URL:

alt-af12.mail.ru

Full analysis: https://app.any.run/tasks/203d0cbf-d450-4cb7-8a6f-5cc1c2f63d69
Verdict: Malicious activity
Analysis date: January 23, 2024, 08:31:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

2DD6DB3747C70072C82942A07EDDD27B

SHA1:

B33F6CC92DF6E4225ACEB68EA41AF6715C074AE5

SHA256:

69A8A35F876B6865E0DD989877AA3DA3F8BA0970CF9812BE6C6422A93842E40C

SSDEEP:

3:gRe5l:gUj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3456)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2052"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3456 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3456"C:\Program Files\Internet Explorer\iexplore.exe" "alt-af12.mail.ru"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
26 370
Read events
26 222
Write events
140
Delete events
8

Modification events

(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3456) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
51
Text files
200
Unknown types
0

Dropped files

PID
Process
Filename
Type
2052iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\KU9R10XM.htmhtml
MD5:B51956ED2A6129F43C5D0ECC011CC5A5
SHA256:1AC63374D015EEE8D9D875502AA63981DBEB9D86A14096DE0D504763808E429B
2052iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\32EB332F23A238B0DC8C4A0D9C936056binary
MD5:9DEBAE2A62DFB53E3A0E2762F2FED804
SHA256:0287A4C08C6837CD1BA0BE4179877600DF3D5409E2100B8D4D99BEDAE76453A0
2052iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\32EB332F23A238B0DC8C4A0D9C936056binary
MD5:C717B97593EA5E1125710CE259333CED
SHA256:6F9EB0B3B0BDEA577B25E5D111C296625178EFFE1815FE68662550454C690DAA
2052iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\login[1].htmhtml
MD5:7601A6F7334DAFCDFC2399F5F3ACA7B6
SHA256:B4607DCAABC19BE0F2CB7265312BB1B81363DB361BC76A56567A28DDB6B5BDB5
2052iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\W6LLILIZ.txttext
MD5:B739CAB4F0E735072B044FE6002AA29C
SHA256:54F4CA86F9341E4C3D4B75A153C95BBC82E5358CEBD73CA2E77DF370B8431AB4
2052iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81Bbinary
MD5:E93FE278EFB74C8F11CE87076B859FC5
SHA256:F73462902F50E4C291F90203969646C55ADA888F9A4DF5DB4150F7A42EA0CDEA
2052iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81Bbinary
MD5:C050BF78834D8F7961BAA8A1C4373CA1
SHA256:9346FF8079CED5A9AC74203D6E94F4FF8CEEBE278732CDEF90409EA5B1CFB4D7
2052iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\RP1MHL22.txttext
MD5:04B4F5D56C2574DFE9CB2C0E78227014
SHA256:14F2DB89CE881624A423ECDDF624736F346FE5377000A439DF47C2982AED9B64
2052iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50D7940D5D3FEDD8634D83074C7A46A3binary
MD5:96ABEE6F7EF5886A58B8D50F128DC61A
SHA256:8BB892247E3E4E20DCDCAB14720B3D6B210E0C238211E755E509172F341DCB01
2052iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_77EBB02497FB930F7932BE0CDFE874FBbinary
MD5:CE54F65367A3207C882187FAEC65FB69
SHA256:BABBB2D75EA406DC9D6B98121CCBC124054AF53895861E09C4959C8A43664789
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
33
TCP/UDP connections
95
DNS requests
36
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2052
iexplore.exe
GET
301
217.69.139.125:80
http://alt-af12.mail.ru/
unknown
html
169 b
unknown
2052
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?098bd4f8ce551810
unknown
unknown
2052
iexplore.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D
unknown
binary
1.41 Kb
unknown
2052
iexplore.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D
unknown
binary
1.40 Kb
unknown
2052
iexplore.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDD%2F2jDCJa5FQkuK6Tw%3D%3D
unknown
binary
1.40 Kb
unknown
2052
iexplore.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDAHEzfkIhtdN293xvg%3D%3D
unknown
binary
1.40 Kb
unknown
2052
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d66bcfdf10b71413
unknown
unknown
2052
iexplore.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDFZ43noMCcDUxwQLHw%3D%3D
unknown
binary
1.40 Kb
unknown
2052
iexplore.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyI%2BPTVbmSvIKrQ%3D
unknown
binary
1.40 Kb
unknown
2052
iexplore.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEH1NQqkrQx1%2BZFPnwZqNWHc%3D
unknown
binary
1.41 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2052
iexplore.exe
217.69.139.125:80
alt-af12.mail.ru
LLC VK
RU
unknown
2052
iexplore.exe
94.100.180.216:443
e.mail.ru
LLC VK
RU
unknown
2052
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2052
iexplore.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
2052
iexplore.exe
94.100.180.61:443
account.mail.ru
LLC VK
RU
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2052
iexplore.exe
95.163.59.243:443
stat.radar.imgsmail.ru
LLC VK
RU
unknown
2052
iexplore.exe
217.69.139.215:443
e.mail.ru
LLC VK
RU
unknown

DNS requests

Domain
IP
Reputation
alt-af12.mail.ru
  • 217.69.139.125
  • 94.100.180.167
  • 217.69.139.88
unknown
e.mail.ru
  • 94.100.180.216
  • 217.69.139.215
  • 217.69.139.216
  • 94.100.180.215
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
account.mail.ru
  • 94.100.180.61
  • 217.69.139.61
unknown
stat.radar.imgsmail.ru
  • 95.163.59.243
whitelisted
light.mail.ru
  • 217.69.139.215
  • 94.100.180.216
  • 217.69.139.216
  • 94.100.180.215
unknown
imgs2.imgsmail.ru
  • 5.181.61.0
unknown
r.mradx.net
  • 95.163.52.80
whitelisted

Threats

No threats detected
No debug info