URL:

hf5qj5.rzwmfzrgxh.com

Full analysis: https://app.any.run/tasks/150a3099-c56c-472e-948f-f246316112a3
Verdict: Malicious activity
Analysis date: November 07, 2023, 20:57:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
SHA1:

BBCA257D07BF3EF862B9E28B23FAF2404DF8AC59

SHA256:

6CA01F5D0C5698E3F2601F90200ACAEE0AA3EC0F68300BA46F8A2F4B94BFA741

SSDEEP:

3:2X3KIn:2HKI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3856)
    • Application launched itself

      • iexplore.exe (PID: 3156)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3856)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3856)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3856)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2912"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3156 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3156"C:\Program Files\Internet Explorer\iexplore.exe" "hf5qj5.rzwmfzrgxh.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3856"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
15 090
Read events
15 021
Write events
64
Delete events
5

Modification events

(PID) Process:(3156) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3156) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3156) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3156) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3156) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3156) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3156) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3156) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3156) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3156) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
25
Text files
15
Unknown types
0

Dropped files

PID
Process
Filename
Type
2912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:BFDD5F1E34F985336D81176262D8DE8A
SHA256:64E2EF942965A27265F54575E04904C429C7B7AB81D63229DFE0DAC3DAE689DE
2912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:DD43F458F87FA3B61A6CF5248AC0D8E8
SHA256:A6D33EBE1B37E9F9D4A86FD2CD92A7E0F49FA69B9B05FCE74F60C23327E8C857
2912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:40941C7787D35FF3C66B3B56324B9751
SHA256:316C5C6C81A1C461F37D395A9F1BCFBABE2D1AD3290AAC32A6F1DB9BC5F3CD96
2912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:29FE81B54EB55454195D0D0A9CC837A5
SHA256:E2FAFEBDD058E2CC21C7AAB4244D25980EE83A9C8EBA38716083D12D3B30AC5A
2912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B59198584CAB69598CECD0845220611Cbinary
MD5:9FEC86B64A3FE9F27B2BE8DF0EF0D53E
SHA256:77E85937966BDFB55DE128685F93C9708FF57FF67F1E872B1BFCF4A9D822DD33
2912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751binary
MD5:60FE01DF86BE2E5331B0CDBE86165686
SHA256:C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8
2912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAbinary
MD5:AC89A852C2AAA3D389B2D2DD312AD367
SHA256:0B720E19270C672F9B6E0EC40B468AC49376807DE08A814573FE038779534F45
2912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B59198584CAB69598CECD0845220611Cbinary
MD5:CFD25CFA2189F1C905810BEEB16802B1
SHA256:91AF22017F4AEB3DE64691ECBECEC20A8C94EE158DE1559E44845C56CDE74901
2912iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\4KCSV9SZ.htmhtml
MD5:370FFAF68F636E8C9B6F7CFA830FD044
SHA256:73D174AA0B325E4B0F718F2339D7362A3EA0E172CBB2C1ABB0408FE5C9FBC688
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
30
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2912
iexplore.exe
GET
302
18.164.52.96:80
http://hf5qj5.rzwmfzrgxh.com/
unknown
unknown
2912
iexplore.exe
GET
200
108.138.2.10:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
binary
2.02 Kb
unknown
2912
iexplore.exe
GET
200
142.250.185.99:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
2912
iexplore.exe
GET
200
23.37.41.57:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
2912
iexplore.exe
GET
307
18.164.52.96:80
http://hf5qj5.rzwmfzrgxh.com/eu
unknown
html
7.52 Kb
unknown
2912
iexplore.exe
GET
200
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b64f2b7eacad1afb
unknown
compressed
4.66 Kb
unknown
2912
iexplore.exe
GET
200
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e94bb274b63b057c
unknown
compressed
4.66 Kb
unknown
2912
iexplore.exe
GET
200
142.250.185.99:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEEyz67apvVllCgpkQqoIv5s%3D
unknown
binary
471 b
unknown
2912
iexplore.exe
GET
200
95.101.54.195:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgTjRXjS7ZYFqZVRNKQqkOluZQ%3D%3D
unknown
binary
503 b
unknown
2912
iexplore.exe
GET
200
142.250.185.99:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
2912
iexplore.exe
18.164.52.96:80
US
unknown
4
System
192.168.100.255:138
whitelisted
2912
iexplore.exe
185.53.179.91:443
www.wall-repair-79237.bond
Team Internet AG
DE
malicious
2912
iexplore.exe
173.222.108.226:80
ctldl.windowsupdate.com
Akamai International B.V.
CH
unknown
2912
iexplore.exe
23.37.41.57:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown
2912
iexplore.exe
95.101.54.195:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
2912
iexplore.exe
142.250.181.228:443
www.google.com
GOOGLE
US
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
www.wall-repair-79237.bond
  • 185.53.179.91
unknown
ctldl.windowsupdate.com
  • 173.222.108.226
  • 173.222.108.210
whitelisted
x1.c.lencr.org
  • 23.37.41.57
whitelisted
r3.o.lencr.org
  • 95.101.54.195
  • 95.101.54.114
  • 95.101.54.211
  • 95.101.54.106
  • 95.101.54.130
  • 2.16.202.112
  • 95.101.54.99
shared
www.google.com
  • 142.250.181.228
whitelisted
ocsp.pki.goog
  • 142.250.185.99
whitelisted
partner.googleadservices.com
  • 142.250.184.226
whitelisted
d1t9jheyiyj1h6.cloudfront.net
  • 18.66.92.162
  • 18.66.92.190
  • 18.66.92.211
  • 18.66.92.165
unknown
o.ss2.us
  • 108.138.2.10
  • 108.138.2.173
  • 108.138.2.195
  • 108.138.2.107
whitelisted
ocsp.rootg2.amazontrust.com
  • 52.84.193.90
whitelisted

Threats

No threats detected
No debug info