URL:

http://45.87.149.34.bc.googleusercontent.com

Full analysis: https://app.any.run/tasks/98cfb6bb-0b30-4155-b88f-2fabbf1d8ed6
Verdict: Malicious activity
Analysis date: September 04, 2023, 17:02:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

0B67FCB1657AA2C290CFBC898FAE3193

SHA1:

0A1233D969E6752E8274ECD8C5C96461BD292AFE

SHA256:

7086E8C65B145F5637DA70C971FE66E92C2D54E994F8FD46023E0AC0DEDDB6CC

SSDEEP:

3:N1KGU6pPALtGTn:CGhmGT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2220)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2220"C:\Program Files\Internet Explorer\iexplore.exe" "http://45.87.149.34.bc.googleusercontent.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2392"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2220 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
16 059
Read events
15 986
Write events
69
Delete events
4

Modification events

(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
35
Text files
52
Unknown types
0

Dropped files

PID
Process
Filename
Type
2392iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\angular-translate.min[1].jstext
MD5:A4D0977836CA8A1C8B6001C029A89B9B
SHA256:55C1FFFB51C6B05E29856C66261FA59FB12393A8E1BB37D5FFB656E2EB387C09
2392iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\fontFace[1].csstext
MD5:338855569759CA44A0734EC4435BCBD0
SHA256:9CD04D1A84368FA539B48CC09D3721091127B9EB2858FF5E4863D6C127CCEDAE
2392iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\8ac9e38d-29c6-41ea-8e47-4ae4d2b1a4e1[1].woffwoff
MD5:A94D80AC65FF1DE7D5BD5FB2F3AB0B63
SHA256:BED9E7DF863BF3B78564D4DF95EDC0C581E5ADA78CB3381198E734AC1D9539D8
2392iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\angular-locale_en[1].jstext
MD5:7DA0269AA66D40D9B9980BD5C0BB902C
SHA256:71F2D3048E604FED91A29C84204F99C7F9CB6B06D9BA04FBB5304951EB51C714
2392iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\conductAllInScope[1]text
MD5:0E84E84CEFE7EC71D48BB27DE0622273
SHA256:CEF5B6D7128FE5E4DDBA4F17D651AE7F2028731E55D344460096693F82A57DB0
2392iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\app[1].jshtml
MD5:79BE6F7DFFA8E49B2CE5B0C87E84FF0C
SHA256:B33F1EFE3FD9E02A76F3A3C2E399B255A7E8F1E108F84ECBFFF99B19A04EED83
2392iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery.min[1].jstext
MD5:CCD0EDD113B78697E04FB5C1B519A5CD
SHA256:A57B5242B9A9ADC4C1EF846C365147B89C472B9CD770FACE331EFCB965346B25
2392iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\angular.min[1].jstext
MD5:C5D22C0A6F50FD66AC9EE980A2B7AC61
SHA256:91FB6887A7D7B8F298F3EA09ABD8284404916B3623679B791A71087A12D65523
2392iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\messages_en[1].jstext
MD5:AA8216EF8220A1311703C93FA6E63207
SHA256:A620B5767D4C8F27792FA5DD1C1541828AA921C564008ED78159302ADEB62727
2392iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\logo[1].pngimage
MD5:2366E2603CEFFBB40899C84FDD580C5B
SHA256:695BCD07565A83117E56FE384126D53CB925B94207EAF2433107E8A08ACCB498
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
54
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2392
iexplore.exe
GET
200
34.96.106.200:80
http://static.parastorage.com/services/wix-public/1.719.0/scripts/error-pages/app.js
unknown
html
5.79 Kb
unknown
2392
iexplore.exe
GET
200
34.96.106.200:80
http://static.parastorage.com/services/wix-public/1.719.0/images/error-pages/logo.png
unknown
image
2.84 Kb
unknown
2392
iexplore.exe
GET
404
34.149.87.45:80
http://45.87.149.34.bc.googleusercontent.com/
unknown
html
1.03 Kb
unknown
2392
iexplore.exe
GET
200
34.96.106.200:80
http://static.parastorage.com/services/third-party/fonts/Helvetica/fontFace.css
unknown
text
3.11 Kb
unknown
2392
iexplore.exe
GET
200
34.96.106.200:80
http://static.parastorage.com/services/third-party/angular-translate/1.1.1/angular-translate.min.js
unknown
text
2.29 Kb
unknown
2392
iexplore.exe
GET
200
34.96.106.200:80
http://static.parastorage.com/services/wix-public/1.719.0/styles/error-pages/styles.css
unknown
text
3.11 Kb
unknown
2392
iexplore.exe
GET
200
34.96.106.200:80
http://static.parastorage.com/services/third-party/angularjs/1.2.28/angular.min.js
unknown
text
39.0 Kb
unknown
2392
iexplore.exe
GET
200
34.96.106.200:80
http://static.parastorage.com/services/third-party/angularjs/1.2.28/i18n/angular-locale_en.js
unknown
text
866 b
unknown
2392
iexplore.exe
GET
200
34.96.106.200:80
http://static.parastorage.com/services/wix-public/1.719.0/scripts/error-pages/locale/messages_en.js
unknown
text
1.94 Kb
unknown
2392
iexplore.exe
GET
200
34.96.106.200:80
http://static.parastorage.com/services/third-party/jquery/2.0.3/jquery.min.js
unknown
text
28.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2392
iexplore.exe
34.149.87.45:80
45.87.149.34.bc.googleusercontent.com
GOOGLE
US
unknown
2392
iexplore.exe
34.96.106.200:80
static.parastorage.com
GOOGLE
US
unknown
2392
iexplore.exe
146.75.121.84:80
www.wix.com
FASTLY
US
unknown
4
System
192.168.100.255:138
whitelisted
2220
iexplore.exe
104.126.37.162:443
www.bing.com
Akamai International B.V.
DE
unknown
2220
iexplore.exe
8.248.131.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
2220
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2392
iexplore.exe
146.75.121.84:443
www.wix.com
FASTLY
US
unknown
2392
iexplore.exe
185.230.61.217:443
support.wix.com
Wix.com Ltd.
US
unknown

DNS requests

Domain
IP
Reputation
45.87.149.34.bc.googleusercontent.com
  • 34.149.87.45
unknown
static.parastorage.com
  • 34.96.106.200
shared
www.wix.com
  • 146.75.121.84
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.162
  • 104.126.37.170
  • 104.126.37.163
  • 104.126.37.160
  • 104.126.37.153
  • 104.126.37.168
  • 104.126.37.154
  • 104.126.37.176
  • 104.126.37.152
whitelisted
ctldl.windowsupdate.com
  • 8.248.131.254
  • 8.241.121.126
  • 67.27.235.126
  • 67.27.157.254
  • 67.27.157.126
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
support.wix.com
  • 185.230.61.217
whitelisted
d2x3xhvgiqkx42.cloudfront.net
  • 108.138.24.75
  • 108.138.24.39
  • 108.138.24.28
  • 108.138.24.189
whitelisted
ocsp.comodoca.com
  • 104.18.14.101
  • 104.18.15.101
whitelisted

Threats

No threats detected
No debug info