URL:

youengage.me

Full analysis: https://app.any.run/tasks/a2be04cc-7ab1-4e73-ba8a-df75b2931de1
Verdict: Malicious activity
Analysis date: March 22, 2024, 11:50:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

68F19A05537C629C3613A3211308E198

SHA1:

7D43F74B3630F1736BEECFDA17743AA1AC040E72

SHA256:

6B3DE3EDEDB805075C89524F7B129B27CD0468044AFD51153E9840D72F4D296C

SSDEEP:

3:7QA/Rn:ZZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3936)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3276"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3936 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3936"C:\Program Files\Internet Explorer\iexplore.exe" "youengage.me"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
16 633
Read events
16 510
Write events
92
Delete events
31

Modification events

(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
736198448
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31095887
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31095887
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
48
Text files
151
Unknown types
18

Dropped files

PID
Process
Filename
Type
3276iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:E53BFE3592DD6DD03BDE7F4ED6CA8846
SHA256:EA0B2CEB79A1C7893E3BB13477C110AD259AAF40AEC6265B1A26C19D2383CEBD
3276iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1DECDAD7EC3944B22AF01515E5BD8140_E0924BFC73BA99707F0EFF1746B1AD4Bbinary
MD5:70D8919551E41AF4A4C6E184EF019C78
SHA256:91BC81DB9DCA91D088DC469EF437959FA5A75A5CD59052AB4995281FD301BC0C
3276iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:8D63C62FEDFBB21C162C5AE9F6E7AD0A
SHA256:C8D36FB8B3A1CAB40D62A1CF9C3748BBD8C87AA9F03631C36E3556FE4C823E63
3276iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:24A996FEF0A69DAFE9D1D7B7BF42CB88
SHA256:981C684988FD3CE17D91676DA0BCB7492B958C22D543D627AB506300A57C0B17
3276iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1DECDAD7EC3944B22AF01515E5BD8140_E0924BFC73BA99707F0EFF1746B1AD4Bbinary
MD5:4E218AAB1470E01E14BD716EEE590BD7
SHA256:19FAF4EFC41B49CA34BFE96D67FDE179D631BBD03B06E2FDD142892FE6D5B864
3276iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\62RRP814.htmhtml
MD5:E3CF4FB883FB968CB27B11DCC4138CF0
SHA256:042A129CE2E956703A555406FB0B386DE9E34B9C8B8AA96A698F507248E44124
3276iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:037AE8164352CA91E80AD33054D1906D
SHA256:07C018EB07002663D5248DAA8A65EAF587955E3DB45735E7E3AC9CB13D7D664E
3276iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\bootstrap-select.min[1].csstext
MD5:2D868F5F03695620AD1C172DFB4EBBDC
SHA256:69279BEE49C5F3502F7A3F07358DA1562CC0A10D57E8A56CFC0F8977D367C99F
3276iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\fontawesome-all[1].csstext
MD5:8F0D6E614145B84E4AB60A0C6E6BA11B
SHA256:91154DDD1F49E822B3D150531EB0D25464EAC57DEB39AEEF69E3A46FC35CBE6F
3276iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\style.min[1].csstext
MD5:5D888445CD09AD35891AC468CD8B04CB
SHA256:FE9AD9796D39E706FE661DDF90151C0EBC03251164354D55F1EE95CA06878B40
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
70
DNS requests
32
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3276
iexplore.exe
GET
307
34.120.184.123:80
http://youengage.me/
unknown
unknown
3276
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEATSnKKOZ0W%2FtJR%2BZNystZc%3D
unknown
binary
471 b
unknown
3276
iexplore.exe
GET
200
172.217.18.99:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDS57q68k6VpwlSRtIvj9A4
unknown
binary
472 b
unknown
3276
iexplore.exe
GET
304
23.32.238.203:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7f30423e8f7249ff
unknown
unknown
3276
iexplore.exe
GET
200
172.217.18.99:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
3276
iexplore.exe
GET
200
172.217.18.99:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIAjrICMzZli2TN25s%3D
unknown
binary
724 b
unknown
3276
iexplore.exe
GET
200
172.217.18.99:80
http://ocsp.pki.goog/s/gts1d4/aumrVTETAxk/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQDoPqxya05ZCxBqAzuYoLz0
unknown
binary
472 b
unknown
3276
iexplore.exe
GET
200
172.217.18.99:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
3276
iexplore.exe
GET
200
108.138.2.195:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
binary
2.02 Kb
unknown
3276
iexplore.exe
GET
200
172.217.18.99:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDBS5NY4gwYhxCot62SBiap
unknown
binary
472 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
3276
iexplore.exe
34.120.184.123:80
youengage.me
GOOGLE-CLOUD-PLATFORM
US
unknown
3276
iexplore.exe
34.120.184.123:443
youengage.me
GOOGLE-CLOUD-PLATFORM
US
unknown
3276
iexplore.exe
23.32.238.203:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3276
iexplore.exe
172.217.18.99:80
ocsp.pki.goog
GOOGLE
US
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3276
iexplore.exe
142.250.186.138:443
fonts.googleapis.com
GOOGLE
US
whitelisted
3276
iexplore.exe
18.245.46.25:443
cdn.zapier.com
US
unknown

DNS requests

Domain
IP
Reputation
youengage.me
  • 34.120.184.123
malicious
ctldl.windowsupdate.com
  • 23.32.238.203
  • 23.32.238.195
  • 23.32.238.201
  • 23.32.238.185
  • 23.32.238.202
  • 23.32.238.208
  • 23.32.238.179
  • 23.32.238.186
  • 23.32.238.192
  • 23.32.238.234
  • 23.32.238.232
  • 23.32.238.224
  • 23.32.238.225
  • 23.32.238.219
  • 23.32.238.218
  • 23.32.238.217
  • 23.32.238.240
  • 23.32.238.226
whitelisted
ocsp.pki.goog
  • 172.217.18.99
whitelisted
fonts.googleapis.com
  • 142.250.186.138
whitelisted
cdn.zapier.com
  • 18.245.46.25
  • 18.245.46.67
  • 18.245.46.71
  • 18.245.46.93
unknown
o.ss2.us
  • 108.138.2.195
  • 108.138.2.10
  • 108.138.2.107
  • 108.138.2.173
whitelisted
ocsp.rootg2.amazontrust.com
  • 18.172.109.64
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.172.109.64
shared
www.googletagmanager.com
  • 216.58.206.72
whitelisted
cdn.firstpromoter.com
  • 18.245.31.25
  • 18.245.31.42
  • 18.245.31.86
  • 18.245.31.95
shared

Threats

No threats detected
No debug info