| URL: | binder-sa.com |
| Full analysis: | https://app.any.run/tasks/68e25df9-0d6c-41ee-998a-5c0e164542e9 |
| Verdict: | Malicious activity |
| Analysis date: | February 07, 2024, 10:41:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | AADC010D384E6DF7914792ED6F65C6F4 |
| SHA1: | 64CAA9CAEABF2F0BF17BC3712CDA31826CD3A092 |
| SHA256: | 5BB28D8EEDBDAF1DEE1BBA98F614DEC148503450176F5AAA81D94F17CE1F3B69 |
| SSDEEP: | 3:6bWT:l |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1588 | "C:\Program Files\Internet Explorer\iexplore.exe" "binder-sa.com" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3564 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1588 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (1588) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (1588) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (1588) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (1588) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1588) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1588) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (1588) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1588) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1588) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1588) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3564 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\ZQPS0YVW.htm | html | |
MD5:293105942FC3274ADE2673BECC728B2E | SHA256:4EDC3EF710FDB555D87A355139D95EEDCB36F086EFF0B78C25522937A95331F1 | |||
| 3564 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\265C0DEB29181DD1891051371C5F863A_DDCF8A1BB8132E191B1D87188F0E5FF4 | binary | |
MD5:A2A4D4115F197A39FA1F8FB7B45CA3A9 | SHA256:AF2ED48DCF4D5792A88CD6C0DB0A5B98C12FE5D987E7A5A76C241DD02CA57EE0 | |||
| 3564 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\polyfills.ee14e44f6e797e80[1].js | text | |
MD5:05E5BB05A981A072ECB96AB9E98C07B4 | SHA256:6328C98731E505ABAA90460C7DEDAA6C1AACC4388DC84E1C38920BEC5A84EFA0 | |||
| 3564 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\265C0DEB29181DD1891051371C5F863A_DDCF8A1BB8132E191B1D87188F0E5FF4 | binary | |
MD5:F6EDA20DD540C3E40C3E9719B4AADC0D | SHA256:3E6597B4DA2B82CB48F833AD17FEAA59954718C90040AA265267EE8572F1097F | |||
| 3564 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\runtime.13ee40132850200d[1].js | text | |
MD5:31D20E3600769DC2A44F4F174939D342 | SHA256:C975DD187AA2CC848181F9FDA45CE78EB19BD6916BB239CB28FC050B6035BA43 | |||
| 3564 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | binary | |
MD5:EA3389C94742BF95538BF660C87BAF69 | SHA256:9340394F5D8228AEB6205EFD12843916FBA1815A018CD67604B829A8E5BC0C06 | |||
| 3564 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:0B0DF1C41223B7B9B9CFBA1ED8D86339 | SHA256:8CA26BE44C5747FAC10E47F5BA6B9CF6338FFDC8A086722EBD4566C93FF8894D | |||
| 3564 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\icon[1].css | text | |
MD5:2FDDB1BB9C2891BD4889B8210AC87EBD | SHA256:4AE70F5AFD112BB84E818663B63CC1FACE87476897BB033EBF1A76D5FEACBE9E | |||
| 3564 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\scripts.16a55c219d7a64c9[1].js | text | |
MD5:F52B6D4CB24BB3C6092CB1FA008DEA0D | SHA256:DD79302314E51263FBE557E840209463EBB1258EE6A391C5A80B5580D3A89CE6 | |||
| 3564 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\css2[1].css | text | |
MD5:0C6AE5DE7B90091339B418A35EDF0831 | SHA256:DED2709E707F46E4F931B65BBEE4DC526549433136E9F042CDBC778F58CFB57D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3564 | iexplore.exe | GET | 200 | 144.208.76.173:80 | http://binder-sa.com/ | US | html | 6.89 Kb | unknown |
3564 | iexplore.exe | GET | 200 | 144.208.76.173:80 | http://binder-sa.com/polyfills.ee14e44f6e797e80.js | US | text | 33.7 Kb | unknown |
3564 | iexplore.exe | GET | — | 144.208.76.173:80 | http://binder-sa.com/main.1b8c75768bc09bcc.js | US | — | — | unknown |
3564 | iexplore.exe | GET | — | 144.208.76.173:80 | http://binder-sa.com/scripts.16a55c219d7a64c9.js | US | — | — | unknown |
1588 | iexplore.exe | GET | 304 | 23.32.238.195:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c7ba49abb4fd7e2c | DE | — | — | unknown |
1588 | iexplore.exe | GET | 200 | 144.208.76.173:80 | http://binder-sa.com/assets/logo/Logo@2x.png | US | image | 21.1 Kb | unknown |
3564 | iexplore.exe | GET | 304 | 23.32.238.195:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?719472706f200c2b | DE | — | — | unknown |
3564 | iexplore.exe | GET | 200 | 142.250.186.35:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDf%2FqechPhkiAm5teJWf%2BUv | US | binary | 472 b | unknown |
3564 | iexplore.exe | GET | 304 | 23.32.238.195:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2589c27b79f3ea05 | DE | — | — | unknown |
3564 | iexplore.exe | GET | 200 | 142.250.186.35:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | US | binary | 1.41 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3564 | iexplore.exe | 144.208.76.173:80 | binder-sa.com | IMH-IAD | US | malicious |
3564 | iexplore.exe | 142.250.186.42:443 | fonts.googleapis.com | GOOGLE | US | whitelisted |
3564 | iexplore.exe | 142.250.186.35:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3564 | iexplore.exe | 23.32.238.195:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
3564 | iexplore.exe | 142.250.186.99:443 | fonts.gstatic.com | GOOGLE | US | whitelisted |
1588 | iexplore.exe | 144.208.76.173:80 | binder-sa.com | IMH-IAD | US | malicious |
1588 | iexplore.exe | 184.86.251.16:443 | www.bing.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
binder-sa.com |
| malicious |
fonts.googleapis.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Exploit Kit Activity Detected | ET EXPLOIT_KIT TA569 Middleware Domain in DNS Lookup (binder-sa .com) |