| URL: | http://www.kurdtvs.net |
| Full analysis: | https://app.any.run/tasks/537d0e5e-5e72-49de-b5b9-a1216f0b7dab |
| Verdict: | Malicious activity |
| Analysis date: | February 24, 2022, 10:20:12 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 1ED6F4B61836975D975A45F2F7CB7D35 |
| SHA1: | 0A0EE47E69D9B1A7DC46C1E5A8F6509AB9839319 |
| SHA256: | 6344EB1E9D92051F8BB093D2A12B69D53571667737362CDB306BFB15D2D1451C |
| SSDEEP: | 3:N1KJS43R:Cc4h |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 652 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2516 CREDAT:4134154 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2516 | "C:\Program Files\Internet Explorer\iexplore.exe" "http://www.kurdtvs.net" | C:\Program Files\Internet Explorer\iexplore.exe | Explorer.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3764 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2516 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (2516) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (2516) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: 491832768 | |||
| (PID) Process: | (2516) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30943592 | |||
| (PID) Process: | (2516) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 791989018 | |||
| (PID) Process: | (2516) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30943592 | |||
| (PID) Process: | (2516) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2516) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2516) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2516) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2516) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\N321I2XM.htm | html | |
MD5:— | SHA256:— | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\ncthMfeWe3y-qpWiKs5PIRmiMRs[1].js | text | |
MD5:— | SHA256:— | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\kurdmax[1].png | image | |
MD5:— | SHA256:— | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\R90CTXMS.htm | html | |
MD5:— | SHA256:— | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\160x51xlogo.png.pagespeed.ic.0Jf2XZDckR[1].png | image | |
MD5:— | SHA256:— | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\nrttvhd[1].png | image | |
MD5:— | SHA256:— | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\kurdsat[1].png | image | |
MD5:— | SHA256:— | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\style[1].css | text | |
MD5:— | SHA256:— | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\22-04-2019-c52af58b-avatv[1].png | image | |
MD5:— | SHA256:— | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\rudawhd[1].png | image | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3764 | iexplore.exe | GET | 200 | 104.21.95.59:80 | http://kurdtvs.net/img/160x51xlogo.png.pagespeed.ic.0Jf2XZDckR.png | US | image | 7.37 Kb | suspicious |
3764 | iexplore.exe | GET | 200 | 104.21.95.59:80 | http://kurdtvs.net/css/style.css?suncode=comp | US | text | 2.40 Kb | suspicious |
3764 | iexplore.exe | GET | 200 | 104.21.95.59:80 | http://kurdtvs.net/uploads/kurdsat.png | US | image | 4.17 Kb | suspicious |
3764 | iexplore.exe | GET | 200 | 104.21.95.59:80 | http://kurdtvs.net/uploads/nrttvhd.png | US | image | 3.24 Kb | suspicious |
3764 | iexplore.exe | GET | 200 | 104.21.95.59:80 | http://kurdtvs.net/uploads/kurdmax.png | US | image | 4.34 Kb | suspicious |
3764 | iexplore.exe | GET | 200 | 104.21.95.59:80 | http://kurdtvs.net/uploads/rudawhd.png | US | image | 3.93 Kb | suspicious |
3764 | iexplore.exe | GET | 200 | 104.21.95.59:80 | http://kurdtvs.net/uploads/files/03-10-2017-b83282e7-Kurdmaxshow.png | US | image | 2.76 Kb | suspicious |
3764 | iexplore.exe | GET | 200 | 104.21.95.59:80 | http://kurdtvs.net/uploads/files/23-04-2016-c02c9b27-nrt2-hd-live-kurdtvs.png | US | image | 2.10 Kb | suspicious |
3764 | iexplore.exe | GET | 200 | 104.21.95.59:80 | http://kurdtvs.net/uploads/newline.png | US | image | 9.27 Kb | suspicious |
3764 | iexplore.exe | GET | 200 | 104.21.95.59:80 | http://kurdtvs.net/uploads/nettv.png | US | image | 4.01 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 104.16.95.65:443 | static.cloudflareinsights.com | Cloudflare Inc | US | shared |
— | — | 13.225.80.25:443 | cdn.worldvectorlogo.com | — | US | unknown |
3764 | iexplore.exe | 13.225.80.25:443 | cdn.worldvectorlogo.com | — | US | unknown |
3764 | iexplore.exe | 142.250.186.138:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
3764 | iexplore.exe | 192.243.59.12:80 | pl15400277.trustedcpmrevenue.com | DataWeb Global Group B.V. | US | malicious |
3764 | iexplore.exe | 23.32.238.201:80 | ctldl.windowsupdate.com | XO Communications | US | suspicious |
2516 | iexplore.exe | 131.253.33.200:443 | www.bing.com | Microsoft Corporation | US | whitelisted |
2516 | iexplore.exe | 23.32.238.201:80 | ctldl.windowsupdate.com | XO Communications | US | suspicious |
2516 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3764 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.kurdtvs.net |
| suspicious |
kurdtvs.net |
| suspicious |
maxcdn.bootstrapcdn.com |
| whitelisted |
jsc.adskeeper.co.uk |
| whitelisted |
images.dmca.com |
| whitelisted |
cdn.worldvectorlogo.com |
| shared |
www.googletagmanager.com |
| whitelisted |
pl15400277.trustedcpmrevenue.com |
| malicious |
static.cloudflareinsights.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |