(PID) Process: | (3048) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (3048) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (3048) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (3048) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2620 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\KtimaLoc509[1].htm | html | |
MD5:C9E0F99CA319D17E4A3891757A2EA381 | SHA256:DF6A2B35D991233B0332B68504A4F8409301A254EFC23ACCD56434BA00F3167A | |||
2620 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\mystyle[1].css | text | |
MD5:C4033C6E44BD5C7FA77142DB49B15E47 | SHA256:D289E65380482A22E0E7B534D1DDFBD21917DC04574CF627B43B6BD63E8F426C | |||
2620 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\ol[1].js | text | |
MD5:E92CA5938BB8D754FF01CE6AA636B679 | SHA256:6594F5B712399CA066F4634F19CD36DAA939753BFD699EECDC874D2A6F49025E | |||
2620 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\balloon[1].css | text | |
MD5:391E6545BA9979874811EA2972016CCA | SHA256:842742AFE694F4266F0FBD65266FCD3C4C2199E0BA3D1A0BF1E6D98ECB191019 | |||
2620 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | binary | |
MD5:E7A6DD6A36E00CDAB0393E05EFEB9867 | SHA256:EAC66084D019A0F45B9DF9E2059E1C57803C3EDCCD273A1D92DF1C563A599263 | |||
2620 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:C3DE9C2BE3D6709B39988270D5E99053 | SHA256:78C8EE1D255AB180969F1ECAC568FDB765EDC1E2F1C50BF004832813C470D1BF | |||
2620 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89 | SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8 | |||
2620 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9FF67FB3141440EED32363089565AE60_D502438C006C606011E2951AE5BC5494 | der | |
MD5:99D23182174A3A72B2DEFF0199E9D3EB | SHA256:F6AFCB3EFADB6E2D34A3D1F33FCD4D96E3F1899032FE94B65AEABE6DA961D1CC | |||
2620 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27 | binary | |
MD5:C7DA1E319527E224F3F8F7CDDEC8E464 | SHA256:92C5694583CA169663CA0E62DC8A5725E8712BF4D24126561E362A01ED201EA4 | |||
2620 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | der | |
MD5:2726A72634E0EB08A7267E2070A89783 | SHA256:A7C19E061138256003B6F53E37EF67A7BAB1A20799A0C2865C5719CEA1F38D5B |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2620 | iexplore.exe | GET | 200 | 168.119.209.22:80 | http://georeg.mywire.org/KtimaLoc509/ | unknown | html | 1.02 Kb | — |
2620 | iexplore.exe | GET | 200 | 168.119.209.22:80 | http://georeg.mywire.org/KtimaLoc509/styles/mystyle.css | unknown | text | 1.08 Kb | — |
2620 | iexplore.exe | GET | 200 | 168.119.209.22:80 | http://georeg.mywire.org/KtimaLoc509/v4.6.4-dist/ol.css | unknown | text | 1.15 Kb | — |
2620 | iexplore.exe | GET | 200 | 168.119.209.22:80 | http://georeg.mywire.org/KtimaLoc509/styles/balloon.css | unknown | text | 1.48 Kb | — |
2620 | iexplore.exe | GET | 200 | 168.119.209.22:80 | http://georeg.mywire.org/KtimaLoc509/v4.6.4-dist/ol.js | unknown | text | 154 Kb | — |
2620 | iexplore.exe | GET | 200 | 23.32.238.233:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?bfb30800836c6a88 | unknown | compressed | 4.66 Kb | — |
2620 | iexplore.exe | GET | 200 | 23.32.238.233:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4a20c10c41b12cb1 | unknown | compressed | 4.66 Kb | — |
2620 | iexplore.exe | GET | 200 | 23.32.238.233:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?992050f6f6632977 | unknown | compressed | 4.66 Kb | — |
2620 | iexplore.exe | GET | 200 | 23.32.238.233:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?cd96e7560c06d13e | unknown | compressed | 4.66 Kb | — |
2620 | iexplore.exe | GET | 200 | 23.32.238.233:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e90117ea99140de1 | unknown | compressed | 4.66 Kb | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
2620 | iexplore.exe | 168.119.209.22:80 | georeg.mywire.org | Hetzner Online GmbH | UA | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
2620 | iexplore.exe | 104.17.24.14:443 | cdnjs.cloudflare.com | CLOUDFLARENET | — | unknown |
2620 | iexplore.exe | 172.64.140.13:443 | use.fontawesome.com | CLOUDFLARENET | US | unknown |
2620 | iexplore.exe | 172.217.18.106:443 | ajax.googleapis.com | GOOGLE | US | unknown |
2620 | iexplore.exe | 23.32.238.233:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2620 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | unknown |
Domain | IP | Reputation |
---|---|---|
georeg.mywire.org |
| unknown |
cdnjs.cloudflare.com |
| unknown |
ajax.googleapis.com |
| unknown |
use.fontawesome.com |
| unknown |
ctldl.windowsupdate.com |
| unknown |
ocsp.digicert.com |
| unknown |
ocsp.pki.goog |
| unknown |
maps.googleapis.com |
| unknown |
api.bing.com |
| unknown |
www.bing.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.mywire .org Domain |
— | — | Potentially Bad Traffic | ET INFO DYNAMIC_DNS HTTP Request to a *.mywire .org Domain |
— | — | Potentially Bad Traffic | ET INFO DYNAMIC_DNS HTTP Request to a *.mywire .org Domain |
— | — | Potentially Bad Traffic | ET INFO DYNAMIC_DNS HTTP Request to a *.mywire .org Domain |
— | — | Potentially Bad Traffic | ET INFO DYNAMIC_DNS HTTP Request to a *.mywire .org Domain |
— | — | Potentially Bad Traffic | ET INFO DYNAMIC_DNS HTTP Request to a *.mywire .org Domain |
— | — | Potentially Bad Traffic | ET INFO DYNAMIC_DNS HTTP Request to a *.mywire .org Domain |
— | — | Potentially Bad Traffic | ET INFO DYNAMIC_DNS HTTP Request to a *.mywire .org Domain |
— | — | Potentially Bad Traffic | ET INFO DYNAMIC_DNS HTTP Request to a *.mywire .org Domain |
— | — | Potentially Bad Traffic | ET INFO DYNAMIC_DNS HTTP Request to a *.mywire .org Domain |