URL:

https://www.pornhub.com

Full analysis: https://app.any.run/tasks/01fb6ccc-2d52-4c8b-bd34-9d4644e1ef28
Verdict: Malicious activity
Analysis date: February 24, 2022, 05:58:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

0BABB28FBAA5A0557CBECB21A8A24715

SHA1:

79CE9FA0965762F0B43CF6DC71BD9672D62B3892

SHA256:

428FEE64F7249D15B802857D45F3A2FEAA44BB3B870DD187D64CF7EBBA3DDE8C

SSDEEP:

3:N8DSLN2:2OLo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 892)
      • iexplore.exe (PID: 440)
      • iexplore.exe (PID: 2676)
      • iexplore.exe (PID: 3544)
      • iexplore.exe (PID: 3548)
      • iexplore.exe (PID: 1368)
  • INFO

    • Reads the computer name

      • iexplore.exe (PID: 3548)
      • iexplore.exe (PID: 892)
      • iexplore.exe (PID: 440)
      • iexplore.exe (PID: 2676)
      • iexplore.exe (PID: 3544)
      • iexplore.exe (PID: 1368)
    • Application launched itself

      • iexplore.exe (PID: 3548)
    • Changes internet zones settings

      • iexplore.exe (PID: 3548)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 892)
      • iexplore.exe (PID: 3548)
      • iexplore.exe (PID: 3544)
      • iexplore.exe (PID: 2676)
      • iexplore.exe (PID: 440)
      • iexplore.exe (PID: 1368)
    • Reads internet explorer settings

      • iexplore.exe (PID: 892)
      • iexplore.exe (PID: 440)
      • iexplore.exe (PID: 2676)
      • iexplore.exe (PID: 3544)
      • iexplore.exe (PID: 1368)
    • Checks supported languages

      • iexplore.exe (PID: 3548)
      • iexplore.exe (PID: 892)
      • iexplore.exe (PID: 440)
      • iexplore.exe (PID: 2676)
      • iexplore.exe (PID: 3544)
      • iexplore.exe (PID: 1368)
    • Creates files in the user directory

      • iexplore.exe (PID: 892)
      • iexplore.exe (PID: 440)
      • iexplore.exe (PID: 3544)
      • iexplore.exe (PID: 3548)
      • iexplore.exe (PID: 1368)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3548)
      • iexplore.exe (PID: 3544)
      • iexplore.exe (PID: 2676)
      • iexplore.exe (PID: 440)
      • iexplore.exe (PID: 892)
      • iexplore.exe (PID: 1368)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
6
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
440"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3548 CREDAT:529685 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
892"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3548 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
1368"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3548 CREDAT:1250613 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2676"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3548 CREDAT:3806481 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3544"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3548 CREDAT:1185043 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3548"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.pornhub.com"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
51 682
Read events
51 208
Write events
474
Delete events
0

Modification events

(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30943555
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30943555
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3548) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
54
Text files
455
Unknown types
28

