URL:

https://w15.mangafreak.net/

Full analysis: https://app.any.run/tasks/1b031344-ccf7-43f8-87fd-93164049aa53
Verdict: Malicious activity
Analysis date: October 20, 2023, 10:11:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

39B4E58F334E8C3D766F1D64C21C761C

SHA1:

97F3004C24974CEAD6828CAD27AAD421768BE7B5

SHA256:

6A10A123B33C775B0506AF0131C761B93D74F5E70D41AF5F61FBC58784801688

SSDEEP:

3:N8qhChn/0Kn:2qU9/z

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3820)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1560"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3820 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3820"C:\Program Files\Internet Explorer\iexplore.exe" "https://w15.mangafreak.net/"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
21 811
Read events
21 752
Write events
59
Delete events
0

Modification events

(PID) Process:(3820) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3820) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3820) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3820) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3820) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3820) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3820) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3820) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000056010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3820) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3820) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
0
Suspicious files
38
Text files
232
Unknown types
0

Dropped files

PID
Process
Filename
Type
1560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:9AC6CC37767D999762666849817A0801
SHA256:757AEEBA3B44894D5C0A9BA1E78D020B528A3F59925F5582B35C387BADC624F2
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\custom_tooltip[1].csstext
MD5:0C2288286917CDE2C8B44921AE944382
SHA256:EFB2F6B63A98DAD7D8CD032E1EA167F825310A0914A10E0DB1B13DA888F4821C
1560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:1DCF2E354C7345B7D861370391FDC15D
SHA256:E87BB973B2E618C5E1012D62C73D2896073F1D2D8BCA5D209150B7172CCF1384
1560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:0FDEA80A7D60F3468FFA6B6672026715
SHA256:A1653A65581F298040E5F7F5BF5E7023AE2904325BE2841004F98A4D923E70C2
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\70x100[1].jpgimage
MD5:A4EB80A6C4297217741CED5311EA598F
SHA256:D0CD34AD26ACF0462527A8CA403B57675790DE50291C9CA46935D51164C78F2A
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\search[1].jstext
MD5:A646B7441D828636D3A239935F47F0EE
SHA256:74142C2EC18399D0EC5C915C17C435A7814A6C37A18C8532C1D7F5EC1FAE1A6E
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\responsiveslides.min[1].jshtml
MD5:04F1B2AC39E762CD516CB359755C8CC6
SHA256:1F306DB5A9C29477ACDD6B78D57734F0AA7936A1FA9B9BA8BD36204BA12AAF40
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\9IVKFTR6.htmhtml
MD5:BAA9AA99D5D67C1260699DB69A0A1AA4
SHA256:E958BDEA9033780E576E6DAD95F37035598D2DC24FF2AD2314AC1B40BCAF3411
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\style[1].csstext
MD5:ED6EF70FAB03F63E0FAD6699B41495CF
SHA256:87811C9C8A799EF6D5AD55AAFF7403BDFFE04A311CCF638154ED73463BA94046
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\70x100[4].jpgimage
MD5:114EB6C1FDA4827879BBB3A0A2212A91
SHA256:25D1D5DA029BCD6FEEACBE89B739C303E86232CEF8D3E7EEA13E1C8C67E8ABE6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
64
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1560
iexplore.exe
GET
200
23.32.238.171:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ab6c62e3d2bbc5b0
unknown
compressed
4.66 Kb
1560
iexplore.exe
GET
200
178.79.242.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?060020e49c501eb3
unknown
compressed
4.66 Kb
1560
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEGtZ2vxuw0JnCTjODIpny8A%3D
unknown
binary
471 b
1560
iexplore.exe
GET
200
178.79.242.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?faeb8e0afac69e8e
unknown
compressed
61.6 Kb
1560
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQD50q2MxTvdnxLfPCm8%2F51a
unknown
binary
472 b
1560
iexplore.exe
GET
200
23.32.238.171:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?0de8e35fb8e63d76
unknown
compressed
61.6 Kb
1560
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCiqTpRpOc3bRIUpkAuvtnV
unknown
binary
472 b
1560
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gts1c3/MFAwTjBMMEowSDAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCDx9GnoHWsw4QZ9qW7IsCPg%3D%3D
unknown
binary
470 b
1560
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
1560
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEAvdydtVepu2EG5DDg8vjd8%3D
unknown
binary
471 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1560
iexplore.exe
104.26.5.92:443
images.mangafreak.net
CLOUDFLARENET
US
unknown
1560
iexplore.exe
178.79.242.128:80
ctldl.windowsupdate.com
LLNW
DE
unknown
1560
iexplore.exe
23.32.238.171:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1560
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
1560
iexplore.exe
142.250.181.234:443
ajax.googleapis.com
GOOGLE
US
unknown
1560
iexplore.exe
142.250.186.78:443
apis.google.com
GOOGLE
US
unknown
1560
iexplore.exe
104.21.69.41:443
cdn.siteswithcontent.com
CLOUDFLARENET
unknown
1560
iexplore.exe
172.67.73.96:443
images.mangafreak.net
CLOUDFLARENET
US
unknown
1560
iexplore.exe
142.250.181.227:80
ocsp.pki.goog
GOOGLE
US
unknown
1560
iexplore.exe
192.243.59.20:443
fibberestimate.com
DataWeb Global Group B.V.
US
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 178.79.242.128
  • 178.79.242.0
  • 23.32.238.171
  • 23.32.238.201
  • 23.32.238.243
  • 23.32.238.242
  • 23.32.238.225
  • 23.32.238.219
  • 23.32.238.241
  • 23.32.238.192
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
apis.google.com
  • 142.250.186.78
unknown
ajax.googleapis.com
  • 142.250.181.234
unknown
cdn.siteswithcontent.com
  • 104.21.69.41
  • 172.67.204.22
unknown
images.mangafreak.net
  • 172.67.73.96
  • 104.26.5.92
  • 104.26.4.92
unknown
ocsp.pki.goog
  • 142.250.181.227
unknown
www.googletagmanager.com
  • 142.250.185.168
unknown
fibberestimate.com
  • 192.243.59.20
  • 173.233.139.164
  • 173.233.137.36
  • 192.243.61.227
  • 192.243.61.225
  • 173.233.137.60
  • 173.233.137.44
  • 192.243.59.13
  • 192.243.59.12
  • 173.233.137.52
unknown
cm.mgid.com
  • 104.19.129.76
  • 104.19.130.76
  • 104.19.133.76
  • 104.19.131.76
  • 104.19.132.76
unknown

Threats

No threats detected
No debug info