URL:

www.Downloadha.com

Full analysis: https://app.any.run/tasks/7ec20e5e-f03e-4118-9d3c-397fbbf56410
Verdict: Malicious activity
Analysis date: January 29, 2024, 08:30:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

91F01F03D49E285DEF2B56496B6183AB

SHA1:

BCD4A9947CACA16778A64273B226B45CDAEB66EA

SHA256:

1B9D88F15C7807FD416FBF87210E3F12D2411E9DE04B55726583318702B07D61

SSDEEP:

3:EXZ7iGTn:cZ7d

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3456)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
552"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3456 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3456"C:\Program Files\Internet Explorer\iexplore.exe" "www.Downloadha.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
20 910
Read events
20 816
Write events
84
Delete events
10

Modification events

(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
41
Text files
59
Unknown types
0

Dropped files

PID
Process
Filename
Type
552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\68FAF71AF355126BCA00CE2E73CC7374_123B8BA19C64CE9A8B3EAC32000FAF3Ebinary
MD5:061B26343631EA1238A777BB7456DABE
SHA256:1D29203225216B02780597D2396718808D87CAEA2D97EF465E318C723D34E037
552iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\DF80G8F4.htmhtml
MD5:1304294C0823CA486542BA408ED761E3
SHA256:3BBE72F3BAA8EC61DE17A1D767FCA58704769684B7ABE9161D0C4EAF4C8F0982
552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1B1F4BA66CDBFEC85A20E11BF729AF23_AA85F8F9DAFF33153B5AEC2E983B94B6binary
MD5:6C1C6DCED129A27590A12619EB7E07A6
SHA256:B29EF056A4DC074831789EDBA0AD80D82151A23A5260354E4ADC8F66DA5D0AB6
552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\68FAF71AF355126BCA00CE2E73CC7374_123B8BA19C64CE9A8B3EAC32000FAF3Ebinary
MD5:5F52976C9B3FCCC191BCA22EE35513DE
SHA256:FFF9EEFCEB2B896C2F3C1C7D36E295991159C6461C4D65555AAF19394C42729A
552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:619C949BE693AD125BCA1C1C1A2CE1C0
SHA256:4643BEE826001E7BD08663EE51651277417BAB4A3C2F9C105301E938129FB5D1
552iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\658DBVYC.htmhtml
MD5:360D303A954BEB4C15A8811D18BD85A7
SHA256:201CC669CF194CF5971C45C94C54FF21E0D4B8BEACB0A0ED07421D59B22BCE62
552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:B4EEA7E7F6CC5753D5BA99BE274D2EEE
SHA256:16878D6C0F46609085C5B4F997C5EC0E603F9C311C4A092BFCCB338F6885332E
552iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\43f04[1].csstext
MD5:688C20CCB4D77AA33962B14E0420BF21
SHA256:25482F369DAE48050952AE25B17A0C30CB6AF33E8FDCE8F8B767F970F774544E
552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAbinary
MD5:6AA46E250780D3B6A3A923670D6BCCF6
SHA256:E02B4F4182480D89550DD04AE6C29758B4C49A98AD37495A89C170B6B6DD5287
552iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:4DB18CF8D025F469A7BE7C11023C12D2
SHA256:305BBE51E4B3DBA3F8FE23182202074BA3B8DB1A4D8C3CFAD0C4C727A83747F4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
58
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
552
iexplore.exe
GET
301
79.127.127.25:80
http://www.downloadha.com/
unknown
html
707 b
unknown
552
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?96e261c22e45b24e
unknown
compressed
65.2 Kb
unknown
552
iexplore.exe
GET
200
23.36.162.85:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso
unknown
binary
1.50 Kb
unknown
552
iexplore.exe
GET
200
23.36.162.85:80
http://subca.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCECbd0itGycRNWmlNOYB%2Bcq0%3D
unknown
binary
1.54 Kb
unknown
552
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?96e4ad55c838a7c7
unknown
compressed
65.2 Kb
unknown
552
iexplore.exe
GET
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?99ca8d6e14d93fcf
unknown
unknown
552
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?588f3b1a3b46a6f6
unknown
compressed
65.2 Kb
unknown
552
iexplore.exe
GET
200
23.36.162.85:80
http://dvcasha2.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNcCPjJ499lHmfPUvPsRjzr1YchwQU5TGtvzoRlvSDvFA81LeQm5Du3iUCEAsNuKWxGURwlhm30XHbGqs%3D
unknown
binary
1.56 Kb
unknown
552
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
552
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
552
iexplore.exe
79.127.127.25:80
www.downloadha.com
Asiatech Data Transmission company
IR
unknown
552
iexplore.exe
79.127.127.25:443
www.downloadha.com
Asiatech Data Transmission company
IR
unknown
552
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
552
iexplore.exe
23.36.162.85:80
subca.ocsp-certum.com
Akamai International B.V.
DE
unknown
552
iexplore.exe
142.250.185.136:443
www.googletagmanager.com
GOOGLE
US
unknown
552
iexplore.exe
185.120.221.242:443
img5.downloadha.com
Asiatech Data Transmission company
IR
unknown
552
iexplore.exe
178.216.250.180:443
cdn.hostdl.com
Asiatech Data Transmission company
IR
unknown

DNS requests

Domain
IP
Reputation
www.downloadha.com
  • 79.127.127.25
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
subca.ocsp-certum.com
  • 23.36.162.85
  • 23.36.162.83
whitelisted
www.googletagmanager.com
  • 142.250.185.136
whitelisted
img5.downloadha.com
  • 185.120.221.242
unknown
cdn.hostdl.com
  • 178.216.250.180
unknown
ocsp.pki.goog
  • 142.250.181.227
whitelisted
cdn.yektanet.com
  • 185.166.104.4
  • 185.166.104.3
malicious
dvcasha2.ocsp-certum.com
  • 23.36.162.85
  • 23.36.162.83
whitelisted
x1.c.lencr.org
  • 2.23.197.184
whitelisted

Threats

No threats detected
No debug info