Dropped files

PID
Process
Filename
Type
3548iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63binary
MD5:0DCEECD17C2865EA9E903DD7BFC4F912
SHA256:5B20E349CF796F2CEBB4682D5017C117E5E94C8ADF411D0179A10DC62DADD245
3548iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63der
MD5:93C468C22F976B61EBFE4D1F95DEAE2D
SHA256:8A4B9884D39F40CA5E73E875D53A635210369BF68707221755C94D18B30B9F89
892iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:CAACCE9AA5F733EE2AE74750F3F7D226
SHA256:DA049BD09DEE3B2A410BF4E56DAB35CCCB2ADC4BE5EFF81E3A185B34C52E0005
892iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\69C6F6EC64E114822DF688DC12CDD86Cder
MD5:35AEC2D39BC7F0FB130DE5C02B67C27B
SHA256:CC2D4A8BABB5D8B8BF8C6D2985744F3AFE27261F84FC21523B91C47031D579F7
3548iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
3548iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
892iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\69C6F6EC64E114822DF688DC12CDD86Cbinary
MD5:4823A137AEFD9972A3DC893A5B71AD23
SHA256:93A073BEE839FE2D05A42129018EC529D84FF1E57C05417EC99BFAA5B6E0ACFF
892iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B126BF247C927A243E186240F06A7849binary
MD5:580030D5CA919A536D000978026034CD
SHA256:D91A27BB7E7A03B933D7F1B1A03246F84900294EBB3222D6FF5D4DADB6952283
892iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B126BF247C927A243E186240F06A7849der
MD5:EA8D5825BDBC99C5D7217BA6C29392BA
SHA256:907C1A6B5AF72322C8495477AA87FAD630B5C09B871543A7C526DE941A5EEBAA
892iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\50CD3D75D026C82E2E718570BD6F44D0_E353C9EBFD1BAB837760A84408CED896der
MD5:2332F744B22D1C11EE936DF49154E31E
SHA256:ACF493E8E788FB5A472C805981009324E189DBFEB639F204330670D1FAE8A50D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
40
TCP/UDP connections
279
DNS requests
53
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
892
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAonX%2BcE1u7LI9XNW0saTgQ%3D
US
der
471 b
whitelisted
892
iexplore.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/DigiCertGlobalRootCA.crl
US
der
631 b
whitelisted
892
iexplore.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/DigiCertTLSHybridECCSHA3842020CA1-1.crl
US
der
19.1 Kb
whitelisted
892
iexplore.exe
GET
200
10.233.64.243:80
http://pornhubvybmsymdol4iibwgwtkpwmeyd6luq2gxajgjzfjvotyt5zhyd.onion/
unknown
compressed
117 Kb
unknown
892
iexplore.exe
GET
200
10.233.64.243:80
http://pornhubvybmsymdol4iibwgwtkpwmeyd6luq2gxajgjzfjvotyt5zhyd.onion/front/menu_livesex?segment=straight&token=MTY0NTY4MjMxMJR2YOX_EMOApHsDaJaPvD5sBESHAKhmZW62iXPlVZzCve5nwKmObA9_ieVYT1QE-VbsRVz5J9uO4KlAhLpRK-A.?
unknown
compressed
2.71 Kb
unknown
892
iexplore.exe
GET
200
172.217.168.195:80
http://crl.pki.goog/gsr1/gsr1.crl
US
der
1.61 Kb
whitelisted
892
iexplore.exe
GET
200
10.233.64.243:80
http://pornhubvybmsymdol4iibwgwtkpwmeyd6luq2gxajgjzfjvotyt5zhyd.onion/front/menu_livesex?segment=gay&token=MTY0NTY4MjMyME4sIOw6FH2pGlTiENhTCOvKUJVV8BKkQqN5I3w0QalUcOgmnHBaL2bsUMaOB1zQUPF3CuAigKvf-rrCZuD1gYw.?
unknown
compressed
2.65 Kb
unknown
892
iexplore.exe
GET
200
172.217.168.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
892
iexplore.exe
GET
200
10.233.64.243:80
http://pornhubvybmsymdol4iibwgwtkpwmeyd6luq2gxajgjzfjvotyt5zhyd.onion/gayporn
unknown
compressed
105 Kb
unknown
892
iexplore.exe
GET
216.18.168.30:80
http://hubt.pornhub.com/htcheck.html?site_id=3
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
892
iexplore.exe
66.254.114.156:443
cdn1-smallimg.phncdn.com
Reflected Networks, Inc.
US
suspicious
892
iexplore.exe
66.254.114.41:443
www.pornhub.com
Reflected Networks, Inc.
US
malicious
3548
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
892
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3548
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
892
iexplore.exe
205.185.208.142:443
di.phncdn.com
Highwinds Network Group, Inc.
US
suspicious
892
iexplore.exe
10.233.64.243:80
pornhubvybmsymdol4iibwgwtkpwmeyd6luq2gxajgjzfjvotyt5zhyd.onion
unknown
892
iexplore.exe
88.221.255.147:80
ctldl.windowsupdate.com
Akamai International B.V.
unknown
892
iexplore.exe
142.251.39.110:443
www.google-analytics.com
Google Inc.
US
whitelisted
892
iexplore.exe
216.18.168.30:80
hubt.pornhub.com
Reflected Networks, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
www.pornhub.com
  • 66.254.114.41
whitelisted
ctldl.windowsupdate.com
  • 88.221.255.147
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
pornhubvybmsymdol4iibwgwtkpwmeyd6luq2gxajgjzfjvotyt5zhyd.onion
  • 10.233.64.243
unknown
di.phncdn.com
  • 205.185.208.142
whitelisted
static.trafficjunky.com
  • 205.185.208.79
whitelisted
ci.phncdn.com
  • 152.195.34.118
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY DNS Query for TOR Hidden Domain .onion Accessible Via TOR
Potential Corporate Privacy Violation
AV POLICY DNS Query for .onion Domain Via TOR - Not Google
Potential Corporate Privacy Violation
ET POLICY DNS Query for TOR Hidden Domain .onion Accessible Via TOR
Potential Corporate Privacy Violation
AV POLICY DNS Query for .onion Domain Via TOR - Not Google
No debug info