URL:

https://www5.putlockerhd.io

Full analysis: https://app.any.run/tasks/dc00375a-b4f2-42bc-8421-5b3945b55734
Verdict: Malicious activity
Analysis date: March 07, 2022, 09:54:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

45BF77EE46E84BA7F841BCC48D1E9AE3

SHA1:

A5176F642E51E72C29D113873F58E0580EB98870

SHA256:

268B77B7E66B5AA19E770584E05E112012E1C7BD093F88E2BDB6A39942924DA6

SSDEEP:

3:N8DSQLVQRJdOyrn:2Oe6vMg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 2884)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 2884)
      • iexplore.exe (PID: 3548)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2884)
      • iexplore.exe (PID: 3548)
    • Reads the computer name

      • iexplore.exe (PID: 3548)
      • iexplore.exe (PID: 2884)
    • Application launched itself

      • iexplore.exe (PID: 3548)
    • Changes internet zones settings

      • iexplore.exe (PID: 3548)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2884)
    • Creates files in the user directory

      • iexplore.exe (PID: 2884)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3548)
      • iexplore.exe (PID: 2884)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3548"C:\Program Files\Internet Explorer\iexplore.exe" "https://www5.putlockerhd.io"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2884"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3548 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\rpcrt4.dll
Total events
18 362
Read events
18 217
Write events
145
Delete events
0

Modification events

(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30945801
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30945801
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
25
Text files
85
Unknown types
23

Dropped files

PID
Process
Filename
Type
2884iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\style_login[1].csstext
MD5:D3FB04434A3D2865A6027CDD96E07299
SHA256:3A3B9E9B6E91FC21340958082750365353ECEAE9887F1B7B6572C7DCD5BC3B8D
2884iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\putlocker.min[1].jstext
MD5:4967CEB0F716110944667A765198748C
SHA256:8BBE0482DF939517C7AF4C302533D975EDDF4E43F33EB088219C923E1722E334
2884iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\custom[1].csstext
MD5:ECEEF8712C9FC506DCBBFBFFBA708C87
SHA256:E87FC1E03904C151DFC8F3D43D73C7EF283678A2DDE8431C40D26CC1031CF8E2
2884iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27der
MD5:A4675CB963129290E7723158F9DE99A9
SHA256:ABE9669462FF0B77BB11141029EEF63530A50D17AC8D26AD919A8084BCE8D377
2884iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\style[1].csstext
MD5:16759EAD9E70C6A2A69ED4588CEC0D70
SHA256:DCF28679B63CC16E9C310D964E98AC5E76F970ABB3C3632AFB16DE1AFC84E4D0
2884iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\main[1].csstext
MD5:3C9AF3ED0FB99221AA99642922FF5476
SHA256:9C986073F6F9D83AF2F1069C9BE99D83BA62A0767BADEC1D4EE2A08CEA42AC68
2884iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\T3FPLT9I.htmhtml
MD5:3B8883F6E4DAFC1159C9BA7DFDF70D23
SHA256:2606B841D565960B69B1D893D4980C915A95A71882ACEDEB7227C7C146877B4A
2884iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:BB420DA6DFE5E8710362D891102A486E
SHA256:B48DE6E6BF7E7B04002C489F40AB6E51D8B5C256FFC9D81183A740A648F9103F
2884iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\bootstrap.min[1].csstext
MD5:E4CB536EEC315DD6C13FA3731A122146
SHA256:07B32D6C16FE581DB6F7A8125AE99D4E61A29E26D29020DDE2122A9583390C29
2884iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:C66BE9FF314D1D12C09A2C94394F15CE
SHA256:F2CCA84B2E1251EC5594710270141C1CA4EEA57460A494961F1FD98AE6F49CFD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
81
DNS requests
33
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2884
iexplore.exe
GET
200
104.18.30.182:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEEhFj8QPMDTBXdjhxO7%2F8SY%3D
US
der
471 b
whitelisted
2884
iexplore.exe
GET
200
142.250.185.163:80
http://crl.pki.goog/gsr1/gsr1.crl
US
der
1.61 Kb
whitelisted
2884
iexplore.exe
GET
200
104.18.31.182:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
US
der
727 b
whitelisted
3548
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
2884
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
2884
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCyLG4l5D%2BaFwoAAAABN4kh
US
der
472 b
whitelisted
2884
iexplore.exe
GET
200
2.16.186.41:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgNba%2Fd%2F3CwO%2BoyGFcKB%2FnE%2FOg%3D%3D
unknown
der
503 b
shared
2884
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
2884
iexplore.exe
GET
200
2.16.186.81:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?80d12204f6b2d369
unknown
compressed
59.5 Kb
whitelisted
2884
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEFJXl5%2FOUoVICgAAAAE3h2s%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2884
iexplore.exe
142.250.185.74:443
fonts.googleapis.com
Google Inc.
US
whitelisted
2884
iexplore.exe
2.16.186.56:80
ctldl.windowsupdate.com
Akamai International B.V.
whitelisted
2884
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2884
iexplore.exe
2.16.186.81:80
ctldl.windowsupdate.com
Akamai International B.V.
whitelisted
2884
iexplore.exe
139.45.197.237:443
bodelen.com
US
malicious
2884
iexplore.exe
142.250.185.163:80
ocsp.pki.goog
Google Inc.
US
whitelisted
2884
iexplore.exe
2.16.186.41:80
r3.o.lencr.org
Akamai International B.V.
whitelisted
2884
iexplore.exe
104.31.16.5:443
www5.putlockerhd.io
Cloudflare Inc
US
unknown
2884
iexplore.exe
23.37.41.57:80
x1.c.lencr.org
Akamai Technologies, Inc.
NL
suspicious
3548
iexplore.exe
131.253.33.200:443
www.bing.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
www5.putlockerhd.io
  • 104.31.16.5
  • 104.31.16.124
unknown
ctldl.windowsupdate.com
  • 2.16.186.81
  • 2.16.186.56
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
s7.addthis.com
  • 104.75.88.126
whitelisted
www.googletagmanager.com
  • 142.250.185.72
whitelisted
bodelen.com
  • 139.45.197.237
malicious
fonts.googleapis.com
  • 142.250.185.74
whitelisted
ocsp.pki.goog
  • 142.250.185.163
whitelisted
x1.c.lencr.org
  • 23.37.41.57
whitelisted
r3.o.lencr.org
  • 2.16.186.41
  • 2.16.186.27
  • 2.16.186.33
  • 2.16.186.10
shared

Threats

No threats detected
No debug info