URL:

http://bapps.net.global.prod.fastly.net/files/apps/face-mobile/?i=118778

Full analysis: https://app.any.run/tasks/9c9a7839-e8a7-4bca-81c6-a2aab652adf5
Verdict: Malicious activity
Analysis date: January 30, 2024, 21:03:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

7195B9A72595F40DF94274B6DF0B8599

SHA1:

4B9D5301C4A9E3267A950C090A62EE0E574559E0

SHA256:

1828241809676A0C93F94CF1108430BECAE807BAA150C9132F7C656B28F3B8EF

SSDEEP:

3:N1Kc8iBa0O6XQK8bYY8JvaM5an:CcbQ0OluJo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 268)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\Internet Explorer\iexplore.exe" "http://bapps.net.global.prod.fastly.net/files/apps/face-mobile/?i=118778"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3468"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:268 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
13 582
Read events
13 503
Write events
73
Delete events
6

Modification events

(PID) Process:(268) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(268) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(268) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(268) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(268) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(268) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(268) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(268) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(268) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(268) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
12
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
3468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAbinary
MD5:F310E773651E66F2B018A7C8F3C5E69B
SHA256:9B97A7AC986576B9AE17C200E639AA3FFF8736892FED15A11C4FC89E006298F0
3468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\nicepage[1].csstext
MD5:997E82109A656242994EE2C4F6D2E735
SHA256:1A67B6D44122B393A12A649C09CA2E00B1D380E2681C599CF06ABEC282B3842D
3468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\gg[1].pngimage
MD5:F0C1EDE11E7ECE89D2D65D02E3F79301
SHA256:41B5F73FB6E48E6F46905D852A8807BC9613C4FBC281D41D6A6E266F4C4EDBB7
3468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:5745427863C133FFBEE9DC2CF749F47C
SHA256:F8D800DB8262F26FE40F52630BBA31F8EB4DD539BF340AEDE349374C4137C24C
268iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:C223880A5B2CBC6A0F7C3CDFF0437989
SHA256:879B5B7415EBAE3618A2375A3231A0528B642D48B7A46D77221BB85A541990FA
3468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\265C0DEB29181DD1891051371C5F863A_8CFD0F060456F65ABC9E95E41A1F781Cbinary
MD5:D5B13C71BBEECCF96D8E4AE66B0CFDF1
SHA256:B9DC7698D0886E12EC1BB0D8489F73B4154B73FE51C928AD692714AB79419071
3468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:8FEBADA1AD56833E9F72ADD7D4D9444D
SHA256:B02EF00F524395D55AB974A153166EF241485E906C4B7945BF152D2A6EB455D2
3468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery-1.9.1.min[1].jstext
MD5:397754BA49E9E0CF4E7C190DA78DDA05
SHA256:C12F6098E641AACA96C60215800F18F5671039AECF812217FAB3C0D152F6ADB4
3468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\265C0DEB29181DD1891051371C5F863A_8CFD0F060456F65ABC9E95E41A1F781Cbinary
MD5:B7EEED26C0315E6D316135BA8A27EA68
SHA256:256AD810B41CA02362E3F3928BA8246EAEA57781C0966912B1B5ECD08466D240
3468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:9B835B83661C1524AA3AC69349680E73
SHA256:4B1F1572531A5AFB82AC933AAFE3990655FAE9087A6D6B3E9E48DA734E765D57
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
23
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3468
iexplore.exe
GET
200
151.101.0.249:80
http://bapps.net.global.prod.fastly.net/files/apps/face-mobile/?i=118778
unknown
html
1.47 Kb
unknown
3468
iexplore.exe
GET
200
151.101.0.249:80
http://bapps.net.global.prod.fastly.net/files/apps/face-mobile/page1.css
unknown
text
259 b
unknown
3468
iexplore.exe
GET
304
23.32.238.59:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7c6c1f20e25e896c
unknown
unknown
3468
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
268
iexplore.exe
GET
404
151.101.0.249:80
http://bapps.net.global.prod.fastly.net/favicon.ico
unknown
html
238 b
unknown
268
iexplore.exe
GET
304
23.32.238.59:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9f1bf971760d5e57
unknown
unknown
268
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
313 b
unknown
1080
svchost.exe
GET
200
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?fc91d912a85a08d5
unknown
compressed
65.2 Kb
unknown
3468
iexplore.exe
GET
200
151.101.0.249:80
http://bapps.net.global.prod.fastly.net/files/apps/face-mobile/nicepage.css
unknown
text
104 Kb
unknown
3468
iexplore.exe
GET
200
151.101.0.249:80
http://bapps.net.global.prod.fastly.net/files/apps/face-mobile/jquery-1.9.1.min.js
unknown
text
32.0 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3468
iexplore.exe
151.101.0.249:80
bapps.net.global.prod.fastly.net
FASTLY
US
malicious
3468
iexplore.exe
172.217.18.10:443
fonts.googleapis.com
GOOGLE
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3468
iexplore.exe
23.32.238.59:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3468
iexplore.exe
142.250.185.163:80
ocsp.pki.goog
GOOGLE
US
whitelisted
268
iexplore.exe
151.101.0.249:80
bapps.net.global.prod.fastly.net
FASTLY
US
malicious
268
iexplore.exe
104.126.37.160:443
www.bing.com
Akamai International B.V.
DE
unknown
268
iexplore.exe
23.32.238.59:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
bapps.net.global.prod.fastly.net
  • 151.101.0.249
  • 151.101.64.249
  • 151.101.128.249
  • 151.101.192.249
unknown
fonts.googleapis.com
  • 172.217.18.10
whitelisted
ctldl.windowsupdate.com
  • 23.32.238.59
  • 23.32.238.67
  • 2.19.198.208
  • 2.19.198.81
  • 23.32.238.18
  • 173.222.108.226
  • 173.222.108.210
whitelisted
ocsp.pki.goog
  • 142.250.185.163
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.160
  • 104.126.37.137
  • 104.126.37.162
  • 104.126.37.170
  • 104.126.37.163
  • 104.126.37.176
  • 104.126.37.161
  • 104.126.37.139
  • 104.126.37.136
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted

Threats

No threats detected
No debug info