URL:

https://www.watchonlinemovies89.com.pk/

Full analysis: https://app.any.run/tasks/bcb7346c-74d8-4ffd-857d-b2ac83ce1452
Verdict: Malicious activity
Analysis date: December 08, 2021, 09:10:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

C9D70E5696161244094A484B9C59AD6B

SHA1:

327AB3CBA2195E55A301135A8E3C6A679A3AAB9D

SHA256:

4F79514FE3E88FE0F8CFAFDB2817E633EFED55F63D695A2C5F41A4766E579DA6

SSDEEP:

3:N8DSLYQJrTNAln:2OLLVNAln

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks supported languages

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 2756)
    • Reads the computer name

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 2756)
    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 520)
    • Executed via COM

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 2756)
    • Creates files in the user directory

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 2756)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 3576)
      • iexplore.exe (PID: 520)
    • Reads the computer name

      • iexplore.exe (PID: 3576)
      • iexplore.exe (PID: 520)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 520)
      • iexplore.exe (PID: 3576)
    • Reads CPU info

      • iexplore.exe (PID: 520)
    • Changes internet zones settings

      • iexplore.exe (PID: 3576)
    • Reads internet explorer settings

      • iexplore.exe (PID: 520)
    • Application launched itself

      • iexplore.exe (PID: 3576)
    • Creates files in the user directory

      • iexplore.exe (PID: 520)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3576)
      • iexplore.exe (PID: 520)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe flashutil32_32_0_0_453_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
520"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3576 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2756C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_453_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_453_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe� Flash� Player Installer/Uninstaller 32.0 r0
Exit code:
0
Version:
32,0,0,453
Modules
Images
c:\windows\system32\macromed\flash\flashutil32_32_0_0_453_activex.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3576"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.watchonlinemovies89.com.pk/"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
19 133
Read events
18 968
Write events
165
Delete events
0

Modification events

(PID) Process:(3576) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3576) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3576) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30927891
(PID) Process:(3576) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3576) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30927891
(PID) Process:(3576) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3576) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3576) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3576) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3576) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
31
Text files
160
Unknown types
42

Dropped files

PID
Process
Filename
Type
520iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\82CB34DD3343FE727DF8890D352E0D8Fder
MD5:86D296A2441CA6A004322906D2E59F36
SHA256:01FDD150C54964014B5FE1118BBE4EC6CF76383CEE8BF6BEC7E35A6A033E3F54
520iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\JBRLR9CF.htmhtml
MD5:D424BB09965FA436A202557489D23204
SHA256:37382C719A616C53577368EBBBA091CAC23B34D4626B7E958FED8E800C7EED94
520iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:3D189734F6D23347F17434609449073C
SHA256:416EFA8E4B3B9A4FB16ACF57F82FF1BE916CFC1B4B30BAFE7D49A10FA94D500F
520iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\style[1].csstext
MD5:08E7B89FC1E7AB58137C5A154AFBE767
SHA256:FAEAA54A05B6F5E00A5D79460AE12EE512DA6293E9CBAF6ECFCB8AB0E54A1FC4
520iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\82CB34DD3343FE727DF8890D352E0D8Fbinary
MD5:070940844A9710A2723AFAAC16503B8E
SHA256:5B2747AE613376B4C63F6D5095BE3E1D8132033D8656D3FAFBF957CC7CF16F3E
520iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
520iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:B314B190E6B1C7DC50DD2C6716AF5C58
SHA256:197215A4BC7950BF23CF9206D95D20AEF9794085EDEDCCB603FEB0F48F7B3FB6
520iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:5719E2E308B2F2E4CB48D58A32E0272A
SHA256:FF32858873500A2DCE46A92F8CA51DEDE4E364C0B1B0C5DDCABB493B7404EF8F
520iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\fxa9z[1].jshtml
MD5:C64BA34AAE028AE1BBD61857FBB0D4E1
SHA256:03C2E2DA2D649809D2E66F8083FA3E893184CDBC0908939056AA8EFE62728E10
520iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\styles[1].csstext
MD5:0055017671C0C431C1C0C9E1B457A445
SHA256:4F63DC157BA14E4E42916628F3F030E1D754EA09529A339DD9FA272C7178DFC2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
91
DNS requests
44
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
520
iexplore.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/Omniroot2025.crl
US
der
7.68 Kb
whitelisted
520
iexplore.exe
GET
200
93.184.220.29:80
http://status.geotrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR3enuod9bxDxzpICGW%2B2sabjf17QQUkFj%2FsJx1qFFUd7Ht8qNDFjiebMUCEAkbuTLDTr%2FH%2FoUW%2FUuYd6c%3D
US
der
471 b
whitelisted
520
iexplore.exe
GET
200
142.250.74.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
der
1.41 Kb
whitelisted
520
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7b4aa066fff217d1
US
compressed
4.70 Kb
whitelisted
520
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
520
iexplore.exe
GET
200
13.225.84.175:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
520
iexplore.exe
GET
200
142.250.74.195:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCKJpvy9pIOCwoAAAABGVGE
US
der
472 b
whitelisted
520
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAVG%2Fhgj9%2BGUHaOfzhTEYXM%3D
US
der
471 b
whitelisted
520
iexplore.exe
GET
200
93.184.220.29:80
http://status.geotrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR3enuod9bxDxzpICGW%2B2sabjf17QQUkFj%2FsJx1qFFUd7Ht8qNDFjiebMUCEA%2BYmf%2B7fGJugjH6U%2FDc8TY%3D
US
der
471 b
whitelisted
3576
iexplore.exe
GET
304
93.184.220.29:80
http://crl3.digicert.com/Omniroot2025.crl
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3576
iexplore.exe
13.107.22.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
520
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
172.67.72.90:443
www.watchonlinemovies89.com.pk
US
unknown
3576
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
520
iexplore.exe
142.250.186.168:443
www.googletagmanager.com
Google Inc.
US
suspicious
142.250.186.168:443
www.googletagmanager.com
Google Inc.
US
suspicious
520
iexplore.exe
172.67.39.148:443
static.addtoany.com
US
unknown
172.67.39.148:443
static.addtoany.com
US
unknown
3576
iexplore.exe
172.67.72.90:443
www.watchonlinemovies89.com.pk
US
unknown
520
iexplore.exe
142.250.74.195:80
ocsp.pki.goog
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.watchonlinemovies89.com.pk
  • 172.67.72.90
  • 104.26.6.146
  • 104.26.7.146
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 13.107.22.200
  • 131.253.33.200
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
www.googletagmanager.com
  • 142.250.186.168
whitelisted
static.addtoany.com
  • 172.67.39.148
  • 104.22.70.197
  • 104.22.71.197
whitelisted
ocsp.pki.goog
  • 142.250.74.195
whitelisted
www.google-analytics.com
  • 142.250.185.142
whitelisted

Threats

PID
Process
Class
Message
520
iexplore.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
No debug info