URL:

www138.civicscience.com/

Full analysis: https://app.any.run/tasks/1e29fbc4-b558-4a59-9426-8f590396eb97
Verdict: Malicious activity
Analysis date: May 02, 2024, 14:09:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

02C1DA165C6446E9C97523372B1AE039

SHA1:

68EFD4EEE3AB4623BE0162036B6B4AF02AE21F4A

SHA256:

501CFBC0DB3C676EEB401E01B7285927BA9E0FD595E44A25AFD8F6066B4A7286

SSDEEP:

3:EPJ3MGBByAt:0xuc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads the computer name

      • wmpnscfg.exe (PID: 1628)
    • Application launched itself

      • iexplore.exe (PID: 3956)
    • Checks supported languages

      • wmpnscfg.exe (PID: 1628)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1628)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1628"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3956"C:\Program Files\Internet Explorer\iexplore.exe" "www138.civicscience.com/"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
4012"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3956 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
14 633
Read events
14 507
Write events
91
Delete events
35

Modification events

(PID) Process:(3956) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3956) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3956) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31104154
(PID) Process:(3956) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3956) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31104154
(PID) Process:(3956) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3956) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3956) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3956) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3956) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
11
Text files
8
Unknown types
6

Dropped files

PID
Process
Filename
Type
4012iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:08C65ABD24A033E6645C1D7A4472A212
SHA256:BEE86107BFBB61A54B202BAB446809AE9CC8EDC9852BB3A00267E90FE5B5126A
4012iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:B752D1807E37658BF7B57354ADD8E423
SHA256:D9DADF2B7D5C0C0DB72188E8D455338B233F70313E375B830FD6C96E03F3A860
4012iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:DA68CDE5EBE71A43F412D10F4F8CC633
SHA256:34504FB03C0D5D63D6B9550A14C539D0FC901FD03E1F6C22FE4BE6DF7FD3EDA9
4012iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62der
MD5:D4A4A15B53222A91621658ED167C9F20
SHA256:460EF1199B03B53E4032D160826B64C13E9CA061669590DC61D21BD170CF3F17
4012iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894der
MD5:4F573033615544EF59FB76EA6FFD5308
SHA256:8BF433EC3C808263A6C337B341122FEF7E14B2CDB1FA834FC608D37F1B51DD6D
4012iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:A7F041E4191DCAD56C76693168F5C92D
SHA256:6BB699E879EC1640DC96679EC9756AB47F471C4E58562A009567BD1AC32A8AAC
4012iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\83D863F495E7D991917B3ABB3E1EB382_B9161772E802C0780317271F45E3BDB6der
MD5:884CB24ECC2A7DE51B75FCC38A81FBD9
SHA256:DD8D6C8C31771E8199F971D335BB0B7E3BA7EF1F0DE17EAB0499C6C09D66C318
4012iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517der
MD5:D7A27C5E6B1BDD64A5DB1C3CFB61D237
SHA256:0A51462FC397D312144D6A426CC8E459321CF1894E95E135B8402FB02EAD376C
4012iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\83D863F495E7D991917B3ABB3E1EB382_B9161772E802C0780317271F45E3BDB6binary
MD5:7A9A8028AEB8DF0DA6658EE3C4D29575
SHA256:1C3C065CD7EDB6E5489159DBCD47E86EC1CE3F1474CD2EF84BE676265B1BFDA2
4012iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8der
MD5:6D6EE73B2C1553B82D647502F532BECC
SHA256:F47ECBD4F4A3BC09FA3C61A9E85FFFCD0BCADF3A350DD103F874438A08B79955
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
23
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4012
iexplore.exe
GET
200
18.239.15.192:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
binary
2.02 Kb
unknown
4012
iexplore.exe
GET
200
18.65.41.80:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
binary
1.49 Kb
unknown
4012
iexplore.exe
GET
200
52.84.193.90:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
US
binary
1.37 Kb
unknown
4012
iexplore.exe
GET
200
18.245.147.27:80
http://ocsp.r2m03.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQqHI%2BsdmapawQncL1rpCEZZ8gTSAQUVdkYX9IczAHhWLS%2Bq9lVQgHXLgICEA8RPJOfcGCTE%2BXmblS%2Byig%3D
US
binary
471 b
unknown
4012
iexplore.exe
GET
200
52.84.193.90:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
US
binary
1.37 Kb
unknown
3956
iexplore.exe
GET
304
95.101.54.131:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c21588876f974d24
DE
unknown
4012
iexplore.exe
GET
304
95.101.54.131:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ee8e7929c6b4ef0e
DE
unknown
3956
iexplore.exe
GET
304
95.101.54.131:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?48102323af88c435
DE
unknown
3956
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
unknown
3956
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
US
binary
313 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
4012
iexplore.exe
54.175.246.190:80
www138.civicscience.com
AMAZON-AES
US
unknown
4012
iexplore.exe
54.175.246.190:443
www138.civicscience.com
AMAZON-AES
US
unknown
4012
iexplore.exe
95.101.54.131:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
4012
iexplore.exe
18.239.15.192:80
o.ss2.us
US
unknown
4012
iexplore.exe
18.65.41.80:80
ocsp.rootg2.amazontrust.com
AMAZON-02
US
unknown
4012
iexplore.exe
52.84.193.90:80
ocsp.rootca1.amazontrust.com
AMAZON-02
US
unknown
4012
iexplore.exe
18.245.147.27:80
ocsp.r2m03.amazontrust.com
US
unknown

DNS requests

Domain
IP
Reputation
www138.civicscience.com
  • 54.175.246.190
  • 18.204.156.254
  • 3.210.231.243
malicious
ctldl.windowsupdate.com
  • 95.101.54.131
  • 95.101.54.195
  • 95.101.54.113
  • 95.101.54.121
  • 95.101.54.203
  • 2.16.202.128
  • 2.16.202.115
  • 95.101.54.128
  • 95.101.54.123
whitelisted
o.ss2.us
  • 18.239.15.192
  • 18.239.15.174
  • 18.239.15.14
  • 18.239.15.186
whitelisted
ocsp.rootg2.amazontrust.com
  • 18.65.41.80
whitelisted
ocsp.rootca1.amazontrust.com
  • 52.84.193.90
shared
ocsp.r2m03.amazontrust.com
  • 18.245.147.27
unknown
d2zqfs55y95cft.cloudfront.net
  • 18.239.36.72
  • 18.239.36.66
  • 18.239.36.120
  • 18.239.36.103
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 2.19.96.11
  • 2.19.96.18
  • 2.19.96.40
  • 2.19.96.34
  • 2.19.96.26
  • 2.19.96.10
  • 2.19.96.41
  • 2.19.96.48
  • 2.19.96.35
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info