URL:

https://www.google.com/url?sa=t&source=web&rct=j&opi=89978449&url=https://www.youtube.com/watch?v=1AV5PFSl7FA&ved=2ahUKEwico-2lgPOJAxXHxQIHHcx3LUIQjjh6BAgdEAE&usg=AOvVaw1eJKI-WL2lOl7pIb-HnEtH

Full analysis: https://app.any.run/tasks/416c0611-2519-4479-9640-76e8a2f88220
Verdict: No threats detected
Analysis date: November 23, 2024, 19:28:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

3232BE750F08FE682BB04ACC69C1B2F7

SHA1:

068CABD777ED6197861D29F25EE37751B7E9D863

SHA256:

73CFC1F98B050F3A14C914556F6DBEDCC873E3149676C2E4A6907E99B3A7C635

SSDEEP:

3:N8DSLI2sljXoW+PhIDNRRVYrSLUxGTKSEIY571jQTkYUNb3KrLtk/sGnkRQWALSM:2OLI2slQpUNRROGLUxGF5YXjQAvN+GTx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1836)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3104)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
848"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1836 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1836"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.google.com/url?sa=t&source=web&rct=j&opi=89978449&url=https://www.youtube.com/watch?v=1AV5PFSl7FA&ved=2ahUKEwico-2lgPOJAxXHxQIHHcx3LUIQjjh6BAgdEAE&usg=AOvVaw1eJKI-WL2lOl7pIb-HnEtH"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3104"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
17 643
Read events
17 525
Write events
94
Delete events
24

Modification events

(PID) Process:(1836) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(1836) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(1836) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31145437
(PID) Process:(1836) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(1836) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31145437
(PID) Process:(1836) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1836) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1836) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1836) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1836) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
1
Suspicious files
38
Text files
46
Unknown types
0

Dropped files

PID
Process
Filename
Type
848iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4FA45AE1010E09657982D8D28B3BD38E_841DF67C840691A847835C0F760B4DC0binary
MD5:56378ED4BB016EC2F3D1219B47183206
SHA256:8AAF78CCB840868014A4A01909FC25C865925156728C0C9228866872434D198B
848iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\supported_browsers[1].htmhtml
MD5:EA78DD72ACBFCCF6A1900CC25B2E4B4E
SHA256:C1B0D6A0C14418ABFE627F52950066187771E5047F5FFA5BE5C0E50EA5E03292
848iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\yt_logo_rgb_light[1].pngimage
MD5:D654F892F287A28026CD4D4DF56C29C8
SHA256:FC6F5D8F32F13D5855840234DC1BFF5C91C35318EE2192D99B13EB3572F0BCA8
848iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\dinosaur[1].pngimage
MD5:BDDA3FFD41C3527AD053E4AFB8CD9E1E
SHA256:1A9251DC3B3C064CFC5E2B90B6C7DC3C225F7017066DB2B77E49DAE90A94A399
848iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:306AFF357F51DE2FD0C763D3615C0443
SHA256:C8D5E5F06D246B3B0FBFBE7058CACC1F2F25F291F63B4ECBE721DF97DA3312D7
848iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199binary
MD5:B0BB9E5855F3AD7A44969BF6AC95DDE7
SHA256:403FDB868250503C6E41B18A5F2D86DB77EA30385BDC5D180750FACC62B2CBE2
848iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:B2D6169AE952E36094DC9E2959E452B3
SHA256:5DEEFA0AA044DF56D6FCD0A465FD5A516A620BD007D851826BC33E47B70CEC06
848iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\O37FWXR3.txttext
MD5:C8A952E1BCA9CBAD53299649F2F52361
SHA256:5602A3410150D1370068D5B8B6107B072B3630780D360EB4AE23987E48475DB2
848iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:E8FEC8B860CA5D4DB095D7DF47D9A57A
SHA256:89A48189F75D88C99A690A7FF7D002880467093280D6A71D2CC2F1D170C3B6D1
848iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\firefox[1].pngimage
MD5:7F980569CE347D0D4B8C669944946846
SHA256:39F9942ADC112194B8AE13BA1088794B6CB6E83BD05A4ED8CE87B53155D0E2F7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
50
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
848
iexplore.exe
GET
304
84.201.210.20:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3a75f9bdfde1ae8f
unknown
whitelisted
848
iexplore.exe
GET
304
84.201.210.20:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?651840a0ef66a591
unknown
whitelisted
848
iexplore.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
848
iexplore.exe
GET
200
142.250.186.67:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
848
iexplore.exe
GET
200
142.250.186.67:80
http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQCdnAM1WJ6jQhB6sJGT2Dti
unknown
whitelisted
848
iexplore.exe
GET
200
142.250.186.67:80
http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEEGoFYJ0C3qQCbRh5xcgwPQ%3D
unknown
whitelisted
848
iexplore.exe
GET
200
142.250.186.67:80
http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQCm0zxQ5KDvqwpdQsrzXj3H
unknown
whitelisted
848
iexplore.exe
GET
200
142.250.186.67:80
http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQDEGAgOcBEqfBC%2B1yioLDZa
unknown
whitelisted
1836
iexplore.exe
GET
304
84.201.210.20:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9f379e501adbc710
unknown
whitelisted
1836
iexplore.exe
GET
304
84.201.210.20:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e5d569a6b1e21146
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
whitelisted
848
iexplore.exe
142.250.185.100:443
www.google.com
GOOGLE
US
whitelisted
848
iexplore.exe
84.201.210.20:80
ctldl.windowsupdate.com
IP4NET Sp. z o.o.
PL
whitelisted
848
iexplore.exe
142.250.186.67:80
ocsp.pki.goog
GOOGLE
US
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
848
iexplore.exe
216.58.206.78:443
www.youtube.com
GOOGLE
US
whitelisted
848
iexplore.exe
216.58.206.74:443
fonts.googleapis.com
GOOGLE
US
whitelisted
848
iexplore.exe
216.58.206.35:443
fonts.gstatic.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.238
whitelisted
www.google.com
  • 142.250.185.100
whitelisted
ctldl.windowsupdate.com
  • 84.201.210.20
  • 217.20.57.39
  • 217.20.57.42
  • 217.20.57.22
  • 217.20.57.25
  • 217.20.57.40
  • 217.20.57.24
whitelisted
ocsp.pki.goog
  • 142.250.186.67
whitelisted
c.pki.goog
  • 142.250.186.67
whitelisted
o.pki.goog
  • 142.250.186.67
whitelisted
www.youtube.com
  • 216.58.206.78
  • 142.250.185.206
  • 142.250.185.110
  • 142.250.184.206
  • 142.250.185.238
  • 216.58.212.174
  • 142.250.185.142
  • 216.58.206.46
  • 142.250.184.238
  • 142.250.186.174
  • 172.217.16.206
  • 142.250.185.78
  • 142.250.181.238
  • 142.250.186.142
  • 142.250.185.174
  • 142.250.186.78
whitelisted
fonts.googleapis.com
  • 216.58.206.74
whitelisted
fonts.gstatic.com
  • 216.58.206.35
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted

Threats

No threats detected
No debug info